Friday, 5 October 2012

BAHAMAS | Ten rules for data protection compliance






Wherever possible obtain consent before acquiring, holding or using personal data. Any forms, whether paper or web-based, which are designed to gather personal data should contain a statement explaining what the information is to be used for and who it may be disclosed to.


Be particularly careful with sensitive personal data (i.e. information relating to race, political opinion, physical or mental health, religious belief, trade union membership, sexuality, criminal offences etc).  Such information should only be held and used where strictly necessary.  Always obtain the consent of the individual concerned and notify them of their likely use(s) of such data.


Wherever possible, be open with individuals concerning the information being held about them. When preparing reports or appending notes to official documents, bear in mind that individuals have the right to see all personal data and could therefore read any 'informal' comments made about them.  Also be aware that this includes e-mails containing personal data and so the same caution should be used when sending e-mails.


Only create and retain personal data where absolutely necessary. Securely dispose of or delete any personal data which is out of date, irrelevant or no longer required.  Hold regular reviews of files and discard unnecessary or obsolete data systematically.


When discarding paper records that contain personal data treat them confidentially (i.e. shred such files rather than disposing of them as waste paper). Similarly any unnecessary or out-of-date electronic records should be deleted.  Computers should not be given away or sold unless you have ensured that all information stored on it has been removed or deleted.


Keep all personal data up to date and accurate. Note any changes of address and other amendments.  If there is any doubt about the accuracy of personal data then it should not be used.


Keep all personal data as secure as possible (e.g. in lockable filing cabinets or in rooms that can be locked when unoccupied).  Do not leave records containing personal data unattended in offices or areas accessible to the members of the public. Ensure that personal data is not displayed on computers screens visible to passers-by.  Be aware that these security considerations also apply to records taken away from the University e.g. for work at home or for an external meeting.  Also bear in mind that e-mail is not necessarily confidential or secure so should not be used for potentially sensitive communications.


Never reveal personal data to third parties without the consent of the individual concerned or without reasonable justification.  This includes parents, guardians, relatives and friends of the data subject who have no right to access information without the data subject's consent.  Personal data can only be legitimately disclosed to third parties for purposes connected with the purpose for which the information is kept or to meet statutory requirements but only where you are satisfied to the enquirers' identity and the legitimacy of the request.

Requests for personal information are received from time to time from organisations such as the police or the Valuation Department of the Ministry of Finance for real property tax purposes. You should endeavour to co-operate with these organizations, but steps should first be taken to ensure that requests are genuine and legitimate.


Always obtain consent from the individual’s concerned before placing information about them on the Internet and before sending any personal data outside of your jurisdiction.


Be aware that if you are using a third party data processor e.g. for bulk mailings or database management and are giving them access to personal data, then you must have a written contract in place with them to ensure that they treat such information confidentially, securely and in compliance with the Data Protection Act 2003.

This post is for your information only and nothing contained in this post is intended to constitute a legal opinion.  If you require any detailed advice you should contact a Bahamian e-commerce attorney.  You can contact a Bahamian attorney specializingin Bahamian e-commerce law by clicking here.

Banks in unacceptable data protection breach




The UK Information Commissioner’s Office (ICO) has found 11 banks and other financial institutions in breach of the Data Protection Act after investigating complaints concerning the disposal of customer information.
  • HBOS
  • Alliance & Leicester
  • Royal Bank of Scotland
  • Scarborough Building Society
  • Clydesdale Bank
  • Natwest
  • United National Bank
  • Barclays Bank
  • Co-operative Bank
  • HFC Bank
  • Nationwide Building Society
  • Post Office
were all found to have discarded personal information in waste bins /receptacles outside their premises.
The Immigration Advisory Service was also found to have disposed of personal information in similar circumstances.

The ICO has now required these organisations to sign a formal undertaking to comply with the Principles of the Data Protection Act. Failure to meet the conditions of the undertaking is likely to lead to further enforcement action by the ICO and could result in prosecution by the Office.

David Smith, Deputy Commissioner, said: “It is unacceptable for banks and other organisations to carelessly discard their customers’ information. It is vital that banks and other organisations take security seriously. If they do not, they not only risk further

action from the Information Commissioner but also risk losing the trust of their customers. Individuals must feel confident that banks and other organisations are safeguarding their personal information.”
The ICO believes that organisations in breach of the Data Protection Act security requirements should face a detailed inspection of their security procedures.

