How Should Public Authorities Handle FOI Requests from Journalists?

Journalists play an essential role in scrutinising the actions of government and public authorities, and in informing the public about decisions and actions that affect their lives. To do this, they often turn to the Freedom of Information Act to obtain information that is not otherwise in the public domain. Yet research by the London School of Economics suggests that journalists’ experience of the FOI process, particularly when dealing with central government, can be characterised by delays, unresponsiveness and refusals on grounds that may be difficult to verify. 

From the perspective of information governance and FOI professionals, however, the picture can look rather different. They are often working under significant resource and workload pressures, while dealing with journalists who may be seeking information against tight publication deadlines or hoping to secure a newsworthy “scoop”. 

So how can public authorities and journalists navigate these competing pressures?
And what can FOI professionals do to handle journalists’ requests in a way that is both legally sound and constructive? 

We answer these questions in episode 9 of the Guardians of Data podcast. 
Ibrahim Hasan was joined by Martin Rosenbaum. Martin spent 16 years at the BBC as the organisation’s leading specialist in using FOI for journalism. Over that time, he broke major stories, trained reporters, and took cases all the way to tribunal hearings.
Martin is also the author of Freedom of Information: A Practical Guidebook . 

Martin’s experience provides some practical lessons for anyone responsible for handling FOI requests from journalists. 

Don’t treat journalists differently 

The first principle is perhaps the most important. A journalist is simply another requester under FOI. 

As Martin explains, FOI gives journalists a legal right to seek information that might otherwise be difficult to obtain. That does not mean every request should be disclosed, but neither should the identity of the requester influence the application of the legislation. For an information governance professional, the task is to apply the law properly, regardless of whether the requester is a journalist, campaigner, researcher or member of the public. 

Good relationships can reduce the FOI burden 

It is tempting to see journalists and FOI officers as being on opposite sides.
Martin’s experience suggests that this is unnecessary. A constructive professional relationship and good communication can actually reducethe workload associated with FOI. 

Communicate early 

One of Martin’s strongest messages is the importance of communication. Journalists often work to publication deadlines. That does not change the statutory requirements of FOI, but it does make prompt communication particularly valuable. From a journalist’s perspective, being contacted on day 19 to clarify something that could have been resolved on day two or three can be extremely frustrating. 

If a request is unclear, contact the journalist as soon as possible. A quick telephone conversation can often establish what the journalist is actually looking for, whether the information is held and how records are organised. It can also prevent the authority spending time searching for information that will not answer the journalist’s question. 

It can also help establish whether information can simply be provided without the need for a formal FOI process. Martin recalls situations where discussions with FOI professionals saved both sides considerable time by identifying information that was not held, explaining terminology or suggesting a more productive approach. 

Don’t confuse sensitivity with exemption 

Some requests from journalists will concern controversial or embarrassing subjects. That is part of the nature of investigative journalism. The potential consequences of publication should not become an informal additional exemption. 

Martin’s own experience demonstrates the value of persistence within the FOI system. Information initially withheld can sometimes be disclosed following an internal review, an ICO investigation or an appeal to the tribunal. He believes that information can sometimes be withheld too broadly at an early stage, with more detailed consideration later resulting in additional disclosure. 

The two rules to remember 

Asked for his best advice, Martin offered two pieces: Think clearly about what you really want and talk to people. These apply to both sides of the FOI process. 

For journalists, a precise request is more likely to produce the information they actually need. For information governance professionals, early communication can make requests easier to understand, search and process. The result is not necessarily less FOI. It is better FOI: a process in which requests are dealt with properly, resources are used sensibly and information that should be in the public domain is made available. And ultimately, that is what FOI is there to achieve. 

Listen to the podcast 

Listen to the full episode 9, in which Martin also discusses his experiences using FOI to investigate government, his battles with other public authorities, taking cases to tribunal, the impact of AI on FOI and what he would like to see FOI change in the future. 

If you want more perspectives on this important topic be sure to check out our other podcast episodes. In Episode 3, Maurice Frankel, the Director of the Campaign for Freedom of Information explains the history of FOI and his views on current and future challenges to the legislation. in Episode 14 barrister, Saara Idelbi, gives advice on handling AI generated information requests. Finally, Episode 17 Ben Worthy discusses the research studies that he has conducted into FOI practice, to give us an insight into the effectiveness of FOI in achieving transparency. We also explore what FOI can (and can’t) achieve and where transparency in the UK might be heading next.

