GDPR: The Data Protection Principles (but not as you know them Jim!)

canstockphoto16138153

Having recently attended the Information Commissioner’s Office Data Protection Practitioners Conference in Manchester, I should start this blog post by echoing the words of our outgoing Commissioner, Christopher Graham, that the Regulation text is not the final version until later this year when it has been reviewed and fully translated for all 28 member states.

But as the Regulation is unlikely to change in material terms, let’s crack on!

Whenever you see blogs and articles about the new EU General Data Protection Regulation, they are often focusing on what’s new and “exciting”, be that in a good or bad context (see our summary here). But this blog post will look at some of the things that are remaining familiar, albeit in an edited ‘reshuffled’ form.

So let’s go back to basics – the Data Protection Principles. Now under the current Data Protection Act 1998 there are 8 principles that cover things from legitimate purpose to retention and security. Under the Regulation these are changing. Chapter 2, Article 5 (1) (a)-(f) now outlines the principles:

“Personal Data shall be;

1, processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’);

2, collected for specified, explicit and legitimate purposes and not further processed in a a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes; (‘purpose limitation’);

3, adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’);

4, accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’);

5, kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 83(1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (‘storage limitation’);

6, processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’);”

Now while the Regulation text doesn’t specifically say “principle 1” etc. it does confirm these as the principles and it is logical to assign numbers (as opposed to A,B,C). Principle A just doesn’t have the same ring to it as, “the first principle”. I suspect that these will now become known by their subject matter, so for example you would have “the accuracy principle” and “the data minimisation principle.”

You will notice that we are also down to 6 principles from our current 8 under the DPA. The 2 “missing principles” have been amalgamated in to the new 6 principles. All the current requirements in the 8 principles are still here but they are now outlined in the finer detail of the text. So, for example, principle 6 in the DPA  (“processed in accordance with data subjects rights”) is not specifically called out as a principle in the Regulation but it is outlined in Ch2 Art 5 (1) (a) that information will be processed in a “fair and transparent manner”. The requirements of which, outlined in the rest of the Regulation, require Data Controllers (and indeed processors) to ensure that Data Subjects can exercise their rights as outlined in the text in Chapter 3.

The same applies to the current principle 8 of the DPA 1998 “not transferred to a country outside of the EEA without adequate protections” principle. Because the ‘protections’ are outlined in other principles (Chapter 4, section 2 (Security) for example) and the regulatory nature of the Regulation, it is expected that as part of your processing under the other principles you will share data internationally in the correct fashion.

As the saying goes, the devil is indeed in the detail with this Regulation. In this document I’ve put the relevant sections into the principles to which they relate. There is some overlap but generally if you’re talking about principle 1, then the references are all sections of the text that are relevant to some degree. This list is by no means exhaustive but it does give you a view as to how the principles are intertwined into the detailed text.

In the next few posts I’ll be exploring these principles more and some of the related requirements to see what this means in practice and what further location specific standards we should be on the watch for.

Scott Sammons is an Information Risk and Security Officer in the Medico-Legal Sector and blogs under the name @privacyminion. Scott is on the Exam Board for the Act Now Data Protection Practitioner Certificate.

Read more about the EU Data Protection Regulation and attend our full day workshop.

Public Health Funerals, Heir Hunters and Freedom of Information

canstockphoto15719562

 

Local authorities are seeing a substantial increase in the number of Freedom of Information (FOI) requests from heir tracing companies for information about those who have had public health funerals. Recent appeal decisions from the Information Commissioner’s Office (ICO) may help to stem the tide.

UK intestacy law states that when someone dies with no will or known family, everything they own passes to the Crown as ownerless property (or ‘Bona Vacantia’). This includes their house, money and personal possessions. Companies who find missing heirs are in a very lucrative business (watch “Heir Hunters” on the BBC). Some require beneficiaries to enter into an agreement to share up to 40% of their inheritance.

In England and Wales, the Bona Vacantia Division (BVD) of the Treasury Solicitor’s Department is responsible for dealing with bona vacantia assets. Everyday BVD publishes an Unclaimed Asset List setting out unclaimed estates which have been recently referred, but not yet administered, and historic cases which have not yet been claimed by entitled relatives. Included in the list is the deceased name, area of death, marital status, place of birth and local authority informant. Sometimes other details will be given (if known) such as spouse’s name, place of marriage and nationality. The list is updated every working day and newly advertised estates appear at the top of the list.

This list is a good starting point for probate researchers but the competition to trace beneficiaries is very fierce and often a number of companies will be trying to trace the same person. That is why such companies often make FOI requests to councils to try and get hold of the information before any of it is passed on to the BVD to publish. If they can identify deceased individuals who may have left a substantial estate, they will have a head start (in tracing the beneficiaries) against their rivals who will not yet be privy to such information.

Many councils have chosen to put a lot of this information on their website; Redbridge, Northampton, Knowsley to name a few. This then allows them to claim the exemption under section 21 of FOI (information is reasonably accessible by other means). Often though the researchers want more than the basic information, which is published by councils.

Of course, where the requested information has been disclosed to the BVD (or is about to be disclosed) and it will appear on the published BVD list, it is open to the council to claim the exemption under section 22 (information intended for future publication). It does not matter that the council will not be publishing the information itself as long as there is a settled intention to publish it on the part of another (in this case the BVD). Section 22 is a qualified exemption and so subject to the public interest test.

