See the Article 29 Working Party Opinion 2/2006 on privacy issues
related to the provision of e-mail screening services:
http://ec.europa.eu/justice_home/fsj/privacy/docs/wpdocs/2006/wp118_en.p
df
Summarising massively the conclusion is that for screening that is
designed to protect the recipient's computer systems, processing can be
done on the grounds of legitimate interest, rather than consent.
Screening to protect users or the organisation does seem to require
consent.
And the WP only mention notifying the recipients, not the senders, of
screened mail though from a quick re-read I can't see that they give any
justification for that limitation.
I've noticed quite a few organisations adding something to their e-mail
footers to say "mail sent to this organisation is likely to be scanned",
which on a technical level seems to be about the best you can do by way
of notification.
Cheers
Andrew
--
Andrew Cormack, Chief Regulatory Adviser
JANET(UK), Lumen House, Library Avenue, Harwell Science and Innovation
Campus, Didcot, OX11 0SG, UK
Phone: +44 (0) 1235 822302
Fax: +44 (0) 1235 822399
JANET, the UK's education and research network
JANET(UK) is a trading name of The JNT Association, a company limited
by guarantee which is registered in England under No. 2881024
and whose Registered Office is at Lumen House, Library Avenue,
Harwell Science and Innovation Campus, Didcot, Oxfordshire. OX11 0SG
> -----Original Message-----
> From: This list is for those interested in Data Protection issues
> [mailto:[log in to unmask]] On Behalf Of Donald
> Henderson
> Sent: 06 March 2009 11:28
> To: [log in to unmask]
> Subject: Re: Checking emails for images etc
>
> Tim,
>
> Whilst I acknowledge the theoretical point that you are arguing, I
> cannot fathom how you would expect anyone who might email an
> organisation to be fully informed about the organisation's policy
> before they send the email. The Council publishes the policy on
> their website, which is probably the most you can hope for.
>
> I think you will find that their practice simply reflects what is
> done by most organisations.
>
> Donald Henderson
> Information Compliance Manager
> Perth & Kinross Council
>
> ________________________________
>
> From: This list is for those interested in Data Protection issues
> [mailto:[log in to unmask]] On Behalf Of Tim Trent
> Sent: 06 March 2009 10:49
> To: [log in to unmask]
> Subject: [data-protection] Checking emails for images etc
>
>
> I just emailed a list member in Cardiff and received the following
> automatic reply:
>
> BEGINS
> YOUR E-MAIL HAS BEEN DELIVERED TO THE INTENDED RECIPIENT.
>
> Your e-mail has been delivered to the intended recipient. For your
> information,
> an image attachment was detected (such as .jpg, .bmp or .gif),
> which may be part
> of a Powerpoint (PPT) file or E-mail background.
>
> A copy of your E-mail has been held in accordance with Cardiff
> Council's ICT
> security policy, and Audit will routinely check these images to
> assess their
> appropriateness.
>
> Any technical queries, please contact the ICT Helpdesk on 029 2087
> 3333.
>
> Any queries regarding this policy, please contact the Authority's
> Audit Manager
> on 029 2087 2275.
> ENDS
>
> Now I have a Friday question for the list:
>
> The email that I sent was personal data. I have no agreement with
> Cardiff Council
> that they may intercept and scan the contents of my emails, nor to
> have the images
> "routinely checked". I am thus unsure of the lawfulness of this
> policy and wonder if
> this might be a breach of my rights as the sender of the email,
> especially as
> there is no prior warning.
>
> What do you all think?
> --
>
> ________________________________
>
>
> Tim Trent - Consultant
> Tel: +44 (0)7710 126618
> web: ComplianceAndPrivacy.com - where busy executives go to find
> the news first
> personal blog: timtrent.blogspot.com/ - news, views, and opinions
> personal website: Tim's Personal Website
> <http://www.trent.karoo.net> - more than anyone needs to know
>
>
> Marketing by Permission
> <http://feeds.feedburner.com/%7Er/MarketingByPermission/%7E6/1>
>
> Important: This message is private and confidential. If you have
> received this message in error, please notify us and remove it from
> your system. This email and any attachment(s) are believed to be
> virus-free, but it is the responsibility of the recipient to make
> all the necessary virus checks. This email and any attachments to
> it are copyright of Meadowood Associates, owners of Compliance And
> Privacy, unless otherwise stated. Their copying, transmission,
> reproduction in whole or in part may only be undertaken with the
> express permission, in writing, of Meadowood Associates, at
> Meadowood House, 30 Redditch, Bracknell, Berkshire, RG12 0TT.
