Skip to main content
Rank 2
January 23, 2024
Solved

gdpr , especially the Accountability Principle.

  • January 23, 2024
  • 13 replies
  • 714 views

Hu, newbie here. didnt read the Privacy Notice to begin with but when did, was upmost confused. as did not underst most of what was being said. Spent a few days on the ICO website guidance, and phoned them more than a few times to get some understanding. They basically said that anything, and mostly everything in an Account is personal data, not just your name and address, but everything in the Account, and calls, especially as they are recorded by OVO. They said because of that everyone answering the phone in OVO has to at the very least be a lawful representative under the GDPR. But all I ever do is get through to Philippes or South Africa and they do not seem to even know what a Controller is, let alone how ot who to transfer a call to if you are exercising any of the rights in the gdpr. did try using the email address in the Provacy Notice and just got a generic reply from someone, so no help there.Anyone know who in OVO you can talk to about gdpr. ICO say that you have to be able to speak to someone as OVO give a phone number, in the Privacy Notice for contacting the Data Controller, so have to make someone available for that purpose.

Anyone know a number that actually knows how to represent OVO lawfully under the GDPR, more than just security anyway as the ICO that it is so very much more than that. and Accountability, not in the normal use of the word but as is it specifically set out in the gdpr.

Thanks

 

Thanks

    Best answer by Blastoise186

    Hello,

    This comment was left by a Forum Volunteer. It is NOT the official response of OVO.

    Firstly, please try to format your posts properly into paragraphs. Giant walls of text are annoying and painful for others to read, so please try to make it easier for other folks in future.

    I think you really, really need to lower and manage your own expectations here tbh. You’re asking too much of the wrong team to do the wrong thing.

    If you actually read the Privacy Policy properly, you would have not only found an email address - dataprotection@ovoenergy.com - AND a postal address - OVO Energy, 1 Rivergate, Temple Quay, Bristol, BS1 6ED - AND two web links to a couple of forms. This one to request access to your data and this one to request erasure of your data. Everything else is either self-service or can be done via Support. FWIW, yes call recordings can be requested this way too.

    Also, not everything in your account is personal data. OVO is allowed to withhold certain stuff from a GDPR request.

    This isn’t the place to be going into details about Data Controllers and Data Processors acting on behalf of a Data Controller. I will refer you back to the ICO for that.

    One merely needs to provide a way of getting in touch with the DPO, there’s nothing in the rules about how. And I’m sorry, but if your preferred way is by phone… Good luck with that. Most large companies don’t allow you to phone the DPO directly. And besides, 99% of the time they need to have a written record of the request - verbal often isn’t enough. This is exactly why there’s no phone number (other than the ICO one) in the “how to contact us” section of OVO’s Privacy Policy.

    Sorry, but this feels like an issue with your expectations vs reality if I’m being honest.

    In my personal view, I’d probably also advise against trying to tell others here on the Forum about how GDPR stuff works unless you fully understand it yourself. This is just a request from me, but it helps to prevent difficult situations from arising as a result of bad advice. Only the Forum Volunteers and Forum Moderators know the full story about how the SSE to OVO Migration worked and I can tell you now that OVO took a total backup of all the old systems before pulling the plug on them. In addition, wiping the old data off of SSE systems merely one month after migrating a customer would have caused its own problems, such as not being able to resolve read disputes or historical billing issues. That data needs to be held for up to six years post-migration. Only then can it be deleted - and most likely will.

    Migrations never lose data when done correctly. Rather than move the original data, you make a copy of it, move that copy over, verify it and only after the migration has been totally verified as complete do you actually proceed to delete the old copy. If something went wrong, you can just go back and grab the missing stuff from the original copy.

    One does not become a GDPR expert simply by reading the ICO website for a few days and calling the ICO once or twice. It took me several months of research to gain the knowledge I have. Given my IT and Cybersecurity backgrounds, I’m also trained on GDPR matters - I have to know it as part of my job.

    13 replies

    Rank 2
    January 29, 2024

    I have waited to respond so I could check the facts with the GDPR Regulator (ICO)

    I have no idea what is going on?

    Leading a Horse to water, may be a well known proverb, it is the context that declares it an insult - as though I am a horse and Blastoise has taken me to water, and I am to ignorant to drink.

    I was not using Moderation as a weapon, simply stating what the T&cs state, and as I felt it to be an insult and that is not acceptable behaviour, and, if no one has any actual experience in relation to my question, that hopefully, because I do feel insulted, they might step in to correct the mistakes, and because they represent OVO, that under the requirements of the GDPR that they might address the question.

    How someone could get banned for asking a question, correcting a response as incorrect, and saying that they felt insulted , would be very strange.

    Of course, as this is an OVO Forum, everything under ti has to comply with the GDPR, as well as T&Cs and one could only be banned after an explanation had been provided, under the GDPRs requirements.

    I do not see how Blastoise being Autistic, is relevant to anything. The statement obviously shows an error. I am diagnosed as Autistic. The suggestion of being able to pick up on signals is wrong. it is hard enough to pick up on signals face to face, and as the Spectrum is so diverse impossible to pick up in a Forum.

    But it is not relevant to anything anyway. there is no questionnaire that has to be filled in, no medical history.

    I have asked a question, the only answer to date, from Blastoise have been completely incorrect as far as the GDPR is concerned. If only for the reason that I asked if anyone had any experience, the actual information has to, because of the GDPR, come from OVO, in its capacity as the Data Controller.