New Podcast: FOI and Transparency in Practice 

In the UK, Freedom of Information laws are now more than 20 years old. If you want to understand how they have impacted the way government operates, there are plenty of clues in the news headlines over the last few years: 

  • The Covid Inquiry gave us an extraordinary insight into how ministers and officials communicated during the pandemic, including the extensive use of WhatsApp. 
  • The Peter Mandleson affair raised questions about the vetting of ministers and civil servants, and more broadly, about what the public is entitled to know about the people exercising public power. 
  • And internationally, the release of the Epstein files demonstrated the enormous public interest in information held by powerful institutions and the political consequences when information is withheld or released. 

In the latest episode of the Guardians of Data podcast we are joined by Dr Ben Worthy, a Reader in Politics and Public Policy at Birkbeck College, University of London. Ben has written extensively on issues around Transparency and Freedom of Information including authoring the book “The Politics of FOI”. Ben discusses the research studies that he has conducted into FOI practice in various sectors, to give us an insight into the effectiveness of FOI in achieving transparency. We also explore what FOI can (and cant) achieve and where transparency in the UK might be heading next. 

Listen on your preferred platform via our podcast page, or download the episode directly.  

If you want more perspectives on this important topic be sure to check out our other podcast episodes. In Episode 3, Maurice Frankel, the Director of the Campaign for Freedom of Information explains the history of FOI and his views on current and future challenges to the legislation. In Episode 9 we talk to Martin Rosenbaum, an 
ex-BBC Journalist, who shares practical tips on dealing with FOI requests from journalists. Finally, in Episode 14 barrister, Saara Idelbi, gives advice on handling AI generated information requests. 

This podcast is sponsored by Phaselaw – a purpose-built solution for document disclosures, like subject access requests and FOI requests. Instead of redacting PDFs one by one, or forcing litigation software to do a job it wasn’t designed for, with Phaselaw you get collection, review, and redaction in one workflow. Teams across the World are using it to cut response times from weeks to days. 

For Guardians of Data listeners, Phaselaw is offering a two-month free trial; run it on live requests, see what it does to your backlog, decide from there. No card, no commitment. 

Head to https://www.phase.law/guardians to claim your free trial.  

Previous episodes of the Guardians of Data podcast have featured Dr. Agnieszka Piotrowska talking about the profound ways that Generative AI is changing human relationships, Professor Kistie Ball talking about employee surveillance without losing trust and Ilyas Nagdee analysing the impact of predictive policing on human rights. 

20 Years of FOI: An Interview with Maurice Frankel  

It is more than 20 years since the Freedom of Information Act came into force. Now more than ever transparency is an important aspect of public life and indeed a democratic necessity.  

In Episode 3 of the Guardians of Data podcast we discussed these issues with our guest was Maurice Frankel OBE, director of the Campaign for Freedom of Information .  

The following is an abridged transcript of the podcast.

Question: What was life like before the Freedom of Information Act? How easy was it to obtain information from the public sector? 

Answer: It was extremely difficult in most cases; unless the information you were asking for, was helpful for the public authorities position, in which case the authority would be prepared to release it. But if you asked for information which might question its position, then it was very difficult to get the information and officials, council leaders and ministers would treat the information as if it was their own personal information, and they’d sometimes be affronted that you would even ask and expect that information to be disclosed. 

What were the other challenges in terms of getting the FOI Act onto the statute books? 

Well, the fact is, the government realized and Tony Blair realised, once the legislation was going through Parliament that, this was something that would cause them problems. And, it came to the point at which, the government privately threatened to pull the FOI Bill from Parliament if further improvements to the bill were made during its parliamentary progress.  

Jack straw, who was the Home Secretary and the Justice Minister, confirmed this in his memoirs; that the government actively considered dropping the FOI Bill, for fear that it had gone too far, that it was providing too much openness; that explains why they put it off for so long. 

You mentioned the cost limit. There was a story recently about an author who had a number of FOI requests about Andrew Mountbatten Windsor refused on costs grounds. Do you think there’s a case here for the cost limit rules to be changed so FOI requests cannot be refused on the grounds of costs if there’s a strong public interest in disclosing the information? 

