Privacy group to challenge UK over test and trace data retention

Open Rights Group threatens legal action over decision to retain personal health data for up to two decades

Digital rights campaigners at the Open Rights Group (ORG) are preparing to legally challenge the UK government over its decision to retain personal health data for up to two decades.

According to The Guardian, ORG is “preparing a legal challenge” and have enlisted data rights lawyer Ravi Naik to draft an open letter addressed to home secretary Priti Patel and health secretary Matt Hancock over the privacy risks associated with the UK's track and trace programme. 

A spokesperson for the digital rights campaign group confirmed to IT Pro that it "will be writing to the government this week to ask for their justifications".

"If these are inadequate we will consider enforcement action or judicial review," they added.

The open letter from the organisation will ask the government to consider switching to a decentralised model, which was the plan until late April when the UK snubbed Apple and Google's jointly-developed contact-tracing API.

Instead, the UK has opted to develop its own centralised contact-tracing system which will retain the personal data of those who had tested positive for the coronavirus for up to two decades.

According to ORG, the decentralised model “has been found to be more likely to comply with both human rights and data protection laws and to enhance trust”.

The digital rights organisation is also asking the government to “publish its assessment of risks and mitigations for vulnerable and marginalised groups”, to clarify who or which political body will be retaining the personal data, and “provide guarantees that data shared through the contact tracing app will not be used to deny access to public services or for the purposes of immigration enforcement”.

Further, ORG wants the government to roll out  “clear communication campaign” in order to “create much-needed trust and confidence in the NHSX app”, which some argue has been breached by the decision to retain the data for a long period of time.

Related Resource

Enhance the safety and security of your people, assets, and operations

Enable a true vision of security with an engineered solution based on hyperconverged and storage platforms

Download now

A spokesperson for the organisation told IT Pro: "We hope the government will adjust its policies to better reflect people’s privacy concerns. If the government increases trust, it will increase participation."

Speaking to The Guardian, ORG executive director Jim Killock added that “the government needs to better explain its reasoning”. 

“What they have done so far has been rushed. Our concern is people will feel reluctant to participate if they feel their personal data is leaving their control,” he said.

Last month, independent security and privacy consultant Dr Chris Culnane and Thinking Cybersecurity CEO Vanessa Teague found that the NHSX contact-tracing app was rife with "varied" security problems that pose a threat to user privacy. Culnane and Teague are also in favour of the decentralised API model.

Featured Resources

How to be an MSP: Seven steps to success

Building your business from the ground up

Download now

The smart buyer’s guide to flash

Find out whether flash storage is right for your business

Download now

How MSPs build outperforming sales teams

The definitive guide to sales

Download now

The business guide to ransomware

Everything you need to know to keep your company afloat

Download now

Most Popular

KPMG offers staff 'four-day fortnight' in hybrid work plans
flexible working

KPMG offers staff 'four-day fortnight' in hybrid work plans

6 May 2021
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

29 Apr 2021
How to move Windows 10 from your old hard drive to SSD
operating systems

How to move Windows 10 from your old hard drive to SSD

30 Apr 2021