Let the Fun Begin! New EU Data General Protection Regulation #GDPR is Adopted

eu falg.jpg

After four years of negotiation, the new EU General Data Protection Regulation (GDPR) has today been formally adopted by the European Parliament. The Regulation will soon be available in all the official EU languages.

The Regulation will take effect twenty days from its post-vote publication in the Official Journal (May 2018) giving Data Controllers two years to prepare for the biggest change to the EU data protection regime in 20 years.

The Regulation will apply to any entity offering goods or services (regardless of payment being taken) and any entity monitoring the behaviours of citizens residing within the EU. Companies are now directly responsible for DP compliance wherever they are based (and not just their EU based offices) as long as they are processing EU citizens’ personal data.

For some breaches of the Regulation (e.g. failing to comply with Data Subjects’ rights or the conditions for processing) Data Controllers can receive a fine of up to 4% of global annual turnover for the preceding year (for undertakings) or 20 million Euros. For other breaches (e.g. failing to keep records or complying with security obligations) the fine can be up to 10 million Euros or 2% of global annual turnover (for undertakings).

The Regulation replaces the previous EU Data Protection Directive (95/46/EC), upon which the UK’s Data Protection Act 1998 (DPA) is based, without the need for further national legislation. It does though allow for substantial national derogations in a number of important areas, so in addition to amending or repealing their existing legislation and guidance, the Government and the Information Commissioner’s Office(ICO) will be working to finalise their positions on key issues such as exemptions, workplace privacy, healthcare services and biomedical research.

The ICO has set up a new GDPR microsite and published a 12 step guide to preparing for the Regulation. Read the Assistant Information Commissioner’s blog here about what more they are planning.

The Regulation is accompanied by the EU Policing and Criminal Justice Data Protection Directive which contains new rules for Data Protection when applied to crime and justice, but which can be implemented by each Member State through its own laws with greater flexibility.

 All Data Protection practitioners and lawyers need to read the Regulation and consider its impact on their organisation and clients. The good people at Covington & Burling LLP have published an automated comparison here to allow readers to see how the Regulation has changed from its previous version.

Training and awareness at all levels needs to start now. Here is a nice video to get you started.

Act Now has a dedicated GDPR section on its website containing articles as well as details of our GDPR webinars and workshops. If you are looking for an up to date DP qualification with a focus on GDPR, have a look at our Data Protection Practitioner Certificate.

GDPR: The Data Protection Principles (but not as you know them Jim!)

canstockphoto16138153

Having recently attended the Information Commissioner’s Office Data Protection Practitioners Conference in Manchester, I should start this blog post by echoing the words of our outgoing Commissioner, Christopher Graham, that the Regulation text is not the final version until later this year when it has been reviewed and fully translated for all 28 member states.

But as the Regulation is unlikely to change in material terms, let’s crack on!

Whenever you see blogs and articles about the new EU General Data Protection Regulation, they are often focusing on what’s new and “exciting”, be that in a good or bad context (see our summary here). But this blog post will look at some of the things that are remaining familiar, albeit in an edited ‘reshuffled’ form.

So let’s go back to basics – the Data Protection Principles. Now under the current Data Protection Act 1998 there are 8 principles that cover things from legitimate purpose to retention and security. Under the Regulation these are changing. Chapter 2, Article 5 (1) (a)-(f) now outlines the principles:

“Personal Data shall be;

1, processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’);

2, collected for specified, explicit and legitimate purposes and not further processed in a a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes; (‘purpose limitation’);

3, adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’);

4, accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’);

5, kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 83(1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (‘storage limitation’);

6, processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’);”

Now while the Regulation text doesn’t specifically say “principle 1” etc. it does confirm these as the principles and it is logical to assign numbers (as opposed to A,B,C). Principle A just doesn’t have the same ring to it as, “the first principle”. I suspect that these will now become known by their subject matter, so for example you would have “the accuracy principle” and “the data minimisation principle.”

You will notice that we are also down to 6 principles from our current 8 under the DPA. The 2 “missing principles” have been amalgamated in to the new 6 principles. All the current requirements in the 8 principles are still here but they are now outlined in the finer detail of the text. So, for example, principle 6 in the DPA  (“processed in accordance with data subjects rights”) is not specifically called out as a principle in the Regulation but it is outlined in Ch2 Art 5 (1) (a) that information will be processed in a “fair and transparent manner”. The requirements of which, outlined in the rest of the Regulation, require Data Controllers (and indeed processors) to ensure that Data Subjects can exercise their rights as outlined in the text in Chapter 3.