Well, I think there’s a good case for that. We argued for that when the FOI Bill was going through Parliament because, it was obvious that you had an absolute limit on what could be disclosed based on the time needed to find it, essentially. And there was no way through that. And that limit applied in the same way to a request about the purchase of government stationery and to information the government held about a life threatening disease or potential pandemic. And, the case for treating those differently and recognising the public interest in serious cases, I think is very strong. Now the government will argue that everybody will make a public interest case for disclosure. But everybody does make a public interest case for disclosure of information about commercial interests, law enforcement matters and so on. And the exemption does not, collapse in every case simply because somebody makes that argument. Tt gives way when there is genuine evidence which justifies a disclosure of otherwise exempt information. I think the same could take place if there was a public interest test applying to the cost limit. 

You mentioned previously with regards to inquiries and their power to seek information from government. The Covid inquiries are ongoing. We’ve about the use of unofficial communications such as WhatsApp, Signal and Google Chat by ministers and advisers and in some cases, them using disappearing messages. What does that say to you about attitudes to transparency when it comes to the major decisions, particularly around Covid? 

Well, a chunk of the history will have been lost forever. It may be that there’s enough been recorded, to make up for that in the main areas. But I think the use of auto deletion, or messaging software, is a very unhealthy development. And if it’s possible to prevent officials using it, even where they need to use messaging software for efficiency purposes, they should not be able to use software, which automatically deletes messages once they’ve been read. I think that is inimical to proper record keeping practices, to accountability and to the operation of the Freedom of Information Act. 

Do you think that the fallout from the Epstein Scandal and the Covid Inquiry so far, is going to lead to improvements in government transparency, or is it going to lead to more unrecorded decisions? 

Well, I think the surprising thing is that very embarrassing material has come out of the Post Office Inquiry. For example, about the real reasons for continuing with various practices, despite the fact that it was well known that the Post Office was subject to the Freedom of Information Act and was receiving Freedom of Information requests. So I think what is perhaps more surprising is how much of that information has survived, despite the existence of FOI. I mean, when the Act was being discussed in the early days, the government would argue that people would use post-it notes to record sensitive information so that these could be pulled off the documents when an FOI request was received. And so they believed that the threat of disclosure would prevent anything significant, which could be embarrassing being recorded in a permanent form at all, and that’s not proved to be the case. And I think that is probably because, first of all, the chances, I think officials will recognise that they’re dealing with vast volumes of documents, and very few of those were ever requested under FOI. And that means the ordinary incentive to carry on, recording information in the ordinary way or sending recorded information to colleagues, in the ordinary way, carries on, despite what in practice, maybe a hypothetical possibility of an FOI request being received at some later stage. So the information is, is not that vulnerable, to pre-emptive destruction, to prevent disclosure. I think that is perhaps a reassuring, result of these inquiries. 

I agree with you, Maurice, that having had over twenty years of FOI, we are seeing the government disclosing more information, sometimes embarrassing as well and certainly the inquiry system is disclosing more information perhaps, than the Freedom of Information Act would have allowed. So together, I think I agree we have made progress. But do you think there is still room for improvement? Do you think certain public authorities need to improve more than others? 

Well, I think there’s room for improvement across the board. I think there’s a number of things. I think the first thing is, authorities are sometimes too keen to impute bad motive to a requester, just as requesters are sometimes too keen to impute bad motive to a public authority for withholding information.  

I think a second problem is that, public authorities are not making proper use of Boolean searches,. That is, they’re not searching for search term A combined with search term B, but excluding search term C. They are simply looking for hits under particular search terms and not intelligently, using the ability that their systems in many cases, must have to narrow the request by proper use of the of search language. So I think that needs to be looked at.  

And I also think that the Act itself needs to be amended, to address some of the shortcomings that it creates. And, chief of those is, the reasonable extension to consider the public interest test. So the twenty working days is extendable by an unspecified reasonable period to consider the public interest test. I think that extension should be got rid of, just as the Environmental Information Regulations have got rid of it (and Scotland’s Freedom of Information Act, has never adopted that approach). 

Where do you think FOI is going? If we get a change of government, do you think you’ll be back on the campaign trail trying to save FOI? 

Well, we are always aware of the fact that the Act could come under threat at any time. The number of times we have had to come in and try and defend the Act against attempts by, initially the Blair Administration, then the Coalition Government, Conservative Government, to stop attacks on FOI is remarkable.  

