Youngest son has been looking for work and was interviewed for some warehouse job with a big name in retail and had this thrust under his nose while being interviewed. Luckily the modern scourge of camera phone proved very useful at this point and he showed me this image when he returned home. Is it a Policy? Who is the data controller? Why do applicants have to sign to agree that their application form goes to a prospective employer? Why do they need medical details? The questions go on and on. Contradiction in the final paragraph. And they’ve squeezed all this into just over 50 words. Is it possible to write a Data Protection Policy that will fit into 140 characters? Who writes this stuff?
Tag: Privacy
The Law of Employee Surveillance
Decreasing public sector budgets and increasingly affordable technology mean that more and more employers are turning to surveillance to catch errant or work shy employees. But this area is a legal minefield. Mistakes can end up with adverse headlines in the media or worse still legal action. In August, West Yorkshire Fire Service was criticized in the papers when a 999 operator, who was on sick leave, found a GPS tracker planted on her car by a private detective hired by her bosses.
A public sector employer wanting to conduct lawful staff surveillance must first ask the question, which legislation applies? If the surveillance involves covert techniques or equipment, it is easy to assume that Part 2 of the Regulation of Investigatory Powers Act 2000 (“RIPA”) applies and that the surveillance must be the subject of an written authorisation by a senior officer and, in the case of a local authority employer, Magistrates’ approval. However, the Investigatory Powers Tribunal has ruled in the past that not all covert surveillance of employees is regulated by RIPA.
In C v The Police and the Secretary of State for the Home Department (14th November 2006, No: IPT/03/32/H), a former police sergeant (C), having retired in 2001, made a claim for a back injury he sustained after tripping on a carpet in a police station. He was awarded damages and an enhanced pension due to the injuries. In 2002, the police instructed a firm of private detectives to observe C to see if he was doing anything that was inconsistent with his claimed injuries. Video footage showed him mowing the lawn. C sued the police claiming that they had carried out Directed Surveillance under RIPA without an authorisation. The Tribunal first had to decide if it had jurisdiction to hear the claim. The case turned on the interpretation of the first limb of the definition of Directed Surveillance i.e. was the surveillance “for the purposes of a specific investigation or a specific operation?”
The Tribunal ruled that this was not the type of surveillance that RIPA was enacted to regulate. It made the distinction between the ordinary functions and the core functions of a public authority:
“The specific core functions and the regulatory powers which go with them are identifiable as distinct from the ordinary functions of public authorities shared by all authorities, such as the employment of staff and the making of contracts. There is no real reason why the performance of the ordinary functions of a public authority should fall within the RIPA regime, which is concerned with the regulation of certain investigatory powers, not with the regulation of employees or of suppliers and service providers.”
The Tribunal also stated that it would not be right to apply RIPA to such surveillance for a number of reasons:
- RIPA does not cover all public authorities, and there was no sense in police employee surveillance being conducted on a different legal footing than, for example, the Treasury, which does not have the same surveillance rights under RIPA.
- The Tribunal has very restrictive rules about evidence, openness and rights of appeal. The effect of these would lead to unfairness for employees of RIPA authorities when challenging their employers’ surveillance as compared to those who were employed by non RIPA authorities.
This case suggests that, even where employee surveillance is being carried out for the purpose of preventing or detecting crime, the question has to be; is it for a core function linked to one of the authority’s regulatory functions? In the local authority context this would include, amongst others, trading standards, environmental heath and licensing. If the surveillance is not being done for one of these purposes it will not be Directed Surveillance and consequently will not be regulated by RIPA.
Of course just because RIPA may not apply, it does not mean that the employer can do what it likes. Whatever type of surveillance is conducted, the right to privacy, under Article 8 of the European Convention on Human Rights, protects employees within the work environment. This means that the surveillance must be carried out in a manner that is in accordance with the law and is necessary and proportionate. There have been a number of cases where employers have been criticised by the courts for failing to take account of the human rights issues when doing surveillance of employees e.g. Copland v UK (3rd April 2007 ECHR) concerning communications surveillance and Jones v Warwick University ((2003) 3 All ER 760) concerning a claim for personal injury. Compliance with the Data Protection Act 1998 (DPA) will be evidence that the surveillance has also been done in compliance with Article 8.