The same applies to the current principle 8 of the DPA 1998 “not transferred to a country outside of the EEA without adequate protections” principle. Because the ‘protections’ are outlined in other principles (Chapter 4, section 2 (Security) for example) and the regulatory nature of the Regulation, it is expected that as part of your processing under the other principles you will share data internationally in the correct fashion.

As the saying goes, the devil is indeed in the detail with this Regulation. In this document I’ve put the relevant sections into the principles to which they relate. There is some overlap but generally if you’re talking about principle 1, then the references are all sections of the text that are relevant to some degree. This list is by no means exhaustive but it does give you a view as to how the principles are intertwined into the detailed text.

In the next few posts I’ll be exploring these principles more and some of the related requirements to see what this means in practice and what further location specific standards we should be on the watch for.

Scott Sammons is an Information Risk and Security Officer in the Medico-Legal Sector and blogs under the name @privacyminion. Scott is on the Exam Board for the Act Now Data Protection Practitioner Certificate.

Read more about the EU Data Protection Regulation and attend our full day workshop.

New Data Sharing Consultation

illust_33_e

In February the Government launched a consultation on introducing laws to allow more citizens’ data to be used for ancillary purposes by the public sector. It says:

“Proportionate, secure and well-governed information sharing between public authorities can improve the lives of citizens. It can also support decisions on the economy which allow businesses to flourish, and improve the efficiency and effectiveness of the public sector. The government aims to do more to unlock the power of data.

The consultation runs till 22nd April 2016. It looks at enabling information sharing between public authorities to improve the lives of citizens and support decisions on the economy and society.” 

The proposals fall into 3 categories:

Improving public services

  • allowing public authorities to share personal data in specific contexts to improve the welfare of a specific person (e.g. automatically providing direct discounts on energy bills of people living in fuel poverty)
  • enabling public authorities to access civil registration data (births, deaths and marriages) (e.g. to prevent the sending of letters to people who have died)

Addressing fraud and debt

  • helping citizens manage their debt more effectively and reduce the overdue debt that they owe to government (i.e. allowing sharing of information for public sector debt collection)
  • helping detect and prevent the losses government currently experiences due to fraudulent activity

Allowing use of data for research and official statistics

  • giving the Office for National Statistics access to detailed administrative government data to improve their statistics
  • using de-identified data in secure facilities to carry out research for public benefit

Cynics may say that the proposals are really about allaying public sector fears that Government initiatives such as the Troubled Families Programme, require them to share personal data which may well breach the Data Protection Act 1998 (DPA).

A new criminal offence for unlawful disclosure of personal data is proposed to be introduced. Those found guilty of an offence will face imprisonment for a term up to two years, a fine or both. Certainly the prison element will be welcomed by the Information Commissioner who has recently reiterated his call for stronger sentencing powers for people convicted of stealing personal data under the DPA.

It is proposed that the new measures will be supported by a statutory Code of Practice, which will set out if, how and when data can be disclosed under each power. Primary legislation will set out the requirement to consult the Information Commissioner, and where appropriate Ministers in the Devolved Administrations and other relevant experts before issuing or revising  these Codes. Compliance with these Codes would be a requirement for any public authority seeking to participate under the proposals; failure to abide by the Codes may result in a public authority being removed from the relevant schedule and losing the ability to disclose or receive data under the power.

The whole law on information sharing needs examining. To echo the words of the Government:

We need to go further and update the legal regime to provide simple and flexible legal gateways to improve public sector access to information in key areas which impact the whole public sector in a systematic and consistent way so that citizens can have confidence that their data is being used for the right purposes and remains securely held.”

In 2014 the Law Commission reported on the outcome of a consultation on the law around sharing of personal information between public sector organisations.  It set out its recommendations, which included a full law reform project to be carried out in order to create a principled and clear legal structure for data sharing, which will meet the needs of society. I have not come across the Government’s response to the recommendations. May be this latest consultation is it!

Of course any new laws will have to be consistent with the new EU General Data Protection Regulation (GDPR), expected to come into force in 2018 and, which will replace the DPA.

These and other Information Sharing developments will be examined in our forthcoming full day workshops and webinars. 

Illustration provided by the Office of the Privacy Commissioner of Canada (www.priv.gc.ca)

Extension of Freedom of Information in Scotland

file351272130459

Following a consultation last year by the Scottish Government, the Freedom of Information (Scotland) Act 2002 (FOISA) was recently extended to cover more organisations.