I mean, we had attempts to remove Parliament itself from the scope of the act in the early days. There was an attempt to expand the cost limit so that the cost limit of effectively 18 hours or 24 hours of time spent looking for information would apply not to a single request, or to all similar requests within a sixty working day period, but to all requests by a requester to the same public authority, whether they were related or not. And that would mean that, and not just from the same individual requester, but from the same organisation. So it would mean that major news organisations would be limited to one or two requests to the Home Office in a in a three month period, spread amongst all of their journalists. This was seriously put forward by the Blair Administration in the early days. And so, I don’t underestimate the threat to FOI.  

The most recent serious threat we had was, the government setting up the Independent Commission on Freedom of Information, in the mid-nineties, where the unspoken aim was to remove information about policy making from the scope of FOI altogether. We did a very detailed analysis of all Tribunal decisions over, I think, a sixteen month period, relying on section 35, and showed that in very many cases, the exemption worked as it the government had intended it to work. That is, it protected sensitive discussions, from disclosure even after the decision had been taken. But that in a number of cases where the public interest justified it, that information was disclosed and the Tribunal accepted that that was the exemption and the public interest test working as it was supposed to, and that there should be no change to that that position. And so I think that was a very important milestone in the Act, because that resulted in the government before the final report was published, announcing that it hoped the Independent Commission would not require any weakening of the Freedom of Information Act, whereas a weakening of the Act had been the whole purpose of setting up the Commission 

And just finally, some words of inspiration for our new professionals please Maurice. 

Try and understand what the rationale for bringing FOI in actually was, and that was that openness serves the public interest. It serves the interest of accountability. It deters bad practice and it exposes unacceptable conduct. Those are all things which authorities, should be endorsing. And the FOI officers in particular, should see that as the benefit of freedom of information. And in my own experience where I’ve been provided information in the right spirit, it does change your view of the authority you’re dealing with. It does make you more willing to accept what they tell you, and more willing to have confidence in their decisions. It increases public trust in the organisation which can only be a good thing.  

You can listen to the full  Episode 3 podcast with Maurice here. 

ICO to Review Public Sector GDPR Compliance Enforcement Approach

In June 2022, the Information Commissioner’s Office (ICO) revised its approach to enforcement of the UK GDPR against public sector organisations.  The two-year trial was announced in an open letter from the Information Commissioner, John Edwards, to public authorities in which he indicated that greater use would be made of the ICO’s wider powers, including warnings, reprimands and enforcement notices, with fines only issued in the most serious cases. Mr Edwards said:

“I am not convinced large fines on their own are as effective a deterrent within the public sector. They do not impact shareholders or individual directors in the same way as they do in the private sector but come directly from the budget for the provision of services. The impact of a public sector fine is also often visited upon the victims of the breach, in the form of reduced budgets for vital services, not the perpetrators. In effect, people affected by a breach get punished twice.”

This new approach has seen the Commissioner over the last two years issue more reprimands than fines. One example of this approach was the issuing of reprimand to the Department for Education (DfE) following its misuse of the personal data of up to 28 million children. The ICO said at the time that, had the new trial approach not been in place, the DfE would have been issued with a fine of over £10 million. Some would say that the DFE got off very lightly and, given their past record, perhaps more stringent sanctions should have been imposed. Two years ago, the ICO criticised the DfE for secretly sharing children’s personal data with the Home Office, triggering fears it could be used for immigration enforcement as part of the government’s hostile environment policy.

More recently the ICO was criticised for only issuing a  reprimand to the Electoral Commission following the discovery that unspecified “hostile actors” had managed to gain access to copies of the electoral registers, from August 2021. Hackers also broke into its emails and control systems. The Commission estimated the register for each year contained the details of around 40 million people. The ICO reprimand revealed that the Commission did not take basic security steps to ensure the protection of personal data.

On 26th June 2024, the ICO announced that it will now review the two-year trial before making a decision on the public sector approach in the autumn. It will be interesting to see whether the ICO views the approach as a success and if it will be continued or even extended to the private sector.

Enjoy reading our blog? Help us reach 10,000 subscribers by subscribing today!

This and other data protection developments will be discussed in detail on our forthcoming  GDPR Update  workshop.

Common FOI Requests By Sector

Despite the General Election, its business as usual for FOI practitioners. In fact many will report an increase in FOI requests. Understanding what requestors are interested in can help FOI practitioners to consider whether proactive publication of this information would benefit their organisation and help to reduce information requests. 