Where the information requested by probate researchers is not published, many councils have claimed the exemption in section 31 arguing that disclosure would prejudice the prevention of crime. Some recent ICO appeal decisions lend support to this approach. In a decision involving Barnsley Metropolitan Borough Council (FS50586033) the complainant requested, amongst other things, details of deceased people who had had public health funerals (including names, last known address, date of birth, date of death, date of funeral, and whether the case has been/will be/or even might be referred to the Treasury Solicitor).

The ICO agreed with the council that section 31 applied and it was not in the public interest to disclose the information. Release of personal details of a deceased individual with no known relatives, and no will, may make the assets of that person vulnerable. The assets of the deceased need to be secured and disclosure of the information may lead to the commission of offences (e.g. arson, identity theft etc.) and cause loss to the unsecured estates. In terms of the public interest the Commissioner states (paragraph 38):

“The Commissioner recognises that there is an inherently strong public interest in avoiding likely prejudice to the prevention of crime. The crime in this case would be likely to include a diverse range from anti-social behaviour, criminal damage, arson, organised groups stripping empty properties to identity fraud and the crimes that can be committed using false documents. The Commissioner accepts that tackling issues like these would involve significant public expense and believes it is in the public interest to protect property and to ensure that public resources are used efficiently. He also accepts that there is a strong public interest in avoiding personal distress to the direct victims of the crime and, in the case of crime related to empty properties, to those in the wider neighbourhood who may be affected.”

Similar decisions were made in complaints involving Birmingham City Council (FS50584670) and the London Borough of Bexley FS50583220. I have still not come across a First Tier Tribunal decision on such requests and so the exemptions, especially section 31, have yet to be comprehensively explored.

Some councils have argued that section 41 (Breach of Confidence) may apply to some of the information requested about the deceased. This can only be the case if the information has come from another party and is highly confidential. Section 41 is unlikely to apply to most requests from probate researchers. For a detailed discussion on access to information about the deceased under FOI, read my article and blog post.

Give your career a boost in 2016 by gaining an internationally recognised qualification in FOI. Keep up to date with all the latest FOI decisions by attending our live webinars and FOI workshops.

I Don’t Believe It! Fees for FOI Tribunal Appeals

Just when you thought FOI was safe (“Oh no we didn’t! Not after that Cabinet Office packed the new FOI Commission with people who don’t particularly care about FOI”, I hear you say), The Ministry of Justice has announced a consultation into changes to fees for, amongst others, FOI appeals at tribunal stage.

If the proposal goes ahead, it will cost £100 to apply for an appeal to the First Tier Tribunal (Information Rights) or the Upper Tribunal (if the case is transferred), and £500 for an oral hearing. Christopher Knight of 11 KBW has produced a helpful summary in this post on the Panopticon Blog.

This proposal is not a great surprise. In July 2012, the Justice Select Committee published its Report into Post-Legislative Scrutiny of the Freedom of Information Act 2000. The Government published its official response in December 2012 and paragraph 24 mentioned the possibility of introducing tribunal fees despite the Committee never suggesting it.

Introducing tribunal fees is clearly an attempt to curtail the public’s right to know in the guise of cost saving. The Campaign for Freedom of Information are mounting a vigorous defence of FOI. We should all try and contribute. Readers can also sign the 38 Degrees Petition to protect FOI laws.

Tribunal fees will have a big impact on the number of challenges to public authority decisions. Overworked FOI Officers may initially see cause for celebration. However if fewer appeals are heard the quality of FOI caselaw on important matters of interpretation will suffer. Consequently application of the FOI exemptions, as well as other provision, will become more difficult. This alone is a good reason for a robust response to the consultation from the public sector.

The consultation paper and the impact assessment on tribunal fees are both on the Ministry of Justice website. The deadline for responses is 15th September 2015.

What else is afoot for FOI? I looked into my crystal ball, after the election, to predict how FOI could change now we have a Conservative majority government. It will be interesting to see how many of my predictions come true when the FOI Commission reports back in November.

Don’t forget on 18th July 2015 the new Re-use of Public Sector Information Regulations 2015 (ROPSI) came into force, replacing the 2005 version. They contain some important changes to the UK public sector information re use regime.

Ibrahim Hasan will be reviewing the latest FOI developments and caselaw in detail, in our forthcoming FOI Update webinar.

Open the Floodgates! Water Companies Subject to EIR

On 23rd February 2015, the Upper Tribunal ruled that water companies are subject to the Environmental Information Regulations 2004 (EIR).

In Fish Legal v Information Commissioner and others [2015] UKUT 0052 (AAC) the Tribunal, applying the previous ruling of the Court of Justice of the European Union (ECJ) from December 2013 (Fish Legal and Emily Shirley v Information Commissioner, United Utilities Water plc, Yorkshire Water Services Ltd, Southern Water Services Ltd), ruled that that water companies are covered by EIR by virtue of their “special powers”. However the Tribunal rejected an argument that they were public authorities by virtue of the fact that they are under the control of other public authorities, such as OFWAT or the Environment Agency.

It’s a complex and the lengthy judgment. Those advising water companies need to read (and re read) all sixty pages. It could have widespread implications for other private organisations that are running public services, such as the electricity, gas, rail and telecommunications industries. However, the Upper Tribunal refused to lay down general principles for when the EIR would apply to such bodies.

It could be that the next round of this lengthy battle will see the parties square up in the Court of Appeal. Then again Thames Water and United Utilities (one of the parties to the appeal) seem to have changed their websites following this ruling to say that they are now covered by EIR and advising what to do to make a request.