>
> ________________________________
>
> All archives of messages are stored permanently and are available
> to the world wide web community at large at
> http://www.jiscmail.ac.uk/lists/data-protection.html
>
> Selected commands (the command has been filled in below in the body
> of the email if you are receiving emails in HTML format):
>
> * Leaving this list: send leave data-protection to
> [log in to unmask] <mailto:[log in to unmask]&BODY=LEAVE
> data-protection>
> * Suspending emails from all JISCMail lists: send SET * NOMAIL
> to [log in to unmask] <mailto:[log in to unmask]&BODY=SET
> * NOMAIL>
> * To receive emails from this list in text format: send SET
> data-protection NOHTML to [log in to unmask]
> <mailto:[log in to unmask]&BODY=SET data-protection NOHTML>
> * To receive emails from this list in HTML format: send SET
> data-protection HTML to [log in to unmask]
> <mailto:[log in to unmask]&BODY=SET data-protection HTML>
>
> All user commands can be found at
> http://www.jiscmail.ac.uk/help/commandref.htm and are sent in the
> body of an otherwise blank email to [log in to unmask]
>
> Any queries about sending or receiving messages please send to the
> list owner [log in to unmask]
>
> (Please send all commands to [log in to unmask] not the list
> or the moderators, and all requests for technical help to
> [log in to unmask], the general office helpline)
>
> ________________________________
>
> Securing the future... - Improving services - Enhancing quality
> of life - Making best use of public resources.
>
> The information in this email is solely for the intended
> recipients.
>
> If you are not an intended recipient, you must not disclose,
> copy, or distribute its contents or use them in any way: please
> advise the sender immediately and delete this email.
>
> Perth & Kinross Council does not warrant that this email or any
> attachments are virus-free and does not accept any liability for
> any loss or damage resulting from any virus infection. Perth &
> Kinross Council may monitor or examine any emails received by its
> email system.
>
> The information contained in this email may not be the views of
> Perth & Kinross Council. It is possible for email to be falsified
> and the sender cannot be held responsible for the integrity of
> the information contained in it.
>
> Requests to Perth & Kinross Council under the Freedom of
> Information (Scotland) Act should be directed to the Freedom of
> Information Team - email: [log in to unmask]
>
> General enquiries should be made to [log in to unmask] or 01738
> 475000.
>
> Securing the future... - Improving services - Enhancing quality
> of life - Making best use of public resources.
>
>
>
> ________________________________
>
> All archives of messages are stored permanently and are available
> to the world wide web community at large at
> http://www.jiscmail.ac.uk/lists/data-protection.html
>
> Selected commands (the command has been filled in below in the body
> of the email if you are receiving emails in HTML format):
>
> * Leaving this list: send leave data-protection to
> [log in to unmask] <mailto:[log in to unmask]&BODY=LEAVE
> data-protection>
> * Suspending emails from all JISCMail lists: send SET * NOMAIL
> to [log in to unmask] <mailto:[log in to unmask]&BODY=SET
> * NOMAIL>
> * To receive emails from this list in text format: send SET
> data-protection NOHTML to [log in to unmask]
> <mailto:[log in to unmask]&BODY=SET data-protection NOHTML>
> * To receive emails from this list in HTML format: send SET
> data-protection HTML to [log in to unmask]
> <mailto:[log in to unmask]&BODY=SET data-protection HTML>
>
> All user commands can be found at
> http://www.jiscmail.ac.uk/help/commandref.htm and are sent in the
> body of an otherwise blank email to [log in to unmask]
>
> Any queries about sending or receiving messages please send to the
> list owner [log in to unmask]
>
> (Please send all commands to [log in to unmask] not the list
> or the moderators, and all requests for technical help to
> [log in to unmask], the general office helpline)
>
> ________________________________
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
All archives of messages are stored permanently and are
available to the world wide web community at large at
http://www.jiscmail.ac.uk/lists/data-protection.html
If you wish to leave this list please send the command
leave data-protection to [log in to unmask]
All user commands can be found at http://www.jiscmail.ac.uk/help/commandref.htm
Any queries about sending or receiving messages please send to the list owner
[log in to unmask]
Full help Desk - please email [log in to unmask] describing your needs
To receive these emails in HTML format send the command:
SET data-protection HTML to [log in to unmask]
(all commands go to [log in to unmask] not the list please)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
|