Working with WhatDoTheyKnow (WDTK), the ICO have analysed a sample of more than 150,000 requests made during 2022 and identified common themes in the information that has been requested. This has been broken down into 5 sectors:

Health

  • Meetings, committees, and minutes
  • Data and statistics
  • Complaints 
  • Recruitment and staffing information, including fuel allowance and travel costs
  • Policies
  • Mental health care

Local Government 

  • Highways, roads and parking  
  • Bus lanes and bus services
  • Children, schools and care
  • Housing and planning
  • Contracts
  • Internal correspondence
  • Asbestos

Education 

  • Admissions
  • Grades, scores and results 
  • Management and finances 
  • Economics, law, engineering, science and medicine courses.

Central Government 

  • Data and statistics
  • Correspondence and communications
  • Meetings
  • Covid-19
  • Costs

Emergency Services 

  • Statistical information
  • Hate crimes, crimes of a sexual nature, assault, and stalking
  • Vehicle and fleet 
  • Roads and speed limits

The ICO says that understanding the public’s information needs can better equip public authorities to meet one of the challenges set out in their recent open letter to senior leaders: ‘… look at what people are asking you about and actively publish it.’ Proactive publication also leads to greater transparency and could decrease the number of information requests public authorities receive.

Our FOI Exemptions workshop is ideal for FOI Officers who want to develop their knowledge of the exemptions and sharpen their Refusal Notice writing skills.

Lessons On Transparency: The ICO Experian Appeal

The Information Commissioner’s Office recently lost its appeal in the Upper Tribunal in relation to an Enforcement Notice issued to Experian.  

The concerned Experian’s marketing arm, Experian Marketing Services (EMS) which provides analytics services for direct mail marketing companies. It obtains personal data from three types of sources; publicly available sources, third parties and Experian’s credit reference agency (CRA) business. The company processes this personal data to build profiles about nearly every UK adult. An individual profile can contain over 400 data points. The company sells access to this data to marketing companies that wish to improve the targeting of their postal direct marketing communications 

On 20th February 2023, the First-Tier (Information Rights) Tribunal (FTT) overturned an ICO Enforcement Notice issued to Experian. The notice alleged several GDPR violations namely; Art. 5(1)(a) (Principle 1, Lawfulness, fairness, and transparency), Art. 6(1) (Lawfulness of processing) and Art. 14 (Information to be provided where personal data have not been obtained from the data subject). For more detail of the FTT judgement read our earlier blog here. 

On 23rd April 2024, the Upper Tribunal dismissed the ICO’s appeal against the FTT’s judgment. This can be read here along with a useful press summary. The Upper Tribunal backed the FTT’s conclusions while repeatedly criticising its unclear reasoning. 

The broader value of the judgment lies in its guidance, for the first time at this level, of what the transparency requirement under the UK GDPR involves (see paragraph 95). It also sets out its views on the current data protection landscape more generally. 5 Essex Court have a good summary of the judgement on their website.  

The ICO’s has issued a (“Let’s look on the bright side”) statement stating that: 

“The ICO will take stock of today’s judgment and carefully consider our next steps, including whether to appeal.” 

This and other data protection developments will be discussed in detail on our forthcoming  GDPR Update  workshop. 

Transparency in Health and Social Care: New ICO Guidance 

Within the health and social care sector, new technologies that use large amounts of personal data are being used to support both direct care and secondary purposes, such as planning and research. An example is the the use of AI to provide automated diagnoses based on medical imaging data from patients. 

Transparency is a key principle of UK Data Protection legislation. Compliance with the first data protection principle and Article 13 and 14 of the UK GDPR ensures that data subjects are aware of how their personal data is used, allowing them to make informed choices about who they disclose their data to and how to exercise their data rights. 

On Monday the Information Commissioner’s Office (ICO) published new guidance to assist health and social care organisations to comply with their transparency obligations under the UK GDPR. It supplements existing ICO guidance on the principle of transparency and the right to be informed. 

The guidance is aimed at all organisations, including from the private and third sector, who deliver health and social care services or process health and social care information. This includes local authorities, suppliers to the health and social care sector, universities using health information for research purposes and others (e.g. fire service, police and education) that use health information for their own purposes. The guidance will help them to understand the definition of transparency and assess appropriate levels of transparency, as well as providing practical steps to developing effective transparency information. 

This and other data protection developments will be discussed by Robert Bateman in our forthcoming GDPR Update workshop. We have also just launched our new workshop, Understanding GDPR Accountability and Conducting Data Protection Audits.   

Experian’s GDPR Appeal: Lawfulness, Fairness, and Transparency

On 20th February 2023, the First-Tier (Information Rights) Tribunal (FTT) overturned an Enforcement Notice issued against Experian by the Information Commissioner’s Office (ICO). 

This case relates to Experian’s marketing arm, Experian Marketing Services (EMS) which provides analytics services for direct mail marketing companies. It obtains personal data from three types of sources; publicly available sources, third parties and Experian’s credit reference agency (CRA) business. The company processes this personal data to build profiles about nearly every UK adult. An individual profile can contain over 400 data points. The company sells access to this data to marketing companies that wish to improve the targeting of their postal direct marketing communications. 

The ICO issued an Enforcement Notice against Experian in April 2020, alleging several GDPR violations namely; Art. 5(1)(a) (Principle 1, Lawfulness, fairness, and transparency), Art. 6(1) (Lawfulness of processing) and Art. 14 (Information to be provided where personal data have not been obtained from the data subject). 

Fair and Transparent Processing: Art 5(1)(a) 

The ICO criticised Experian’s privacy notice for being unclear and for not emphasising the “surprising” aspects of Experian’s processing. It ordered Experian to: 

  • Provide an up-front summary of Experian’s direct marketing processing. 
  • Put “surprising” information (e.g. regarding profiling via data from multiple sources) on the first or second layer of the notice. 
  • Use clearer and more concise language. 
  • Disclose each source and use of data and explain how data is shared, providing examples.  

The ICO also ordered Experian to stop using credit reference agency data (CRA data) for any purpose other than those requested by Data Subjects. 

Lawful Processing: Arts. 5(1)(a) and 6(1) 

All processing of personal data under the GDPR requires a legal basis. Experian processed all personal data held for marketing purposes on the basis of its legitimate interests, including personal data that was originally collected on the basis of consent. Before relying on legitimate interests, controllers must conduct a “legitimate interests assessment” to balance the risks of processing the risks. Experian had done this, but the ICO said the company had got the balance wrong. It ordered Experian to: 

  • Delete all personal data that had been collected via consent and was subsequently being processed on the basis of Experian’s legitimate interests. 
  • Stop processing personal data where an “objective” legitimate interests assessment revealed that the risks of the processing outweigh the benefits. 
  • Review the GDPR compliance of all third parties providing Experian with personal data. 
  • Stop processing any personal data that has not been collected in a GDPR-compliant way. 

Transparency: Art. 14 

Art. 14 GDPR requires controllers to provide notice to data subjects when obtaining personal data from a third-party or publicly available source. Experian did not do provide such notices relying on the exceptions in Art 14. 

Where Experian had received personal data from third parties, it said that it did not need to provide a notice because “the data subject already has the information”. It noted that before a third party sent Experian personal data, the third party would provide Data Subjects with its own privacy notice. That privacy notice would contain links to Experian’s privacy notice.
Where Experian had obtained personal data from a publicly available source, such as the electoral register, it claimed that to provide a notice would involve “disproportionate effort”. 

The ICO did not agree that these exceptions applied to Experian, and ordered it to: 

  • Send an Art. 14 notice to all Data Subjects whose personal data had been obtained from a third-party source or (with some exceptions) a publicly available source. 
  • Stop processing personal data about Data Subjects who had not received an Art. 14 notice. 

The FTT Decision  

The FTT found that Experian committed only two GDPR violations: 

  • Failing to provide an Art. 14 notice to people whose data had been obtained from publicly available sources. 
  • Processing personal data on the basis of “legitimate interests” where that personal data had been originally obtained on the basis of “consent” (by the time of the hearing, Experian had stopped doing this). 

The FTT said that the ICO’s Enforcement Notice should have given more weight to:  

  • The costs of complying with the corrective measures. 
  • The benefits of Experian’s processing. 
  • The fact that Data Subjects would (supposedly) not want to receive an Art. 14 notice. 

The FTT overturned most of the ICO’s corrective measures. The only new obligation on Experian is to send Art. 14 notices in future to some people whose data comes from publicly available sources. 

FTT on Transparency 

Experian had improved its privacy notice before the hearing, and the FTT was satisfied that it met the Art. 14 requirements. It agreed that Experian did not need to provide a notice to Data Subjects where it had received their personal data from a third party. The FTT said that “…the reasonable data subject will be familiar with hyperlinks and how to follow them”.
People who wanted to know about Experian’s processing had the opportunity to learn about it via third-party privacy notices. 

However, the FTT did not agree with Experian’s reliance on the “disproportionate effort” exception. In future, Experian will need to provide Art. 14 notices to some Data Subjects whose personal data comes from publicly available sources. 

FTT on Risks of Processing 

An ICO expert witness claimed that Experian’s use of CRA data presented a risk to Data Subjects. The witness later admitted he had misunderstood this risk. The FTT found that Experian’s use of CRA data actually decreased the risk of harm to Data Subjects. For example, Experian used CRA data to “screen out” data subjects with poor credit history from receiving marketing about low-interest credit cards. The FTT found that this helped increase the accuracy of marketing and was therefore beneficial. As such, the FTT found that the ICO had not properly accounted for the benefits of Experian’s processing of CRA data. 

The ICO’s Planned Appeal 

The FTT’s decision focuses heavily on whether Experian’s processing was likely to cause damage or distress to Data Subjects. Because the FTT found that the risk of damage was low, Experian could rely on exceptions that might not have applied to riskier processing.  

The ICO has confirmed that it will appeal the decision. There are no details yet on their arguments but they may claim that the FTT took an excessively narrow interpretation of privacy harms. 

This and other data protection developments will be discussed in detail on our forthcoming  GDPR Update  workshop. There are only 3 places left on our next Advanced Certificate in GDPR Practice.  

New DP and IG Practitioner Apprenticeship

Act Now Training has teamed up with Damar Training on materials and expertise underpinning its new Data Protection and Information Governance Practitioner Level 4 Apprenticeship.

The apprenticeship, which received final approval in March, will help develop the skills of those working in the increasingly important fields of data protection and information governance. 

With the rapid advancement of technology, there is a huge amount of personal data being processed by organisations, which is the subject of important decisions affecting every aspect of people’s lives. This poses significant legal and ethical challenges, as well as the risk of incurring considerable fines from regulators for non compliance. 

This apprenticeship aims to develop individuals into accomplished data protection and information governance practitioners with the knowledge, skills and competencies to address these challenges.

Ibrahim Hasan, Director of Act Now, said:

“We are excited to be working Damar Training to help deliver this much needed apprenticeship. We are committed to developing the IG sector and encouraging a diverse range of entrants to the IG profession. We have looked at every aspect of the IG Apprenticeship standard to ensure the training materials equip budding IG officers with the knowledge and skills they need to implement the full range of IG legislation in a practical way.”

Damar’s managing director, Jonathan Bourne, added:

“We want apprenticeships to create real, long-term value for apprentices and organisations. It is vital therefore that we work with partners who really understand not only the technical detail but also the needs of employers.

Act Now Training are acknowledged as leaders in the field, having recently won the Information and Records Management Society (IRMS) Supplier of the Year award for the second consecutive year. I am delighted therefore that we are able to bring together their 20 years of deep sector expertise with Damar’s 40+ year record of delivering apprenticeship in business and professional services.”

This apprenticeship has already sparked significant interest, particularly among large public and private sector organisations and professional services firms. Damar has also assembled an employer reference group that is feeding into the design process in real time to ensure that the programme works for employers.

The employer reference group met for the first time on May 25. It included industry professionals across a variety of sectors including private and public health care, financial services, local and national government, education, IT and data consultancy, some of whom were part of the apprenticeship trailblazer group.

If your organisation is interested in the apprenticeship please get in touch with us to discuss further.

Reflections of an Act Now FOI Trainer

People in a meeting

Susan Wolf writes…

They say time flies when you are having fun. Well, I must have been having fun because I can’t quite believe I have been training with Act Now for over 12 months. Really where has the time gone? During my time at the University of Northumbria I developed the habit of keeping a journal in which I reflected on my teaching. Old habits die hard and I have continued this practice now that I am a regular Act Now training consultant. Looking back over my journal for the last 12 months a number of common themes became apparent. I thought it might be interesting to share these. However before I do, I just want to thank all the delegates I have met for challenging me, keeping me on my toes and reminding me how interesting life can be in Freedom of Information Land.