The CON29 Drainage and Water Enquiry provides information regarding water and sewerage services for prospective property buyers. This has been a good source of income for the water companies who enjoy an almost monopoly over the information. Could personal search companies now turn their attention to water companies and try to obtain access to this information with a view to providing their own water and drainage search reports? If the battle over Con29 Local Land Charges information held by councils is anything to go by (currently at the ECJ for a preliminary ruling), EIR geeks are in for a treat!

We will be discussing these and other recent EIR developments in our EIR workshops.

The ICO and Seven Shades of Grey

If you’ve nothing to do at lunchtime and you’re an experienced DP person try the ICO quiz on the difference between Data Controllers and Data Processors. You can find it here. After all it’s not a hard quiz. Data Controllers determine the purpose and own the data; data processors just do as they’re told. For years we’ve had this easy to understand relationship and many organisations have outsourced some work involving personal data, drawn up the contract, monitored the performance of it and we all knew where we were. Data Controllers were liable for any problems and Data Processors just did as they were instructed.

Recent guidance from the ICO changes this. Instead of clear yes/no and black/white definitions the commissioner recommends that each relationship with another person processing your data is examined to see how much influence the other person has over how the data is processed. As a result there are no easy answers. Just some shades of grey.

If you are eager to do the quiz and go for it without reading the guidance prepare yourself for a shock. Better DP experts than yourself have taken the test and not performed at all well.

The guidance is well meaning but bends over backwards to accommodate every possible possibility that it’s not that useful.

Image credit www.jimbanks.com

The new EU Data Protection Regulation; Shoulda, Woulda, Coulda?

MC900440392

On the 13th March 2014 the European Union (EU) Parliament voted with an overwhelming majority to approve a new Data Protection Regulation within the EU. Voting on the initial text that was put forward by the Commission, and not the text put forward by the LIBE committee, the EU Parliament seem to have taken a “middle path” with regards to how this Regulation should work. Many of the Commission’s proposed appointed powers have gone, there doesn’t appear to be any “strict” provisions in there that the LIBE committee would have wanted and yet this approved draft is proposing a comprehensive and different world for Data Protection.

A fully updated draft has not been released by the EU as yet so I went through the painstaking task of making the edits confirmed by the EU to the original commission text. I can safely say I won’t be doing that again and once the approved draft is published I highly recommend that you read through from the beginning to get a flavour of where the regulation is heading and the wording used. I have however pulled out some of the highlights below for general consumption. Before I start however, I will declare that I am from the private sector but as Data Protection & Privacy is more than just a job for me (it’s a passion) I’m not one of those people that have campaigned against it (even if I think some if it is just barmy in my humble opinion).

For those that have worked only with the UK Data Protection Act this new world comes as a bit of a shock. Instead of a principle based approach the current regulation is more of a “financial regulation” with specific stances, requirements and demonstrations that certain things are occurring within an entity. For example, Point 60 requires Data Controllers to demonstrate and ensure compliance with the regulation, with a new sentence stating “this should be verified by independent internal or external auditors”.

However having said that, the EU Parliament have edited Point 65, so that it clears up the “administrative burden” query (or tries to) by stating that yes controllers must demonstrate compliance with the regulation however “equal emphasis and significance should be placed on good practice and compliance and not just the completion of documentation”. One assumes therefore that auditing to “a check list” isn’t going to occur even though the regulation spells out some things that need to be done specifically. Interesting…

‘Data Protection Impact Assessments’ are now outlined in points 71a&b and are very similar to the commission’s proposal that assessments should be done on the lifecycle of information management for processing of personal data. Section 75 states that for public sector bodies processing sensitive personal data or data on more than 5000 data subjects in 12 months they will need to periodically monitor compliance with the regulation. Is the requirement to self-audit the same as the requirement to tick a box?

The phrase that appeared in the initial draft on ‘data portability’ has also changed. It is still there but now Point 55 changes the “right to data portability” to “controllers should be encouraged to develop interoperable formats that enable data portability”. Encouraged how and by whom still remains to be seen.

Another ‘hot phrase’ in the initial draft and current buzz word after the European Court of Justice decision is the “right to be forgotten”, and as predicted that has been changed to now Point 53 has been updated to state that “the right to be forgotten” is indeed now to be called the “right to erasure” and that this right is overwritten where processing is needed for the performance of a contract or to meet local legal requirements. Point 54 & 54a specifically make reference to “online information” and the requirement for the facilitator to block or remove such data if the data subject requests.

On that point, similar concerns around the watering down of legitimate interests have also tried to be abated in this text, and now Point 39 specifically outlines a purpose for processing personal data being a valid “legitimate interest”. Namely the processing for Information Security / Network Security purposes where strictly necessary. 39a also outlines that ‘legitimate interest’ can also include processing for the prevention or limitation of damages on the controller, providing this does not significantly go against the data subject’s rights and freedoms. 39b adds direct marketing processing as a ‘legitimate interest’ again providing this does not go against the rights and freedoms of the individual. Is it me or do some of these provisions say “You can do it, but…”.

There are some further oddities in here; for example, point 32 states that if a controller does not want to follow ‘data minimisation’ requirements there is a burden of proof to justify the processing of Personal Data for that specific purpose / scenario. Again this is nothing new as this is in line with the principles of the UK DPA but we have not seen a requirement to document and justify before. 32 also states that collecting consent on behalf of 3rd parties is no longer seen as valid consent. Therefore if a business needs 3rd party data alongside the initial data subject’s data would it need to contact said 3rd party to seek consent. But then, isn’t it processing said data in order to contact them to get the consent? How would this work I wonder… citizens aren’t going to this for controllers so what other options are there?