Barclays tops data protection complaints list




25 May 2011 

 
The ICO received more valid complaints against Barclays Bank last year than about the other major banks or building societies, Which? investigation finds

The UK's data protection watchdog received more legitimate complaints against Barclays Bank than any of the other major banks or building societies last year, research by consumer rights publisher Which? Money has found. 

From August 2009 to August 2010, the Information Commissioner's Office received 116 complaints about the bank "where compliance with [data protection principles] was assessed as unlikely". Lloyds TSB was just behind with 114 such complaints.

The most frequent complaints related to "subject access requests", when an individual asks an organisation to reveal what data it holds about them. The ICO found that 272 such complaints against the UK's eight major banks were valid, in that the bank had breached the act by failing to comply with the individual's request.
The next most frequent cause for complaint was "inaccurate data". The ICO received 41 valid complaints about the accuracy of Barclays' data during the period in question. 

In response to the report, Barclays said it is committed to protecting its customers' data. "We have no greater priority than the security of our customers’ money and personal information," it said in a statement. “Whenever there is a substantial data breach we ensure we alert the Information Commissioner’s Office, the FSA and our customers where appropriate and we do everything we can to minimise the risk."

The ICO said the numbers reveal serious issues with the way financial institutions handle customer data. "While the number of upheld complaints is small compared to the millions of bank accounts in the UK, mishandling of financial information can have a serious effect on individuals’ lives," it said. "It needs to be looked after properly and customer’s data protection rights respected."

Monday, 1 October 2012

Apple vs Samsung: IP History in the Making (Collier IP)



IP History in the making as a US court on Friday 24th August ordered Samsung to pay Apple over $1bn (£664m) after ruling it had infringed Apple’s Intellectual Property. Samsung are going to appeal and Apple has indicated it will seek sales bans on eight of the phones at the heart of the lawsuit at a hearing on 20 September. The models include the Galaxy S 4G, Galaxy S2 AT&T model, Galaxy S2 Skyrocket, Galaxy S2 T-Mobile model, Galaxy S2 Epic 4G, Galaxy S Showcase, Droid Charge and Galaxy Prevail.

The outcome was very different to the UK court hearing where Judge Colin Birss QC said: “They (the Samsung Galaxy Tablets) do not have the same understated and extreme simplicity which is possessed by the Apple design. They are not as cool.” He said consumers were not likely to get the two tablet computers mixed up and ruled the Samsung tablets do not infringe Apple’s registered design. With different nuances in IP law between the US and the UK, different interpretations are placed on whether IP infringement has taken place.

Google, who recently issued a complaint against Apple responded on Sunday in the US. “The court of appeals will review both infringement and the validity of the patent claims,” it said. “Most of these don’t relate to the core Android operating system, and several are being re-examined by the US Patent Office. The mobile industry is moving fast and all players – including newcomers – are building upon ideas that have been around for decades. We continue to work with our partners to give consumers innovative and affordable products, and we don’t want anything to limit that.”

However, Apple could also attempt to limit sales of other Android-based models it believes infringe its patents.

According to recent data from analysts at IDC based on shipments of phones, Android had a 68.1% of the global smartphone market between April and June. Apple’s iOS had 16.9% and Windows Phone/Windows Mobile had 5.4%.

Maybe the industry will settle on cross licensing arrangements, but whatever the outcome, this is IP History in the making.

Legal risks lurking in cyberspace


(R CHEEKS JR.)

IN today's brave new digital era, the power of the internet as a driver of business growth is unparalleled. Recognising this, the best led regional enterprises continue to augment their models of market engagement to include an interactive presence in cyberspace.

For Bahamian businesses seeking to leverage the marketing and transactional power of the Internet through e-commerce initiatives, important (and in many cases unresolved) questions of legal compliance arise. For the uninformed business the voyage into cyberspace is likely to be very risky. One important risk is that of extraterritorial liability.

A business that develops an interactive online presence may, in the absence of proper guidance, unwittingly expose itself to liability for breach of the laws of another jurisdiction from which its portal is accessible. These risks are amplified where the online activity is of a kind typically subject to strict regulation around the world. Businesses that have faced the greatest difficulty in this regard are those involved with online betting and gaming and the provision of usually regulated professional services. Questions can frequently arise surrounding such issues as how or where customers’ personal information is to be stored or processed, or what is an adequate level of due diligence to perform over a customer that one is meeting in the expanse of cyberspace with little to no personal contact.