The Freedom of Information (Scotland) Act 2002 (Designation of Persons as Scottish Public Authorities) Order 2016, S.I. 2016/139, came into force on 2nd March 2016. It is made under Section 5 of FOISA. It comes into force on 1st September 2016.

The Order extends coverage of FOISA to contractors overseeing and managing private prisons, bodies providing secure accommodation for children and young people, grant-aided schools, independent special schools and Scottish Health Innovations Limited. These bodies also become subject to the Environmental Information (Scotland) Regulations 2004 in relation to any requests they receive for environmental information.

This is the second order brought forward under Section 5 of FOISA; the first came into force on 1 April 2014 and covers arms-length culture, sport and leisure trusts established by local authorities.

Freedom of Information in Scotland seems to sail in much more calmer waters than in the rest of the UK where the FOI Act comes under intense scrutiny (some say “attack’) from politicians from time to time. The Independent Commission on Freedom of Information was established by the Cabinet Office in July last year to examine the operation of the FOI Act and whether it required any changes. Its recent report says FOI is working well and does not need major changes. However, it does make twenty-one recommendations.

Think you know about FOISA? Have a go at the FOISA test.

 Looking for a FOISA qualification? Our Practitioner Certificate in the Freedom of Information (Scotland) Act 2002 is the only certificated course specially designed for FOI practitioners in Scotland. It is endorsed by the Centre for FOI based at Dundee University

Information Commissioner Congratulates Act Now DP Practitioner Certificate Candidates

ChristopherGraham_1546629c

 

 

 

 

Act Now Training’s Data Protection Practitioner Certificate continues to go from strength to strength. In Autumn 2015, a total of 16 delegates from the local government, health, education and private sectors passed the course with flying colours. 9 delegates achieved a merit and 3 achieved a distinction.

The Information Commissioner, Christopher Graham, said:

“Congratulations to all the successful candidates. It was worth all the slog, as I am sure you will find in your future careers. And it’s good to know that there is another cohort of qualified professionals looking after our data in the increasingly competitive digital world. All organisations need to take data protection and data security seriously or risk losing their reputation – not to mention customers. The new EU data protection framework brings these issues into even sharper focus – which makes your expertise even more essential.”

Over the years this course has produced many satisfied customers:

This was an excellent course specifically designed for the day to day practical use of DP. It demystified the subject in a way which I could understand. Tim Turner is an excellent tutor with a good sound knowledge and ability to put it across. HC, West Yorkshire Police

Tim broke the course down into manageable chunks and gave useful, practical examples that illustrated his points. This course has given me not only the knowledge but also the confidence to improve at my job and make my organisation better too! Thanks Tim! DH, Cheshire West and Chester Council

This course was designed to be more learner friendly in the way it is examined. It shows your practical knowledge in the assessment along with your ability to use the legislation in your project. A worthwhile course for the modern day data protection officer. DJ, Northumberland CC

Since commencing in my role I was expected to develop a knowledge of and interpret the DPA. This course has embedded my understanding of the act and given me the confidence to challenge existing and new practices to ensure compliance.  SD, NYFRS

I would thoroughly recommend the course, which has a sensible, practical focus and deals with the application of an otherwise abstract and complex piece of legislation to real life situations.
AG, Parliamentary and Health Service Ombudsman

The Data Protection Practitioner Certificate is our own qualification for those who work with Data Protection and privacy issues on a day-to-day basis. The course, designed in consultation with a panel of experts from the UK and Europe, takes place over four days (one day per week) and involves lectures, assessments and exercises. This is followed by a written assessment. Candidates are then required to complete a practical project (in their own time) to achieve the certificate.

The emphasis of the course is on practical skills which a Data protection Officer needs to do their job and raise DP standards in their organisation. The course syllabus has been recently revised to include more themes covered by the new European General Data Protection Regulation (GDPR) expected to come into force in 2018.

Candidates also now have the option to take our specially designed GDPR webinars after completion and up to 12 months in the future as part of their course. This has been included for our Certificate candidates free of charge (normally £49+Vat each) allowing them to customise their learning with the greatest flexibility and ensure their preparations for GDPR are assisted with the most up to date information.

To learn more please visit our website or get in touch.

 

Act Now Wins E-Learning Gap Analysis Tender

canstockphoto19900785

 

Act Now is pleased to announce that it has won a contract to deliver consultancy services to a major organisation in the regulatory sector.

We have been asked to use our information law and security expertise to assess the content of the organisation’s mandatory e-learning modules covering the Data Protection Act, Information Security (ISO 27001:2013 certification) and the Freedom of Information Act.

The purpose of the assessment is to ensure that the training content meets the legislative and ISO 27001 (2013) requirements and meets the needs of the organisation’s staff, associates and contractors, providing them with a gap analysis report based on the current training provision, examples of best practice and legislative requirements.

This project will be led by Ibrahim Hasan and Frank Rankin who are well-known experts and trainers in this field. Commenting on the award of the contract, Ibrahim Hasan said:

“I am very pleased to have the opportunity to use our expertise on this project. This is one of many recent consultancy projects Act Now has undertaken and enhances our reputation as one of the UK’s leading providers of in house training and consultancy in information law and information management.”

Act Now is also starting to develop an international reputation. In January 2015 Ibrahim Hasan and Paul Gibbons were in the Far East to deliver data protection audit training to the Government of Brunei.

We have also developed a number of interactive e learning solutions to assist organisations comply with their legislative and regulatory requirements.  With the new EU Data Protection Regulation likely to come into force in 2018, it is important that all organisations assess their staffs’ data protection awareness and compliance.

Please take a moment to browse our in house training and consultancy pages. Feel free to get in touch to discuss your requirements in this area.

A Hard Rain’s a-Gonna Fall

 

clip_image001_thumb.png

 

 

 

 

 

 

 

 

 

 

 

 

The song was written by Bob Dylan in 1962. Dylan has stated that all of the lyrics were taken from the initial lines of songs that he thought he would never have time to write. This blog has had so many working titles (see below) that it seems to fit.

My story starts when I bought a Senior rail card. I did it online. As a fully paid up member of the grumpy old men’s club and having some knowledge of Data Protection and marketing issues I made sure I opted out of any “from time to time we may pass on” and “carefully selected third parties” sneaky data collection statements. The process was easy. The card arrived; I used it frequently.

Then the mailings arrived. It’s my normal practice as a GOM and DPA nerd to contact organisations who direct market me and ask them where they obtained my name and address. I  call it a Subject Access Request in my letter. Over the autumn in surge in mailings revealed that The Association of Train Operating Companies had been the originator of many mailings through their sale of my details to Medialab.

As a side issue it’s remarkable how the marketing industry reacts when I make subject access requests. Their first reaction and often their only reaction is to instantly remove me from their database and apologise profusely. To me this isn’t how to respond to a subject access request. In fact one charity when I queried this said that their industry code of practice only required them to remove my name not provide me with the normal things that SARs provide. When I replied pointing out the relevant sections of the DPA the request was escalated to the CEO who decided that Yes they would go further than the Code of Practice and give me what I asked for. Thanks Chiefie.

On to Medialab. They acknowledge on their website (which is currently being re-designed) that they have many lists including all Rail card holders. The actual phrase is We buy data and media across various channels to generate customers with real lifetime value. The blurb says that Senior rail card holder are all over 60, all opted in and are all suitable targets for offers involving wine, charities, gardening, food etc. Leaving aside the obvious fair processing and reasonable expectations it appears that Medialab and actively pushing their list obtained by ATOC for purpose a for purposes b, c, d  etc. So apart from buying the lists which ATOC says are all consenting adults they are conspiring with service companies who are looking to target their marketing. You could even make a case that Senior Rail card holders are a vulnerable group. When I bought my Rail card I definitely did not consent to receiving offers about wine, charities, gardening, food. Just because I am old doesn’t mean I have to conform to my chronological stereotype. I thought buying a railcard was about cheap train travel. If some one who targets poor obtaining and re-use statements on websites has missed the fact that he has consented to his data being sold on how do ordinary people spot it. (If in fact there was a FPN – ATOC can’t prove they had one…)

Second aside. I was once engaged by a well known cuddly well respected Society with its HQ in London to deliver a training session on Data Protection. They were nice people and the Chief Exec sat supportively in the front row. When we arrived at the point of discussing whether data acquired for purpose A by Data Controller A could not be used for an incompatible purpose B by Data Controller B the chief Exec intoned  “I think you’ll find that most big organisations share data to see if there are any opportunities for cross marketing”. When told that this was probably a breach of the act his support for me ended and he left the room presumably to set up another breach of Principle 2.

Back to ATOC. I kept on at them – they weren’t very punctual but I generously put this down to Xmas holidays. Eventually after me disputing my giving of consent I asked them to provide documentary evidence that I had consented to passing my data to 3rd parties. This elicited the following email.

“I am sorry to hear that you have received emails and phone calls from third parties that you were not expecting. I have reviewed your account and can verify that your name and contact information has now been removed from our supplier database and that only Medialab has access to this. You should no longer receive any emails related to your Railcard purchase.

Unfortunately we are unable to provide material confirmation as to your original acceptance of these offers as once an online application is completed this information is fed directly into our database and this live information serves as confirmation of customer opt-ins. We are able to obtain evidence of opt-ins for paper applications and the equivalent of this for online applications is the live record and your record now reflects your request to be removed from our mailing list.”

To wrap it up. The volume of mailings has slowed down. ATOC has taken me off their list but can’t prove I consented to them selling my details. Marketing companies still hold my data and are probably selling it to anyone who thinks old people are an easy touch. The mailing and marketing industry doesn’t know what a subject access request is.

So I’ll leave you guys to ‘Choose an Alternate title’ (which in itself a 1967 song…)

When is consent not consent? – When you can’t see it

When is consent not consent? – When you can’t prove it

Marketing databases are black holes. Data is irretrievable except for marketing companies.

The invisible consent mystery.

Who do you believe? A data controller who can’t prove he has consent or a data subject who knows he never gave it.

Wanted Old person who likes travel to test an online application form.

Senior Rail Cards on the wrong track.

Pssst! Wanna buy a list of old people who’ll buy anything…

Grumpy old DP expert taken for a train ride.

Charities just don’t get it. Direct marketing organisations know they’re breaking the law but hey! it adds to turnover. Everyone makes money from Senior rail cards.

Of course the new  EU General Data Protection Regulation (GDPR), when it comes into force in 2018, will require a rethink of of how companies obtain and record consent to marketing.

Give your career a boost in 2016 and prepare for GDPR by gaining a qualification.

The Act Now Data Protection Practitioner Certificate is a practical qualification for Data Protection Officers and advisers both in the public and the private sector. Successful candidates will be able to demonstrate that they possess a good knowledge of the law, both the current Data Protection Act as well as the forthcoming EU Data Protection Regulation.

See http://www.actnow.org.uk/dpp

Image credit: http://www.pophistorydig.com/wp-content/uploads/2012/03/Hard-Rain-art-2-280.jpg

Freedom of Information Commission Report

 

FOI Commission photo

 

The Independent Commission on Freedom of Information was established by the Cabinet Office in July last year to examine the operation of the Freedom of Information Act 2000 (FOI) and whether it required any changes. In October I predicted (and I was not alone) that, bearing in mind the Commission’s restricted terms of reference as well the track record of some of its members, it was likely that sweeping restrictions would be made to the UK’s FOI regime.

Thankfully it seems that the Commission has seen sense. Its recent report says FOI is working well and does not need major changes. It does though make twenty-one recommendations, many of which would enhance the Act:

1. A time limit for public interest extensions

That the government legislates to amend section 10(3) to abolish the public interest test extension to the time limit, and replace it instead with a time limit extension for requests where the public authority reasonably believes that it will be impracticable to respond to the request on time because of the complexity or volume of the requested information, or the need to consult third parties who may be affected by the release of the requested information. This time limit extension will be limited to an additional 20 working days only.

2. A time limit for internal reviews

That the government legislates to impose a statutory time limit for internal reviews of 20 working days.

3. Change to Section 77

That the government legislates to make the offence at section 77 of the Act triable either-way.

4. FOI statistics

That the government legislates to impose a requirement on all public authorities who are subject to the Act and employ 100 or more full time equivalent employees to publish statistics on their compliance under the Act. The publication of these statistics should be co-ordinated by a central body, such as a department or the Information Commissioner (IC).

5. FOI disclosure logs

That the government legislates to impose a requirement on all public authorities who are subject to the Act and employ 100 or more full time equivalent employees to publish all requests and responses where they provide information to a requestor. This should be done as soon as the information is given out wherever practicable.

All the above were also recommended by the Justice Select Committee in its Report into Post-Legislative Scrutiny of the Freedom of Information Act 2000 published in July 2012. All were rejected by the Government in its response to that report.

This time, in the Government’s response to the FOI Commission, Mike Hancock MP has said that the Government will issue a revised S.45 Code of Practice setting out what information public authorities with more than 100 full time employees should publish.

6. Senior employees’ information

Public bodies should be required to publish in their annual statement of accounts a breakdown of the benefits in kind and expenses of senior employees by reference to clear categories.

Local authorities already have these obligations in relation to senior staff earning more than £50,000 by virtue of the Local Government Transparency Code.

7: Information Commissioner responsibilities

The government should give the IC (Information Commissioner) responsibility for monitoring and ensuring public authorities’ compliance with their proactive publication obligations.

8. Section 35(1)(a) – Formulation of government policy

The government should legislate to replace section 35(1)(a) with an exemption which will protect information which would disclose internal communications that relate to government policy.

9. Section 35(1)(b) – Ministerial communications

The government should legislate to expand section 35(1)(b) so that, as well as protecting inter-ministerial communications, it protects any information that relates to collective Cabinet decision-making, and repeal section 36(2)(a).

10. Section 35 – Public interest

The government should legislate to amend section 35 to make clear that, in making a public interest determination under section 35(1)(a), the public interest in maintaining the exemption is not lessened merely because a decision has been taken in the matter.

11. Section 35 – Public interest (2)

The government should legislate to amend section 35 to make clear that, in making a public interest determination under section 35, regard shall be had to the particular public interest in the maintenance of the convention of the collective responsibility of Ministers of the Crown, and the need for the free and frank exchange of views or advice for the purposes of deliberation.

The above 4 recommendations are clearly designed to make it easier for the Government (and the National Assembly for Wales) to withhold information. Other bodies cannot claim this exemption anyway.

12. Section 36 – The Qualified Person’s opinion

The government should legislate to amend section 36 to remove the requirement for the reasonable opinion of a qualified person.

Some of our clients have welcomed this recommendation citing the difficulty of getting access to senior officers to make a decision about complex FOI matters.

13. The ministerial veto

The government should legislate to put beyond doubt that it has the power to exercise a veto over the release of information under the Act.

14. The veto again

The government should legislate to make clear that the power to veto is to be exercised where the accountable person takes a different view of the public interest in disclosure. This should include the ability of the accountable person to form their own opinions as to as to all the facts and circumstances of the case, including the nature and extent of any potential benefits, damage and risks arising out of the communication of the information, and of the requirements of the public interest.

15. And again…

The government should legislate so that the executive veto is available only to overturn a decision of the IC where the accountable person takes a different view of the public interest in disclosure. Where a veto is exercised, appeal rights would fall away and a challenge to the exercise of the veto would be by way of judicial review to the High Court. The government should consider whether the amended veto should make clear that the fact that the government could choose to appeal instead of issuing a veto will not be a relevant factor in determining the lawfulness of an exercise of the veto. Until legislation can be enacted, the government should only exercise the veto to overturn a decision of the IC.

16. Guess what this recommendation is about?

The government should legislate to allow the veto to confirm a decision of the IC where the IC upholds a decision of a pubic authority on the public interest in release. This would mean that the right of appeal would fall away and challenge would be instead by way of judicial review.

Strengthening the ministerial veto under section 53 seemed to be a “dead cert” (in betting parlance). In March 2015, the Guardian’s successful challenge to the application of the veto to the disclosure of Prince Charles’ letters to government departments, was confirmed by the Supreme Court. The Government seems to have accepted the Commission’s recommendations for the time being:

“In line with the Commission’s thinking, the government will in future only deploy the veto after an Information Commissioner decision. On the basis that this approach proves effective, we will not bring forward legislation at this stage.”

17. Appeal rights

That the government legislates to remove the right of appeal to the First-tier Tribunal against decisions of the IC made in respect of the Act. Where someone remained dissatisfied with the IC’s decision, an appeal would still lie to the Upper Tribunal. The Upper Tribunal appeal is not intended to replicate the full-merits appeal that currently exists before the IC and First-tier Tribunal, but is limited to a point of law.

Whilst this recommendation will save public authorities money, some commentators (especially journalists) have expressed concern that it hampers appeal rights and makes the appeal mechanism much less accessible than at present to those who do not have the money to instruct lawyers. They have a point; especially when one considers the very real possibility of the government introducing fees for tribunal appeals.

18. Format of responses

That the government legislates to clarify section 11(1)(a) and (c) of the Act so that it is clear that requestors can request information, or a digest or summary of information, be provided in a hard copy printed form, an electronic form, or orally. Where a requestor specifies a specific electronic document format, that request should be granted if the public authority already holds the information in that format, or if it can readily convert it into that format. Where the information requested is a dataset, the requirements at section 11(1A) will apply. The legislation should make clear that the obligations on public authorities to provide information in a particular format extend no further than this.

In my view this is already clear in the legislation and in ICO guidance.

19. The Section 45 code

That the government reviews section 45 of the Act to ensure that the range of issues on which guidance can be offered to public authorities under the Code is adequate. The government should also review and update the Code to take account of the ten years of operation of the Act’s information access scheme.

20. Vexatious requests

That the government provides guidance, in a revised Code of Practice issued under section 45, encouraging public authorities to use section 14(1) in appropriate cases.

21. More money for the ICO

That the government reviews whether the amount of funding provided to the IC for delivering his functions under the Act is adequate, taking into account the recommendations in this report and the wider circumstances.

Much of the above can be implemented without the need for legislation through a revised/additional Section 45 code of practice and guidance. It’s worth remember that the new EU General Data Protection Regulation (GDPR) will also require changes to FOI when it comes into force in 2018; specifically section 40 which make reference to the Data Protection Act 1998 (which the GDPR will replace).

Labour’s Tom Watson has claimed that the FOI Commission was a waste of time and money and has called on the government to publish its costs. If they don’t he will, no doubt, make an FOI request to the Cabinet Office!

We will be discussing this and other recent FOI decisions in our forthcoming FOI workshops and webinars. For those wanting an internationally recognised qualification the BCS Certificate in Freedom of Information starts on 13th April.

Public Health Funerals, Heir Hunters and Freedom of Information

canstockphoto15719562

 

Local authorities are seeing a substantial increase in the number of Freedom of Information (FOI) requests from heir tracing companies for information about those who have had public health funerals. Recent appeal decisions from the Information Commissioner’s Office (ICO) may help to stem the tide.

UK intestacy law states that when someone dies with no will or known family, everything they own passes to the Crown as ownerless property (or ‘Bona Vacantia’). This includes their house, money and personal possessions. Companies who find missing heirs are in a very lucrative business (watch “Heir Hunters” on the BBC). Some require beneficiaries to enter into an agreement to share up to 40% of their inheritance.

In England and Wales, the Bona Vacantia Division (BVD) of the Treasury Solicitor’s Department is responsible for dealing with bona vacantia assets. Everyday BVD publishes an Unclaimed Asset List setting out unclaimed estates which have been recently referred, but not yet administered, and historic cases which have not yet been claimed by entitled relatives. Included in the list is the deceased name, area of death, marital status, place of birth and local authority informant. Sometimes other details will be given (if known) such as spouse’s name, place of marriage and nationality. The list is updated every working day and newly advertised estates appear at the top of the list.

This list is a good starting point for probate researchers but the competition to trace beneficiaries is very fierce and often a number of companies will be trying to trace the same person. That is why such companies often make FOI requests to councils to try and get hold of the information before any of it is passed on to the BVD to publish. If they can identify deceased individuals who may have left a substantial estate, they will have a head start (in tracing the beneficiaries) against their rivals who will not yet be privy to such information.

Many councils have chosen to put a lot of this information on their website; Redbridge, Northampton, Knowsley to name a few. This then allows them to claim the exemption under section 21 of FOI (information is reasonably accessible by other means). Often though the researchers want more than the basic information, which is published by councils.

Of course, where the requested information has been disclosed to the BVD (or is about to be disclosed) and it will appear on the published BVD list, it is open to the council to claim the exemption under section 22 (information intended for future publication). It does not matter that the council will not be publishing the information itself as long as there is a settled intention to publish it on the part of another (in this case the BVD). Section 22 is a qualified exemption and so subject to the public interest test.

Where the information requested by probate researchers is not published, many councils have claimed the exemption in section 31 arguing that disclosure would prejudice the prevention of crime. Some recent ICO appeal decisions lend support to this approach. In a decision involving Barnsley Metropolitan Borough Council (FS50586033) the complainant requested, amongst other things, details of deceased people who had had public health funerals (including names, last known address, date of birth, date of death, date of funeral, and whether the case has been/will be/or even might be referred to the Treasury Solicitor).

The ICO agreed with the council that section 31 applied and it was not in the public interest to disclose the information. Release of personal details of a deceased individual with no known relatives, and no will, may make the assets of that person vulnerable. The assets of the deceased need to be secured and disclosure of the information may lead to the commission of offences (e.g. arson, identity theft etc.) and cause loss to the unsecured estates. In terms of the public interest the Commissioner states (paragraph 38):

“The Commissioner recognises that there is an inherently strong public interest in avoiding likely prejudice to the prevention of crime. The crime in this case would be likely to include a diverse range from anti-social behaviour, criminal damage, arson, organised groups stripping empty properties to identity fraud and the crimes that can be committed using false documents. The Commissioner accepts that tackling issues like these would involve significant public expense and believes it is in the public interest to protect property and to ensure that public resources are used efficiently. He also accepts that there is a strong public interest in avoiding personal distress to the direct victims of the crime and, in the case of crime related to empty properties, to those in the wider neighbourhood who may be affected.”

Similar decisions were made in complaints involving Birmingham City Council (FS50584670) and the London Borough of Bexley FS50583220. I have still not come across a First Tier Tribunal decision on such requests and so the exemptions, especially section 31, have yet to be comprehensively explored.

Some councils have argued that section 41 (Breach of Confidence) may apply to some of the information requested about the deceased. This can only be the case if the information has come from another party and is highly confidential. Section 41 is unlikely to apply to most requests from probate researchers. For a detailed discussion on access to information about the deceased under FOI, read my article and blog post.

Give your career a boost in 2016 by gaining an internationally recognised qualification in FOI. Keep up to date with all the latest FOI decisions by attending our live webinars and FOI workshops.

Monitoring Staff Use of Social Networks: The Human Rights Implications

canstockphoto9076695

According to a recent FOI request made by BBC Radio 5 live, last year there was a rise in the number of UK council staff suspended after being accused of breaking social media rules. Many employers, both in the public and the private sector, now monitor staff use of social media within the office environment. The possibilities are endless but care must be taken not to overstep the legal limits.

All employers have to respect their employees’ right to privacy under Article 8 of the European Convention on Human Rights (ECHR).  This means that any surveillance or monitoring must be carried out in a manner that is in accordance with the law and is necessary and proportionate (see Copland v UK (3rd April 2007 ECHR))

A January 2016 judgment of the European Court of Human Rights show that a careful balancing exercise needs to be undertaken when applying the law (Barbulescu v Romania (application 61496/08). In this case, the employer had asked employees such as the applicant to set up Yahoo! messenger accounts for work purposes. Its policies clearly prohibited the use of such work accounts for personal matters. The employer suspected the applicant of misusing his account, so it monitored his messages for a period during July 2007 without his knowledge.

The employer accused the applicant of using his messenger account for personal purposes; he denied this until he was presented with a 45-page printout of his messages with various people, some of which were of an intimate nature. The employer had also accessed his private messenger account (though it did not make use of the contents).

The applicant was sacked for breach of company policy. When he challenged his dismissal before the courts, his employer relied on the print out of his messages as evidence. He argued that, in accessing and using those personal messages, the employer had breached his right to privacy under Article 8 ECHR.

The Court accepted the applicant’s privacy rights were engaged in this case. However the employer’s monitoring was limited in scope and proportionate. It is reasonable for an employer to verify that employees are completing their professional tasks during working hours. Key considerations were:

  • The emails at the centre of the debate had been sent via a Yahoo Messenger account that was created, at the employer’s request, for the specific purpose of responding to client enquiries.
  • The employee’s personal communications came to light only as a result of the employer accessing communications that were expected to contain only business related materials and had therefore been accessed legitimately.
  • The employer operated a clear internal policy prohibiting employees from using the internet for personal and non-business related reasons.
  • The case highlights the need for companies to have a clear internet and electronic communications policy and the importance of such a policy being communicated to employees.

When monitoring employees, the employer will inevitably be gathering personal data about employees and so consideration also has to be given to the provisions of the Data Protection Act 1998 (DPA). The Information Commissioner’s Office’s (ICO) Employment Practices Code, includes a section on surveillance of employees at work. In December 2014, Caerphilly County Borough Council signed an undertaking after an ICO investigation found that the Council’s surveillance of an employee, suspected of fraudulently claiming to be sick, had breached the DPA.

Compliance with the DPA will also help demonstrate that the surveillance is human rights compliant since protection of individuals’ privacy is a cornerstone of the DPA. Of course the data protection angle will bite harder when the new EU Data Protection Regulation comes into force in 2018. Failure to comply could lead to a fine of up to 20 million Euros or 4% of global annual turnover.

Act Now has a range of workshops relating to surveillance and monitoring both within and outside the workplace. Our products include a RIPA polices and procedures toolkit and e-learning modules.