Talking of consent, the concern that consent becomes more specific hasn’t been removed as Point 25 clarifies that consent will require “clear affirmative action” by a data subject in order to be seen as a valid consent. Silence or simply use by the data subject of a service would not be acceptable as a valid consent to process personal data. To the above point, how would a controller get such consent from 3rd parties?

Consent has also been factored in for the use of profiling and that consent can be removed at any time. However Point 58 has been updated to state the for profiling, “Profiling which leads to measures producing legal effects concerning the data subject or does similarly significantly affect the interests, rights or freedoms of the concerned data subject should only be allowed when expressly authorised by law, carried out in the course of entering or performance of a contract, or when the data subject has given his consent”. Now here I believe that “carried out in the course of entering or performance of a contract” means that credit profiling can continue in the UK otherwise these seems to conflict with current legal requirements on Banks and Lenders to ensure that you as the customer can afford the product they offer and that you as the lender are lending responsibly – this can only be done by credit profiling surely?

Another area of concern from the initial text was around breach notification. There is still no useful outline as to what a material breach consists of however Point 67 confirms that data breach notification to the relevant authority “should be presumed to be not later than 72 hours” – somewhat better than the initial 24 hours but still something causing concern among various industries.

On the up side however, a new point specifically referencing Freedom of Information has been added. Point 18 has been updated to make reference to relevant member states Freedom of Information (FOI) legislation and how this regulation interacts with that. That’s some concerns appeased… or is it?

The EU Parliament have also updated what is expected of us DPOs and point 75a states that DPOs should have the following experience / qualifications;

  • extensive knowledge of the substance and application of data protection law, including technical and organisational measures and procedures;
  • mastery of technical requirements for privacy by design, privacy by default and data security;
  • industry-specific knowledge in accordance with the size of the controller or processor and the sensitivity of the data to be processed;
  • the ability to carry out inspections, consultation, documentation, and log file analysis;
  • and the ability to work with employee representation.

The controller should enable the data protection officer to take part in advanced training measures to maintain the specialized knowledge required to perform his or her duties.

Overall the current draft regulation has either been improved from what it was, stayed the same, or gotten worse in some places.

There are some ups and downs, and a few more changes that have been made that I have not referenced here (as I could be here all day). As for next steps for the Regulation I really don’t know who to believe. The ICO in a recent statement stated that they don’t believe there will be a tangible regulation until 2017 at the earliest. But in the same breath they also said (they being David Smith the Deputy ICO) that you should get your house in order now with current requirements as this puts you in a good place ready for the Regulation in 2017. Given how the Parliament approved the text way ahead of schedule and that this piece of legislation is the “most lobbied and campaigned on” in the EU’s history I am inclined to believe that all bets are off. I can see the case that it will come through quickly, especially as the EU is very defensive of Data Protection and Privacy of late. But then I also see the argument and stance from the European Council that they don’t want to rush this and instead want to take their time. As this Regulation would need agreement from the Council, the Parliament and the Commission I can see it rattling on for a while. But, as my favourite TV programme as a child used to say “Stand by for action; anything can happen in the next half an hour”. (For those that don’t know, that was from Stingray – and yes, I am a Geek that needs to get out more).

I have my word document unofficial text which I am happy to share on request but it is very much unofficial and really isn’t to be considered “official” in any capacity. Well worth a read though, and again I recommend that when the official text is finally updated and released (the EU moves at its own pace on such things) that you have it as some bed time reading to fill you with hope (and possibly nightmares).

Nighty night.

Scott Sammons is currently a European Data Protection Officer within the Finance Industry and blogs under the name @privacyminion . Scott is on the Exam Board for the Act Now Data Protection Practitioner Certificate which is a qualification designed to give candidates a head start in understanding and implementing the proposed EU Data Protection Regulation.

What is “information” under FOI?

canstockphoto0925773Section 1 of the Freedom of Information 2000 (FOI) contains the general right of access to information held by public authorities. But what exactly is “information”? Section 84 defines information as “information recorded in any form.” This includes information held on paper, computer, video, audiotapes as well as that contained in manuscript notes. FOI does not give access to information that is known to the public authority but is not available in some recorded form (see Ingle v Information Commissioner (EA/2007/0023) ).

Mere marks made on documents are also information according to an Information Tribunal decision from 2009 (O Connell v the Information Commissioner and Crown Prosecution Service (EA/2009/0010)). Here the Tribunal considered access to manuscript notes made by a defence barrister, during a criminal trial, on his client’s typed police interview record. The Information Commissioner’s view was that some of the notes, which consisted of asterisks and underlining of words on a document, were not information for the purposes of FOI.

The Tribunal rejected this submission. In its view, however tenuous and potentially misleading the material sought may be, it still constituted information; even if it was only information to the effect that certain marks had been made on certain sheets of paper held by the public authority. The Tribunal did however rule that the requested information was sensitive personal data, disclosure of which would breach the Data Protection Principles. Consequently it was exempt under section 40(2) being third party personal data.