Additionally, publishers such as newspapers and magazines who distribute information via their websites also face significant extra territorial legal exposure, particularly in the context of defamation, IP infringement and contempt claims arising as a result of the unlimited accessibility of their publication around the world.

The risk of extraterritorial liability, however, is not confined to these domains. The US-based Internet giant Yahoo! learned this lesson in very expensive fashion. This article will outline the circumstances of Yahoo's experience as an illustration of the compliance risks that some Bahamian businesses may face once they have blasted off into cyberspace.

The case of LICRA v Yahoo is now famous in technology circles. In May of 2000 the French Supreme Court ordered Yahoo! to implement technical measures to prevent customers based in France from buying Nazi memorabilia which were being sold in online auctions conducted on Yahoo's US-based website. The website came to the attention of the French authorities who sued Yahoo claiming that its website violated French law which prohibits the exhibition of Nazi related material.

Naturally, Yahoo's lawyers resisted the suit asserting that as a US-based outfit operating from the US, the material appearing on Yahoo's website was perfectly legal in its own jurisdiction and, indeed, protected by the US First Amendment. At the heart of this matter was the question of legal jurisdiction in cyberspace, a question that continues to perplex technology law practitioners worldwide. Yahoo submitted that it could not be sued in France under French law, as the French Courts had no jurisdiction in the matter. The French judge held quite a different opinion. The French Courts held that it was competent to rule on the matter as the visualisation in France of the offending objects in question meant that Yahoo had breached French law on French territory. To protect itself from the order of the French court, Yahoo applied to the US District Court of California asking for a declaration that the Order was unenforceable in the US. The US court, after considering the French judgment held that “the First Amendment precludes enforcement within the United States of a French order intended to regulate the content of its speech over the Internet.” It also condemned the fact that “by imposing restrictions on the US-based Yahoo.com, the French court tried to regulate the activities of a US corporation within the US on the basis that such activities can be accessed by Internet users in France.”

This case nicely illustrates how the borderless nature of the Internet presents an unprecedented challenge to the concept of sovereign rights and legal jurisdiction in the context of cyberspace. These matters continue to raise very interesting questions of international law and policy, the answers to many of which remain unclear. What is abundantly clear however is that businesses seeking to develop an interactive online presence should ensure that they are properly advised in relation to the very specific and often complicated risks involved. Bahamian businesses operating online must ensure that their cyberspace activity complies with Bahamian domestic law. In addition, a properly advised business will be well aware of the extraterritorial risks lurking in cyberspace and will deploy legal and practical measures to mitigate such risks.

This post is for your information only and is not intended to constitute a legal opinion.  If you require specific advice you should contact a Bahamian e-commerce attorney.  You can contact a Bahamian e-commerce attorney by clicking here.

Monday, 24 September 2012

BAHAMAS - BUILDING & CONSTRUCTION LAW (THE BASICS)

 (A) Building permits

Building permits are granted under the Building Regulation Act for all construction.  In Nassau, application is made to the Ministry of Works.  In the Family Islands, district councils appoint boards which issue building permits for each district.

(B) Building contracts

The internationally recognized forms of building contracts are widely used, especially for larger projects.  For example, the forms of the American Institute of Architects are common for large and medium projects, supplemented to suit local conditions.  There is an ample and varied reservoir of architects, contractors, sub-contractors, and other personnel to take your project from the design concept to ultimate completion.  For smaller projects, such as most home construction, an exchange of correspondence and construction documents, such as the approved plans, is usually sufficient.  Legal advice is also readily available.
 
(C) Completion and formalities
 
A building should be more than 95% complete before it is accepted.  All the remedial or defective work should corrected before practical or substantial completion.  The architect and his consultants check the site and prepare a punch list of work still to be done by the contractor and sub-contractors.

(D) Construction deficiencies and warranties 
 
Provisions relating to deficiencies and warranties are usually covered by the building contract.  It is left to the architect to determine whether the building can be accepted with certain deficiencies.  It is still the contractor’s responsibility to correct those deficiencies within the stipulated time.  Warranties are issued before the architect executes his certificate of substantial or practical completion.  Arbitration is commonly used to deal with construction disputes.  

This post is for your information only and is not intended to constitute a legal opinion.  If you require specific advice, you should contact a Bahamian construction law attorney.  You can contact a construction law attorney in The Bahamas by clicking here.