    I most certainly not here to start a fight. I am only here because I cannot seem to find the information , that is supposed to be in the Privacy Notice, and either is, and no one who answers the number in the Privacy Notice is properly trained, or the information in the Privacy Notice, is not accurate or transparent, as the GDPR requires.

    Whatever the reason, I cannot seem to find a way to contact OVO, by phone, as I did not get a response from the email in the Privacy Notice, and, as the Privacy Notice gives a phone number for the contact details of the data Controller, that has to be possible to do, and, as anyone that answers a phone representing OVO, has to be able to demonstrate compliance with the GDPR,that person must be a representative of the Controller so according to the ICO, therefore has to either be able to be a lawful representative themselves, or declare that they are not amd provide the information, of a different number, or transfer the call to a lawful representative.

    As everyone that answers the calls seems to be either in South Africa or the Philippines, so must be declared under the GDPR to be Data Processors, and not Data Controllers, so cannot lawfully represent the Controller, they should be declaring, when you call for an stated GDPR matters, what their formal position is, and acting accordingly.

    As they do not, I assumed that there would be many in the same position, and given that something like a quarter of people do not even have email, I assumed that a quarter of people would have had experience, given the wide ranging impact on everything OVO does, including complaints.

     

    As I have no wish to get into a fight with anyone. Blastoise, could you please, unless you know the answer of who to direct me to, or have had the experience yourself, not respond. It doesn’t help to have inaccurate information, which does not address the question.

    Thank you

    Blastoise186
    Super User
    Super User
    January 29, 2024

    I will spell out the answer one final time.

    1. Write a letter detailing your concerns. It can either be handwritten or done on a computer and printed out - either way works but make sure to include a return address and your account details, otherwise OVO can’t respond
    2. Go to a post office
    3. Buy an A4 envelope - they’re about £1 at most
    4. Buy a 1st Class Large Letter Stamp - £2.50 should be enough
    5. Put the letter in the envelope and write the address on it that’s at the bottom of this comment and attach the stamp in the top right corner on the same side as the address
    6. Hand it to the Post Office staff, they’ll do the rest
    7. OVO will get back to you once they’ve read it - using the exact address as written below will ensure it gets routed directly to the DPO who deals with GDPR matters, or at very least a member of the team who knows how to handle this stuff

    The address is:

    ATTN: Data Protection Officer

    OVO Energy

    1 Rivergate

    Temple Quay

    Bristol

    BS1 6ED

    If you are not willing to accept this answer, then I’m sorry but we will not assist you further via the OVO Forum. For your information, for the purposes of what you seek, the Data Protection Officer IS the Data Controller and/or an authorised representative of the Data Controller. They will assist you with your query.

    Securing energy by zapping security bugs... For that is The Blastoise Way! Remember, I'm just like you - AI Powered Evil Geniuses aren't Staff!
    Rank 2
    February 1, 2024

    Dear Balstoise. You clearly have not read my question.

    Let me make it clear yet again. I know of the other ways to contact the Controller, it is however my given Right to contact the Data Controller by Phone. I need to know how to contact the Data Controller by Phone, not in any other way.

    I asked if anyone had any experience of how to contact OVO -by Phone. 

    Because OVO has a Customer Service, that you can contact by Phone, and states on the website, that is the Contact details for the Data Controller include a phone number, you have to be able to, by law, contact the Data Controller by Phone. 

    The postal address, is by law required for formal documents that have to be formally submitted. OVO cannot require a person to use a method that would be financially detrimental to them for basic communications, such as contacting the Data Controller. 

    It might only be a few pounds, but for those of us that do not have a few spare pounds kicking around it cannot be required. And you forgot to add on the cost of having it signed for, which would be required, or someone in OVO might just say they did not receive it.

    And, you forgot the basics of the GDPR, That a Controller can  only collect data, when it is necessary, for the specific purpose; which it clearly is not, because OVO provide a phone number, and, if I am required to give my name and address, that is personal data that the Controller is, by law, not allowed to collect, until after it has met the requirements of the GDPR, and provided the information on how it intends to Process any Data, and how ones Rights are met. All if which has to be done before any data is collected, so cannot by law  be done in the manner you suggest.

    Your answer cannot be accepted, because it does not relate to the question. If you had addressed the actual question, and provided information that I did not already know, then of course I would accept it. it is only your, one persons opinion, not that of the entire Forum, and isnt even correct in most details relating to the GDPR, it certainly is not the answer to the question, nor an answer from someone that has had experience.

    I need to know, as is my legal Right, who and how to contact the Data Controller by Phone.

    It obviously cannot be the outsourced customer services in S Africa or Philippines, and they seemingly have no idea what  a Data Controller is, let alone who to contact.

    Which Is why I asked if any Customer had experience, and had been able to contact the data Controller.

    The DPO is not the Controller. The Controller appoints the DPO and the DPO is given specific tasks under the GDPR, which do not include the day to day tasks of the Controller. There is not a Phone number for the DPO, so that is not applicable anyway.

    My question was not for you in particular, and why you would answer unless you had direct knowledge and experience of implementing your Rights of receiving a demonstration of Accountability, and so could answer the question of how to contact the Controller .

    So once again, does anyone know, or had experience of how to contact the Data Controller -by Phone.

     

    Thank you