It is an oft-repeated phrase that FOI provides a right of access to information rather than documents. However, a request for a copy of a document will generally be a valid request for all of the information contained within that document (including visual format, design, layout etc). In considering whether the public authority has complied with the request, the question is whether all of the information recorded in the document has been provided. It will not be sufficient to rephrase the document or provide an outline or summary of its contents unless the applicant has specifically expressed a preference for a digest or summary under section 11(1)(c).

In April 2013 the First Tier Tribunal (Information Rights), ruled that images of MPs’ expense claim receipts was information to which the FOI applied (IPSA v Information Commissioner (EA/2012/0242)). The background to the request was that, following the MPs’ expenses scandal, the then newly-formed Independent Parliamentary Standards Authority (IPSA), decided that it would not routinely publish images of the receipts submitted to IPSA by MPs in support of their expenses claims.  Only text transcribed from the submitted receipts would be published.

A journalist made an FOI request for the actual receipts submitted by a number of MPs. The question arose as to whether images of those receipts held by IPSA contained “information” within the meaning of section 1 of FOI, which was not captured by the transcription process favoured by IPSA. The Tribunal concluded that the definition of information (in this case) included logos, letterheads, handwriting, manuscript comments, and even the layout and style of the requested documents. These were not disclosed to the requestor as a result of providing a transcription, rather than a copy, of the relevant receipts.

The Upper Tribunal’s appeal decision in this case, has now put the matter beyond doubt. In Independent Parliamentary Standards Authority v IC & Leapman [2014] UKUT 33 (AAC) Judge Williams dismissed the appeal by IPSA. At Paragraph 22 of the judgement he said:

“It is to me also trite to note that the wording on a typical receipt or invoice is only part of what a recipient sees when looking at it. Typically there will be verbal and numerical content to be read and understood, but there will also be visual content to be seen, rather than read, but which may also require to be understood for the recipient to have appreciated the whole of the experience, if I may term it that, communicated by the receipt or invoice.”

In the judge’s view information is more than just the words and figures on a piece of paper. Sometimes the nature of the request will mean that the only way to convey all the information on a document is to disclose the original or at least a copy. He gave the example of Land Registry plans, drawings and photographic evidence of a particular building.

In coming to his decision the judge took note of the Scottish Court of Session decision in Glasgow CC v SIC [2009] CSIH 73 under the Freedom of Information (Scotland) Act 2002 (FOISA). As a general point of principle, the Commissioner and the Tribunal is not bound by Court of Session decisions on FOISA, although they may be considered persuasive where the terms of FOISA mirror the terms of FOI. In the Scottish case the applicant specifically wanted the public authority to provide copies of the documents, although he acknowledged that the same information was available elsewhere. The Court confirmed that FOISA entitles requesters to the information within a document, rather than a copy of the document itself. To the extent that this request was specifically for copies of the documents over and above the information they contained, it was invalid. The Court rejected an argument that the copy documents were “information” distinct from the information contained within them.

The Court stated at paragraph 45 of the judgment:

“Where the request does not describe the information requested… but refers to a document which may contain the relevant information, it may nonetheless be reasonably clear in the circumstances that it is the information recorded in the document that is relevant.”

However paragraph 48 should be noted:

“The difference between the original and a copy… does not consist in any difference between the information recorded in each document: that information, if the copy is true and accurate, will be identical.” (my emphasis)

In the IPSA case, the judge ruled that transcriptions of the requested receipts would not be “true and accurate”, as they would not contain all the same information as on the originals e.g. logos, style, layout etc.

If you want to know more on the Scottish case, read the briefing note published by the Scottish Information Commissioner. The basic principles (and these apply equally to FOI requests) are:

  • The Freedom of Information (Scotland) Act 2002 (FOISA) provides a right of access to information and not a right of access to copies of specific documents.
  • Authorities should not automatically refuse requests for copies of documents, as long as it is reasonably clear from the request that it is the information recorded in the document that the applicant wants.
  • Requesting a document (e.g. a report, a minute or a contract) is a commonplace way to describe information. Where it is reasonably clear that a request is for the information contained in a document, the authority should respond to the request as one properly made under FOISA.
  • If a request is for a document, but it is not reasonably clear what information is being requested, the authority should contact the applicant to seek clarification.

These are interesting decisions especially for those public authorities who often insist, when refusing to supply actual documents (such as minutes of meetings) that FOI is about access to information not documents. Sometimes the requestor is interested in the document, which contains the requested information, as it will give a further insight into its background and the thoughts/observations of the producers/subjects of the document.

Finally to quote one of our FOI trainers (Philip Bradshaw):

“Much will also in practice depend on the wording of the request. Contrast “How much did you spend on pencils?” with “Can I have a copy of your pencil invoices”. You can clearly provide in permanent form all the recorded information within scope of the first request without copies, but not perhaps for the second.”

Ibrahim Hasan will be discussing this and other recent FOI decisions in the FOI Update workshops which are delivered in online sessions as well as face to face.

Freedom of Information Caselaw Roundup

FOI3The Freedom of Information Act 2000 (FOI) applies to information held by a public authority or held on its behalf by another person (Section 3(2)). What of information about people working for a public authority but who are legally employed by a third party?

This question arose recently in an appeal to the First Tier Tribunal (Information Rights) (FTT). In Hackett v Information Commissioner (EA/2012/0265), the  (ULT), an education charity running 21 Academy schools, was asked for, amongst other things, details of senior staff members’ pay, pension contributions, other remuneration and expenses.  The request was refused on the basis that the information was not held by ULT, but by the United Church School Trust (UCST) who employed the staff and who, as a non-publicly funded charity, is not subject to FOI.

