FOI request detail

FOI request concerning the 'I am not a robot' box on the fair refund web page

Request ID: FOI-2698-1920
Date published: 06 January 2020

You asked

Hi Can I please have all meeting notes, emails and any other communications concerning the addition of the 'I am not a robot' check addition to the service delay refund process?

We answered

TfL Ref: 2698-1920

Thank you for your request received by us on 4 December 2019 asking for information about the addition of the 'I am not a robot' check addition to the service delay refund process.

Your request has been considered in accordance with the requirements of the Freedom of Information Act and our information access policy. You asked for:

all meeting notes, emails and any other communications concerning the addition of the 'I am not a robot' check addition to the service delay refund process?

Firstly, we would like to apologise for any difficulty that you may have experienced with the additional security measures that we had to put in place in August 2019.

We take the protection of our customers data extremely seriously. In August 2019 there was an attempted credential stuffing attack on a small number of Oyster Online accounts, which resulted in us having to respond quickly to put in place a number of operational counter measures, one being the CAPTCHA page. This was in no way intended to prevent customers from submitting Service Delay Refunds.

We continue to advise customers not to provide third parties with their Contactless and Oyster account log on details and to not re-use passwords across multiple sites.
Any communications that we do hold would be exempt under section 31(1), Prevention and detection of crime. Release of information under the Freedom of Information Act is a release to the public both at home and abroad. Therefore TfL must consider how any potential recipient of the information might use it, rather than make assumptions about the intentions of the individual making the request. This is because we consider that withholding the information requested is currently stopping bots from logging into the service and making automated login attempts thereby making disclosure of  any requested communications that we do hold exempt under this exemption.
The use of this exemption is subject to an assessment of the public interest in relation to the disclosure of the information concerned. We recognise the need for openness and transparency by public authorities, but in this instance we consider that there is greater public interest in safeguarding our information systems and protecting the integrity of the London transport network from the realistic possibility of attacks on our software systems .
Please see the attached information sheet for details of your right to appeal as well as information on copyright and what to do if you would like to re-use any of the information we have disclosed.

Yours sincerely

 

Jasmine Howard
FOI Case Officer
Information Governance
Transport For London

 

Back to top

Want to make a request?

We'll email you the response within 20 working days.


We'll publish the response online without disclosing any personal information.