Brighton and Hove Buses:
Privacy Concerns
In May 2024 Unite (the “Union”) published an article raising serious concerns that Brighton and Hove Buses, part of the Go-Ahead Group had installed covert audio recording devices on some of its buses spying on passengers and drivers. From a data protection perspective, the absence of transparency surrounding the use of this technology raised serious questions about compliance with data protection laws.
Transparency and Fair Processing
Under the General Data Protection Regulation (GDPR, and, in this instance specifically the UK GDPR) data controllers must process personal data in a way that is transparent. Transparency could have been achieved by displaying warning signs on the buses. If Unite’s article is accurate, Brighton and Hove Buses may have violated this fundamental principle, and, if correct, the lack of disclosure undermines an individual's ability to make informed decisions about whether to use the service or take alternative measures to protect their privacy.
Brighton and Hove Buses claimed that the recordings were intended to protect drivers from verbal abuse, however without clear documentation and communication of the legal basis relied upon for this processing, these recordings could be deemed unlawful. It would be interesting to read any data privacy impact assessment (DPIA), or legitimate interests’ assessment (LIA) completed to risk assess this processing.

Purpose Limitation and Data Minimisation
The principle of Purpose Limitation states that personal data should be collected for specific, explicit, and legitimate purposes. Furthermore, under the principle of data minimisation, only the data necessary to achieve these purposes should be collected. If the reported audio devices capture passenger conversations beyond the intended scope of driver protection, the company may be breaching these principles.
Retention, Storage, and Security
Questions also arise about how these audio recordings, if made, are retained, stored, and secured. UK GDPR mandates strict safeguards to protect personal data from unauthorised access or misuse. If recordings have been made, then the bus company would have to clearly outline its retention schedule for such recordings and ensure robust measures are in place to secure them. Additionally, if sensitive information was to be inadvertently recorded (for example, a conversation between a couple regarding their health issues) then Brighton and Hove Buses would have to handle it with heightened care.
Enforcement and Accountability
The Information Commissioner's Office (ICO), responsible for enforcing data protection laws in the UK has been made aware of the situation through a formal complaint lodged by the Unite trade union. If the ICO finds that Brighton and Hove Buses have breached data protection laws, the organisation could face significant fines and reputational damage.
Public and Workforce Trust
Beyond the legal aspects, this incident underscores the importance of maintaining trust with both customers and employees. Covertly introducing surveillance measures without consultation or consent erodes confidence and fuels resentment, something Brighton and Hove Buses appears to be experiencing, as evidenced by growing discontent among its employees.
Conclusion
This case serves as a reminder for organisations to prioritise privacy and comply with data protection laws when implementing surveillance measures. Transparency, consultation, and adherence to legal requirements are not just obligations, they are essential to building and maintaining trust.
This article is for general information only. It does not constitute legal advice, and should not be relied upon as such. If you require any further information regarding its content please contact us at info@kpdpconsultancy.co.uk. Law as of February 2025.