The appellant argued that the corporate structure of ULT and UCST was an accounting process set up to avoid disclosure of the requested information which was about the spending of public money. In addition he submitted that both companies were subsidiaries of the United Church Schools Company and as such were, in effect, both part of one company.

The FTT upheld the decision of the Information Commissioner that the information was not held by ULT, but by UCST, and so not subject to FOI.  It took account of the fact that the corporate structure had been urged on ULT by the Department for Education, the two charities had maintained a complete corporate separation and that the service agreement between ULT and UCST expressly referred to the senior staff being employed by UCST. Could this decision mean that more public bodies will adopt innovative structures to avoid public scrutiny of their finances?

The section 40 exemption applies to personal data disclosure of which would breach one of the Data Protection Principles. This usually involves considering whether disclosure would be fair and lawful under Principle 1. Not all personal data will be exempt from disclosure. Sometimes there is a legitimate interest in the public knowing some personal data.

In Innes v Information Commissioner (EA/2013/0044) the FTT ruled that the reasons for a head teacher’s long-term sickness absence from his school did not have to be disclosed as they constituted personal data, but whether the head teacher was being paid a salary during his absence should be disclosed. As head teacher, the individual in question occupied a senior position of responsibility at the school. He was no longer performing an active function at the school and whether or not he was being paid from public funds during the period of absence and inactivity is a legitimate matter of public interest and one which outweighs his right to privacy.

Personal Data under section 40 has the same meaning as in Section 1 of the Data Protection Act i.e. it has to be information, which relates to a living identifiable individual. The requested information does not always have to include a name. Even job title information can be personal data according to the FTT decision in London Borough of Barnet v Information Commissioner and another (EA/2012/0261). Here the requestor wanted the job titles of council employees who had attended a meeting at a solicitor’s firm in respect of a major council outsourcing project. Referring to a Supreme Court decision (South Lanarkshire Council v The Scottish Information Commissioner [2013] UKSC 55), the FTT ruled that disclosing details of a job title held by more than one local authority official could constitute processing personal data if there was a chance of those individuals being identified. The test was whether the subjects could be identified, not just by an ordinary member of the public but, by a “motivated intruder” (including the requestor himself with all the other information at his disposal).

Continuing on the same theme, in Yiannis Voyias v Information Commissioner (EA/2013/0003), the FTT held that the London Borough of Camden was correct to refuse to disclose the number of hours its employees worked and how much overtime they were paid. It was satisfied that disclosure of this information would lead to the identification of individuals and would be unfair. Therefore section 40 applied.

Personal data in Building Regulations applications held by councils is not exempt under section 40 just because it relates to another person’s property. In James Henderson v IC EA/2013/0055), the appellant’s neighbour was carrying out renovations on the other side of their shared wall. This resulted in cracks on his side of the wall, followed by a steel beam coming through the wall. He asked Brentwood Council for details of the works, as a Building Control application had been made to them.

The FTT held that full details of a Building Regulations application was personal data; but disclosing this information would not contravene the First Data Protection Principle. Therefore, the exemption set out in section 40(2) did not apply and the information was ordered to be disclosed. The FTT disagreed with the Commissioner, who held that the data subject would have had a reasonable expectation of privacy in relation to the information. In doing so the FTT took account of the fact that (a) before starting any work the data subject was obliged to make a formal application to the local authority which meant that the property and the work would be subject to inspections by their officers, (b) the property was to be rented out rather than lived in by him; and (c) the work had a direct effect on his neighbour’s property.

The Freedom of Information (Scotland) Act 2002 has a specific exemption to cover a deceased person’s health record. There is no such exemption in the 2000 Act. Sometimes the section 41 exemption (Breach of Confidence) can be claimed.

Two recent Tribunal decisions again emphasise the importance of checking whether the requestor is the deceased’s appointed personal representative. In Webber v IC and Nottinghamshire Healthcare NHS Trust (GIA/4090/2012), the appellant had made an FOI request for information (including hospital records) about the death of her son in 1999. The Commissioner and the FTT upheld the decision to refuse on section 41 grounds. The Upper Tribunal also dismissed the appeal. It ruled that disclosure would entail a Breach of Confidence which was actionable after the patient’s death. The appellant was not the personal representative of the deceased even though she could have applied to become so.

The Upper Tribunal also found that there would not have been a public interest defence to the Breach of Confidence. It gave weight to the fact that some of the information sought would or could come into the public domain or be obtained in another way: a coroners’ inquest, or through an application under the Access to Health Records Act 1990. This allows for requests for access to information to be made by, amongst others, the patients’ personal representative.

When considering disclosure of a deceased person’s information, consideration has to be given to any wishes expressed by the deceased before their death. In Trott and Skinner v Information Commissioner (EA/2012/0195) (March 2013) the appellants requested information relating to the care records of their deceased sister. East Sussex County Council confirmed that it held a relevant care file but refused to disclose it on the basis that it was provided in confidence. The FTT and the Commissioner were satisfied that the section 41 exemption was engaged. The requested information was confidential, disclosure of which would be a Breach of Confidence. Amongst other things it took account of the fact that the deceased was given the opportunity to indicate (in her home care agreement) that she agreed to let the Council “share personal information on care with family members/friends listed below.” She did not sign her agreement or list anybody in the space provided. The Tribunal also heard that on several occasions she was given specific assurances that her information would be kept confidential.

Furthermore the FTT was satisfied that the Breach of Confidence would be actionable. This was despite the fact that the sisters were the next of kin of the deceased. They were not the personal representatives of the deceased though. Neither the council nor the Commissioner had enquired as to who was. On further inquiry by the Tribunal, it was discovered that there was a will and therefore an Executor who has standing to act as the deceased’s personal representative. There was no evidence of consent for disclosure under FOI from this Executor. Therefore section 41 was engaged and there was no public interest defence to the disclosure.

Give your career a boost in 2014 by gaining an internationally recognised qualification in FOI. Keep up to date with all the latest FOI decisions in 2014 by attending our FOI Update workshops.

Section 36 of FOI: An Appellant’s Perspective

Norman Baird writes:FOI4

The University of London International Programmes offers an LLB degree by distance learning. It is studied by thousands of students worldwide. With such a large number of students, the University relies on a large number of lecturers from a variety of universities to mark the exam scripts. The University provides some academic support – in the form of written guides and recorded lectures – but relies on private institutions to provide face-to-face tuition. I am Academic Director of one such institution. I made an FOI request for the marking guidelines issued to the markers.

My request was declined. The University relied on S.36(2)(c) which is engaged if, in the reasonable opinion of the Qualified Person(QP), disclosure would or would be likely to prejudice the effective conduct of public affairs. If it is engaged it is then subject to a public interest test. The University stated that :

“disclosing the marking guidelines, in this case and as a precedent, would fundamentally affect one of the University’s core functions, that of robust exam assessment”.

And this opinion was arrived at on the basis of three subsidiary claims of particular harms. These are, somewhat confusingly, also described in terms of prejudices.

First, the University contended that “the disclosure of the marking guidelines… would be likely to prejudice the effective operation of the University’s examiners in preparing the most robust and effective guidelines…”

Second, that “disclosure of the marking guidelines would be likely to prejudice the actions and efforts of students, who may try to adapt their essay answers to marking guidelines developed at examiner level for examiners, resulting in mistakes in comprehension and lower attainment scores.”

Third, the University maintained that “disclosure would be likely to prejudice the nature of the guidelines, where a requirement to establish a process to publish marking guidelines will transform them from useful internal assessment tools to just another external facing study aid, of which a wide range of provision already exists.”

The Information Commissioner found in favour of the University and so I appealed to the First Tier Tribunal (Information Rights) on the grounds that the opinion was neither reasonable in substance nor reasonably arrived at. In addition, I contended that the public interest in favour of disclosure outweighed the arguments against. But in the limited space here I only want to look at a couple of my submissions.

My first ground was that the Qualified Person, Vice-Chancellor (V-C) Professor Geoffrey Crossick, had not expressed an opinion as required by the section. This had been added to my grounds of appeal at a late stage as it was only when the University responded to my initial appeal that I first saw the ‘opinion’ signed by the Qualified Person. He had been provided with an ‘evidence pack’ in which he was advised that, in the opinion of the International Academy of the University, disclosure would be prejudicial. He had written:

“I have now reviewed the evidence with respect to the FOI request asking for… the marking guidelines. It is my conclusion that the opinion – that disclosing the marking guidelines, in this case and as a precedent, would fundamentally affect one of the University’s core functions, that of robust exam assessment – is reasonable in substance.

I confirm that, in my capacity as qualified person, that this exemption is engaged with respect to the request for marking guidelines.”

He states that the opinion (of the International Academy) that disclosure would be prejudicial was a reasonable one. Now, it is clear that one person may recognise another’s opinion as reasonable without sharing that opinion. The section requires the QP to express his opinion that prejudice would or would be likely to be caused. The V-C did not do so.

And it is not possible to conclude from his final sentence that he believed that prejudice would result. He appears to have formed the view that, provided he thought the opinion was reasonable, the section was engaged. In effect, he expressed himself in terms consistent with the role of the Information Commissioner and not that required of a Qualified Person.

It is notable that the V-C was not consulted again at the internal review stage and there was no other evidence that, in his opinion, disclosure would be prejudicial. In addition, the advice given in the evidence pack with which the V-C had been provided the advice was ambiguous. Although S.36(2)(c) was reproduced, the V-C had been advised that the University’s opinion was that disclosure would be prejudicial and that he was required to ‘authorise’ the exemption.

My second ground of appeal was that the ‘opinion’ was not reasonably arrived at. There were a number of limbs to this submission including the fact that the subsidiary claims were unsupported by evidence, were barely comprehensible and there was no evidence that anyone involved in making the decision or advising the V-C had actually read the documents.

But I would like to focus on one submission as it appears to me to be central to the way in which the ‘opinion’ and the Decision Notice (DN) should be approached. It is well established that although the opinion need only be a reasonable opinion and not the most reasonable it must be ‘rational’, ‘not illogical’, ‘not arbitrary’. I submitted that there was a lack of logical coherence between the opinion and the subsidiary harms upon which it rests.

The ‘opinion’ was that disclosure would prejudice robust exam assessment. The subsidiary claims, however, are expressed in terms of likely effects. To conclude that prejudice to the assessment system would occur because prejudice to students and examiners is likely is as illogical and irrational as concluding that consumption of a drug would be fatal on the grounds that it is likely to induce a fatal heart attack and/or terminal cancer.

The response to this argument by the Information Commissioner was that although the University and the Decision Notice had claimed throughout that disclosure ‘would’ cause prejudice the overall tenor of the opinion and the DN was that the ‘would be likely’ limb was being relied on. In effect, the IC is saying that although he said one thing he meant another. As I argued at the Tribunal, if the opinion is to be read so that it is consistent with the subsidiary claims it is impossible for a requester to argue that the opinion and the subsidiary claims are incoherent.

The section is a powerful one for a Public Authority. It has been described as a ‘get out of jail free card’ and so it is submitted that it ought to be construed narrowly and applied strictly. It is not particularly difficult to express the opinion correctly. And although the Decision Notice is not to be read as though it is a judgment of the Court of Appeal, a requester who appeals is at a great disadvantage if all its inconsistencies are smoothed over to ensure the appearance of logical consistency and coherence.

It has been said (and was repeated at the Tribunal) that a requester will find it difficult to establish that an opinion was not ‘ a reasonable opinion reasonably arrived’. That will certainly be true if an opinion can be found when none was expressed and if the central requirements of reasonableness – rationality and logical coherence – are ignored or fudged.

I look forward to reading the opinion of the Tribunal but I am not optimistic.

Norman Baird has been lecturing on Criminal Law and Jurisprudence for approximately 30 years and runs law courses in London and abroad. He also publishes a blog: www.llblondon.com

Ibrahim Hasan will be discussing this and other recent FOI decisions in our FOI Update workshops in 2014.

Do you want an international recognised qualification in FOI? The BCS/ISEB Certificate in Freedom of Information starts in March 2014 in London and Manchester.

Data Sharing Consultation – Do we need new laws?

The Law Commission has opened a consultation on the law around sharing of personal information between public sector organisations. Law Commissioner Frances Patterson QC says:

“It could be that more data sharing would improve public services but, if that is so, we need to understand why data is not being shared.  Is there a good reason to prevent data sharing?  Or is the law an unnecessary obstacle?  Are there other reasons stopping appropriate data sharing?  These are the questions we want to answer in this consultation.”

The legalitiecanstockphoto1632442s of data sharing is a subject which often confuses public sector officials. Local authorities, in particular, are often stumped by the “To Share or Not to Share” question, even if the sharing is for very good reasons (e.g. child protection or crime prevention). In some cases, even internal departments have felt constrained from updating each other about a change of a service user’s address.

More often than not, the Data Protection Act 1998 (DPA) is made the scapegoat for officials’ failure to fully understand the law. It is wrongly perceived as a barrier to data sharing despite offering a range of justifications (e.g. consent, legal obligation, protecting vital interests etc. (Schedule 2)).

Many attempts have been made to resolve this “problem”. In May 2011, the Information Commissioner published a statutory Code of Practice on data sharing. The code explains how the DPA applies to the sharing of personal data both within and outside an organisation. It provides practical advice to the public, private and third sectors, and covers systematic data sharing arrangements as well as one off requests for information. Under Section 52 of the DPA, the code can be used as evidence in any legal proceedings and can be taken into account by the courts and the Commissioner himself when considering any issue.

Despite the clear guidance in the code, the Government has sometimes toyed with the idea of new laws. Last year, according a story in the Guardian newspaper, proposals were to be published by the Cabinet Office minister, Francis Maude, which would make it “easier” for government and public-sector organisations to share confidential information supplied by the public:

“In May, we will publish proposals that will make data sharing easier – and, in particular, we will revisit the recommendations of the Walport-Thomas Review that would make it easier for legitimate requests for data sharing to be agreed with a view to considering their implementation,” said Maude, adding that current barriers between databases made it difficult for public sector workers to access relevant information.

“It’s clearly wrong to have social workers, doctors, dentists, Job Centres, the police all working in isolation on the same problems.”

The Guardian reported that the proposals are expected to include fast-track procedures for ministers to license the sharing of data in areas where it is currently prohibited, subject to privacy safeguards.  I could not find the proposals on the web. Anybody know whether they were ever published?

Confusion around data sharing continues to reign! The tragic case of Daniel Pelka is one example. The recent report into the four-year-old’s death, published by the independent Coventry Safeguarding Children Board identified a number of missed opportunities where professionals across a number of agencies should have done more to protect Daniel. Amongst other things, it concluded that the sharing of information and communications between all agencies was not robust enough.

Ill informed comments about the current law (especially the DPA) do not help. In a recent Daily Telegraph article by Michael Gove, the Education Minister claimed that, whilst tying to understand the underlying causes of child exploitation, he discovered that OFSTED “was prevented by “data protection” rules, “child protection” concerns and other bewildering regulations from sharing that data with us, or even with the police.” There is nothing in the DPA which prevents this. Don’t just take my word for it. Read the Information Commissioner’s riposte to the learned Mr Gove.

Do we really need new laws on data sharing or a better awareness of the existing ones? My view is that the current law is adequate to regulate yet allow responsible data sharing. The DPA and the Data Sharing Code need to be properly understood. They can be a tool allowing responsible data sharing. Most public sector data sharing will be lawful if organisations comply with the Eight Data Protection Principles; particularly the First Principle which requires information to be processed fairly and lawfully. There are also numerous exemptions in the Act including where sharing is required for the purpose of prevention or detection of crime (section 29).

The Law Commission consultation runs until 16 December 2013 and the paper may be accessed at: http://lawcommission.justice.gov.uk/. Responses can be emailed to data.sharing@lawcommission.gsi.gov.uk or sent by post.

More Information: Read our article for a full explanation of the ICO Data Sharing Code or watch this free webinar. We also run full day Multi Agency Information Sharing workshops.