Training practitioners is not something new to me. For over 11 years I taught FOI practitioners on the Northumbria University LLM in Information Rights Law & Practice Degree. However, the Act Now courses, with their focus on practical training have exposed me to a wider range of people, from a wide range of public sector organisations, all trying to get to grips with broadly similar issues. From the most experienced practitioner who wants a ‘top up course’ to the absolute beginner who has just landed their first job in information rights, all practitioners appear to share some common concerns and worries.

There are also some widely shared misconceptions which still seem to cause the odd debate, despite the Freedom of Information Act 2000 being almost 15 years old. For instance, I have heard some delegates say that the ‘clock start’s ticking’ on a FOI request on the day it is received by a public authority. I have also heard delegates talk about fines that the ICO can impose for breaches of the Freedom of Information Act. Those are always good to correct, and it is nice to hear the sigh of relief when they are advised correctly on these points.

However, I also frequently get asked questions that there are, quite simply, no definitive answers to. In good ‘lawyer’ tradition I could say ‘well that depends’ but that isn’t always what people want to hear. For example, I have been asked questions about how far a public authority must go in advising and assisting an applicant, or how many times they need to go back to the applicant to clarify a tricky request. Another question that taxes people is how long it is reasonable to wait between requests before engaging S. 14 (2) for repeated requests. These are always good for some discussion, but often time is limited on a one-day course, particularly when delegates quite rightly expect we cover all the course content.

Other misconceptions or worries centre on issues relating to the redaction of staff names in email correspondence; how to distinguish between ‘business as usual’ questions and FOI requests; or the significance of ‘confidentiality’ markings on information provided by third party contractors. The ‘new’ Freedom of Information 2018 Code of Practice addresses some of these issues. However not all FOI practitioners are necessarily aware of the provisions of the new Code. Of course, it is difficult for practitioners, who are undoubtedly over-burdened, to keep up to date and on top of things, or indeed for us to cover these issues in detail in a one-day course. One way of keeping up to date is to read our Act Now blogs, which are all written by Act Now consultants and which deal with new developments and case law. However, this journey of reflection has made me realise that it would be useful to write some ‘Back to Basics’ blogs that address some of the issues and concerns that I know FOI practitioners share. Over the coming months we will be publishing a series of ‘FOI Basics Blogs’ on the issues raised during our one-day FOI courses starting with a blog on ‘Business as Usual or FOI Request’?

For those FOI practitioners who want to take their training and understanding to the next level, Act Now Training now offer a 4-day FOI Practitioner Certificate this course is modelled on the highly successful GDPR Practitioner Certificate and was launched in May 2019. We have now delivered it seven times and it is absolutely clear this model enables FOI practitioners to develop a more detailed knowledge and understanding of the FOI in practice. It gives delegates the chance to explore the exemptions in far more detail over two days, with Day 3 focussing on the most frequently used exemptions, including Sections 40 and 43. The course also prepares delegates for writing a Refusal Notice which forms part of the final assessment.

Delegates have given very positive feedback:

“The course was very well structured and well timed. The length of the course was ideal as this gave sufficient time to discuss all areas relating to FOI and also gave candidates ample time for discussion and study. The trainer was very supportive and the knowledge that has been imparted has enabled me to develop the FOI function with our organisation. Highly Recommended.”
JW, Heywood Middleton and Rochdale NHS

“The course was excellent and really sets you up for the exam, I would recommend it to others working in the field. I have put what I learned on the course to good use as I am a FOI and DPA Manager in a very busy post with lots of business each and every day; many of the requests are unusual. The course and now passing the exam have given me the confidence to do my job.”
JH, NI Courts and Tribunals Service

“Thank you for a great course – as always all the trainers at Act Now are extremely knowledgeable, approachable and make the learning experience really enjoyable.”
KF, St Helens Council

As you can see Delegates are enjoying the course content and delivery style. Most importantly they are able to take away their gained knowledge and apply it to their everyday role with confidence. After all, that is the purpose and objective of a course such as this. It makes me immensely proud and pleased to be able to be a part of the team that helps delegates in this way everyday and I look forward to the next 12 months.

Susan Wolf is a trainer for Act Now Training. She has over ten years experience teaching information rights practitioners on the LLM Information Rights Law & Practice at Northumbria University. All our trainers are available to deliver customised in house training, health checks and audits. Please read the testimonials from satisfied clients and get in touch for a quote.