MP113 Unintended Data Disclosure when using SR8.2

Proposer Ian Speller
Lead Analyst SEC Change
Date raised 28/01/2020
StageWithdrawn
Implementation date Unknown
Latest update On 8 August 2022, SECAS officially received notification from the Proposer that they have decided to withdraw the Modification Proposal, in accordance with the Right to Withdraw provisions in SEC Section D5.1.

What is the issue?

DCC Service Users routinely query the DCC System to discover or validate various customer, property or meter data as part of their business processes. Queries can be generated using various identifiers, including the MPxN, address and postcode, which are all treated as personal data under General Data Protection Regulation (GDPR).

If a DCC Service User submits a query to the DCC System with a house name and postcode, but without a unique reference, the results may return data of an unintended property due to the ‘matching postcode’ in place. The Proposer believes that could include unintended personal data, which would be a breach of GDPR.

Who is impacted?

DCC

What SEC documents are affected?

Appendix AD ‘DCC User Interface Specification’

Timeline

28 Jan 2020
Draft Proposal raised
13 Mar 2020
Converted to Modification Proposal
10 Jun 2020
Update provided to the SSC
02 Sep 2020
Working Group meeting
10 Mar 2021
Update provided to the SSC
12 Jul 2021
Present to Requirement Workshop for discussion
01 Sep 2021
Present to Working Group for discussion

Modification documents

MP113 September 2020 Working Group Meeting summary
25/09/2020
MP113 Modification Report v0.3
19/02/2020
No files
No files
No files
No files
No files

If you believe there is a problem with this modification, please let us know HERE.