🙇‍♂️ here’s the @NHSEngland Test and Trace privacy notice. “This privacy notice explains what personal identifiable information is collected by this service” PII 🤦‍♂️🙇‍♂️🙇‍♂️🤷🏼‍♂️🤷🏼‍♂️

https://contact-tracing.phe.gov.uk/help/privacy-notice
“the NHS Test and Trace needs to collect personal identifiable information.”

The information collected on people with coronavirus or those with symptoms includes their:

full name
date of birth
home postcode and house number
telephone number
email address
The information collected on the contacts of people with coronavirus includes, where available, their:

full name
home postcode and house number
telephone number
email address
“The personal identifiable information collected by the NHS Test and Trace is protected in several ways.” <PII again! 🤦‍♂️
“The personal identifiable information collected by the NHS Test and Trace on people with coronavirus or who have symptoms will be kept for 20 years.” < PII again 🤦‍♂️ But oh my kept for TWENTY YEARS!! Show the legal basis for that please
“The personal identifiable information collected on the contacts of people with coronavirus, including those who are showing symptoms, will be kept for 5 years.” <PII again! 🤦‍♂️ But why is this data kept for FIVE years? What’s the legal basis? Where’s the assessment
You have to contact the FOI office to exercise your data protection rights ? 🤷🏼‍♂️ @PHE_uk
Dear @phe_uk 🤦‍♂️ “The law on protecting personal identifiable information, known as the General Data Protection Regulation (GDPR), allows PHE to use the personal identifiable information collected by the NHS Test and Trace.”🤦‍♂️ PII
There is a data protection officer who can be contacted with concerns .. but rights are exercised via the FOI team.
And the privacy notice for Test and Trace was ‘First published: 04 March 2020’ Really? 4 March ...
👀 “PHE also has special permission from the Department for Health & Social Care to use personal identifiable information without people’s consent where this is in the public interest. This is known as ‘Section 251’ approval and includes the use of the information collected ..
... by the NHS Test and Trace to protect the public from coronavirus.”

Not explained but assumed it is Section 251 of the Health Services Act.
The Privacy Notice is not the same as the NHS Covid App
I’ve emailed some enquires to the data protection office and copied the feedback team as per the privacy notice. The feedback email address is ‘closed and no longer monitored’. Oh dear.

I await a response - hopefully - from the data protection office
In my email to the @PHE_uk I have asked (among other things) for clarification of the retention periods of 5 years & 20 years, what data precisely will be used wrt to Section 251 for the broad purpose of public interest (& what interest) + details of assessment inc for 9(2)(i)
Hmm I received two auto replies to my email to the 'Feedback' email address - this https://twitter.com/PrivacyMatters/status/1265948452606955520?s=20
and this - the mail box is for CTAS queries only e.g. contact tracer queries. CTAS is provided by https://portal.e-lfh.org.uk 

Goodness me. A bit of a mess.
You can follow @PrivacyMatters.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled: