Jump to content

Recommended Posts

Posted
Wonder if he works for a Managed print service, great sales info if you know when contracts are expiring. Not sure why you would post newly acquired info all over the internet though.
  • Thanks 1
Posted

A student who had left a couple of years before placed an FOI request while I was still at work. He was a "difficult" student.

 

He continued to be difficult after leaving, as he was encouraging other former students to make FOI requests with the sole aim of wasting time for staff. Requests were dealt with, and interest in this "sport" died off.

Posted

At the risk of sounding like a grumpy old git, it is not spamming. He is using a legitimate method of identifying what printers/copiers/services a school has.

Yes, it will then be used for business, but because it is via what do they know, then all their competitors have the same info.

  • Thanks 3
Posted
At the risk of sounding like a grumpy old git, it is not spamming. He is using a legitimate method of identifying what printers/copiers/services a school has.

 

I don't think it is what FOIA was introduced for, though. That was to ensure public bodies are kept accountable, it wasn't to save a company from paying some cold-callers.

 

Also, let's take a moment to discuss the security risk of us all posting online saying what systems we have. Why tell someone which platforms we have so people know a route into our network? Especially in the week in which Log4J became known, why would I tell some random on the Internet that we've got Papercut?

 

I'd refuse his request as vexatious. It certainly vexes me!

  • Thanks 2
Posted

Long and short is they are using it to their advantage and they are not doing anything wrong.

 

Can be a very useful tool to get information as a member of the public.

Posted
I don't think it is what FOIA was introduced for, though. That was to ensure public bodies are kept accountable, it wasn't to save a company from paying some cold-callers.

Agreed, but it is within the letter of the law, if it isn't in the spirit of it. As much as it vexes me too, we can't make up the law to suit ourselves.

The law needs revisiting, but it is what it is currently.

Posted
Agreed, but it is within the letter of the law, if it isn't in the spirit of it. As much as it vexes me too, we can't make up the law to suit ourselves.

The law needs revisiting, but it is what it is currently.

 

I'm not trying to make up the law to suit me. I'm suggesting if it vexes us, we should also follow the letter of the law and refuse vexatious requests - https://ico.org.uk/for-organisations/guide-to-freedom-of-information/refusing-a-request/#:~:text=PDF%20(229.08K)-,When%20can%20we%20refuse%20a%20request%20as%20vexatious%3F,can%20refuse%20to%20comply%20with%20a%20request%20that%20is%20vexatious.,-If%20so%2C%20you

Posted

Just to add a different viewpoint

 

There is a proper reason that this sort of thing exists

 

e.g. if someone found out that the Head of an academy has a relative who runs a printer company and suspects that all the schools in the academy are being pressurised to have their contract with this company

 

 

this is, as far as I know, the reason that such things exists - to allow people to dig out situation where someone working for a publicly funded organisation uses it in a way that benefits themselves.

 

In this case I would agree that this is not the case

but limiting the ability of a printer sales person to find out this sort of thing also limits the ability of the other person as well

 

you can't have swings without roundabouts

(or something like that)

 

- - - Updated - - -

 

As an extra bit - would it be valid for the school to reply but leave out the bit about the make etc for security reasons??

  • Thanks 1
Posted
There is a proper reason that this sort of thing exists

 

e.g. if someone found out that the Head of an academy has a relative who runs a printer company and suspects that all the schools in the academy are being pressurised to have their contract with this company

 

 

this is, as far as I know, the reason that such things exists - to allow people to dig out situation where someone working for a publicly funded organisation uses it in a way that benefits themselves.

 

In this case I would agree that this is not the case

but limiting the ability of a printer sales person to find out this sort of thing also limits the ability of the other person as well

 

I would be okay with people making FOI requests in those circumstances, but as you say, that isn't what is going on here. This is someone with a commercial interest in the information using the FOIA to save themselves money. I don't see why limiting people with commercial interests also limits the whistleblower/concerned citizen.

Posted
I'm not trying to make up the law to suit me. I'm suggesting if it vexes us, we should also follow the letter of the law and refuse vexatious requests - https://ico.org.uk/for-organisations/guide-to-freedom-of-information/refusing-a-request/#:~:text=PDF%20(229.08K)-,When%20can%20we%20refuse%20a%20request%20as%20vexatious%3F,can%20refuse%20to%20comply%20with%20a%20request%20that%20is%20vexatious.,-If%20so%2C%20you

 

I know it is annoying but from the article you quote:

The key question to ask yourself is whether the request is likely to cause a disproportionate or unjustifiable level of distress, disruption or irritation.

 

Answering 4 questions, as long as he hasn't bombarded you before, is not vexatious.

 

The article also says

As a general rule, you should not take into account the identity or intentions of a requester when considering whether to comply with a request for information. You cannot refuse a request simply because it does not seem to be of much value.
Posted
I would be okay with people making FOI requests in those circumstances, but as you say, that isn't what is going on here. This is someone with a commercial interest in the information using the FOIA to save themselves money. I don't see why limiting people with commercial interests also limits the whistleblower/concerned citizen.

 

How do you define someone with a commercial interest? Journalists have a commercial interest as they are paid to investigate these things. Should journalists be banned from making FOI requests? If there is a conflict of interest to uncover then someone with a commercial interest is going to be more likely to investigate than someone without. We are all concerned citizens but we all have bills to pay. If schools don't want to respond to requests like this then they should just stick details of all contracts over a certain threshold on their website and refer requesters to that page. It's public money. It's important that the public know how it is spent. At least this guy isn't keeping the information to himself.

Posted
I'm not trying to make up the law to suit me.

Sorry, didn't mean to suggest you were!

More that the law leaves these big gaps that people can take advantage of and we have to follow it, even if it is an a*s.

Posted
If schools don't want to respond to requests like this then they should just stick details of all contracts over a certain threshold on their website and refer requesters to that page.

 

We don't have to do that? I thought there were some requirements on this somewhere...

Posted (edited)
I'm not trying to make up the law to suit me. I'm suggesting if it vexes us, we should also follow the letter of the law and refuse vexatious requests - https://ico.org.uk/for-organisations/guide-to-freedom-of-information/refusing-a-request/#:~:text=PDF%20(229.08K)-,When%20can%20we%20refuse%20a%20request%20as%20vexatious%3F,can%20refuse%20to%20comply%20with%20a%20request%20that%20is%20vexatious.,-If%20so%2C%20you

That link is pretty clear, receiving a single request asking for a set of simple information is not vexatious.

 

As an extra bit - would it be valid for the school to reply but leave out the bit about the make etc for security reasons??

 

Not that I can see, no. Simply knowing what system you have is not a security threat.

 

Everyone needs to remember that the law very much leans on the public interest side of things when determining exemptions for FoI.

 

If you aren't sure, run it past your DPO. There are some exemptions that can only be decided on by a properly qualified person anyway.

Edited by localzuk
Posted
Not that I can see, no. Simply knowing what system you have is not a security threat.

See, I kinda disagree with that. It's really dependent on what you've already disclosed. If you've already told people what your edge appliances, firewalls, your ISP, your AV solution, your wifi solution, what CCTV systems you have etc. are then eventually it can become a security threat. How you handle FOIs? Well, That's a whole different kettle of fish, but disclosing everything could easily present a security threat. Not that obfuscation should be your only security tool in your kit, but it should be a part of it.

Posted
See, I kinda disagree with that. It's really dependent on what you've already disclosed. If you've already told people what your edge appliances, firewalls, your ISP, your AV solution, your wifi solution, what CCTV systems you have etc. are then eventually it can become a security threat

 

Agreed. We have refused FOI requests about our CCTV system before. How many cameras do you have? Are all points of access covered by CCTV? Do the cameras include night vision? Do they include gait recognition? Answering those might have been all a burglar's Christmases at once.

Posted
How do you define someone with a commercial interest? Journalists have a commercial interest as they are paid to investigate these things. Should journalists be banned from making FOI requests?

 

Yeah, I see where you're coming from and quantifying it could be difficult, but I'm sure you agree a newspaper with a potential story of mismanaged public money is not the same as a sales company who don't want to pay cold-callers. Maybe we need to put up with these misuses of the FOIA to ensure the legitimate uses are still possible.

Posted
See, I kinda disagree with that. It's really dependent on what you've already disclosed. If you've already told people what your edge appliances, firewalls, your ISP, your AV solution, your wifi solution, what CCTV systems you have etc. are then eventually it can become a security threat. How you handle FOIs? Well, That's a whole different kettle of fish, but disclosing everything could easily present a security threat. Not that obfuscation should be your only security tool in your kit, but it should be a part of it.

It is if that system is an unpatched Papercut server...

 

The law makes certain exemptions and that's it. Knowing that you run Ricoh copiers is simply not a security risk. Knowing that you have a certain brand of firewall or cctv camera is not a security risk either. Security by obscurity is not security. This is very much why you should be running things past a properly qualified person when making these determinations. The law has very little wiggle room with this, and the public interest test matters.

 

There is no general exemption for perceived security risks.

  • Thanks 1
Posted (edited)
The law makes certain exemptions and that's it. Knowing that you run Ricoh copiers is simply not a security risk. Knowing that you have a certain brand of firewall or cctv camera is not a security risk either. Security by obscurity is not security. This is very much why you should be running things past a properly qualified person when making these determinations. The law has very little wiggle room with this, and the public interest test matters.

I agree that knowing your brands is not a security risk, but declaring specific models of copiers, firewalls and CCTV cameras IS however, I would argue a security risk. Especially in an education setting where upgrading these security risks isn't always seen by senior leaders as a priority.

I agree that security by obscurity is not security - well security by obscurity ALONE is not security, but security by obscurity should be by design part of your process.... but neither is it security to tell everyone exactly where the potential weak spots are in your systems.

 

Again, talk to your legal teams and DPO on this, but if there are specific reasons you believe that disclosure could prejudice the effective conduct of public affairs, then you do have mechanisms to reject it. It's up to your legal teams and DPO to help make that decision as to whether make and models could prejudice your day-to-day operations long term though.

Edited by paulkerton

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...