All employers, be they public or private sector, have to comply with the DPA when doing surveillance, as they will be gathering and using personal information about living individuals. The Information Commissioner has published the Data Protection Employment Practices Code, which sets out rules to be followed when dealing with employees’ personal data.
Part 3 of the code covers all types of employee surveillance from video monitoring and vehicle tracking to email and Internet surveillance. Indeed those public authorities who are doing surveillance of their employees which now, in the light of the above Tribunal case, cannot be authorised under RIPA also have to pay special attention to the code. Whilst the code is not law, it can be taken into account by the Information Commissioner and the courts in deciding whether the DPA has been complied with.
One of the other main recommendations of the code is that senior management should normally authorise any covert surveillance of employees. They should satisfy themselves that there are grounds for suspecting criminal activity or equivalent malpractice. They should carry out an impact assessment and consider whether the surveillance is necessary and proportionate to what is sought to be achieved i.e. the same considerations that public sector employers subject to RIPA would have to consider when doing a RIPA authorisation. This assessment is best done in writing using a “Non-RIPA” surveillance form (Our RIPA Policy and Procedures Toolkit contains such a form).
If covert surveillance of an employee results in his/her dismissal, the matter will usually end up before the Employment Tribunal in the form of unfair dismissal proceedings. Here the Tribunal will also have to consider whether evidence has been gathered fairly and lawfully. In City And County Of Swansea v Gayle UKEAT 0501_12_1604 (16 April 2013) Swansea Council conducted covert video surveillance on the claimant, when he was for good reason suspected of playing squash during work time, whilst claiming payment for being at work at the time. The surveillance confirmed he was seen at the sports centre on a succession of Thursdays when he should have been at work.
The Employment Tribunal upheld a claim for unfair dismissal (though awarding nil compensation, for contributory conduct) because of the Tribunal’s distaste for the employer’s use of covert surveillance. Its view was that Article 8 (right to privacy) was engaged and broken in doing so. It took account of the council’s lack of awareness of its obligations under the DPA and the Code.
These views were rejected on appeal to the Employment Appeal Tribunal. The appeal was allowed with a substituted finding that the dismissal was not unfair. The Tribunal did not accept that here there was any breach of Article 8(1) so as to require the Tribunal to consider the requirements of 8(2) at all. If, however, the Tribunal had done so it would have been bound to consider the legitimate aim which the Council claimed to have. Here one of two such aims might have been identified. The first was the prevention of crime, the second the protection of the rights and freedoms of others, the “others” here being the employers whose money was at stake and who had contractual rights in agreement with the claimant that he would behave in a way in which as it happened he did not.
This is an interesting case for employers. Dismissals will not necessarily be unfair when covert surveillance is used as part of the dismissal process. Employees acting fraudulently on employer’s time cannot expect their actions to be kept private from the employer. However, employers would be well advised to tread with caution. Following the correct procedures and being mindful of their obligations under the DPA (as well as Human Rights) will inevitably put an employer in a better position.
Employee surveillance may not always engage RIPA. However data protection and human rights laws will always have to be carefully considered. In cases of surveillance of staff e-mail and internet usage Section 4 of RIPA and the Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations 2000 will also need to be considered. For more on the latter please see our online training course (Email and Internet Monitoring: How to do it lawfully).
Act Now can help you get to grips with this difficult area. Please see our full program of surveillance law courses which can also be customised and delivered at your premises. If you want a quick update try our forthcoming webinars.
Listen to Ibrahim Hasan’s interview on BBC File on Four on Secrecy and Surveillance: of http://www.bbc.co.uk/programmes/b03bdsyk
Data Sharing Consultation – Do we need new laws?
The Law Commission has opened a consultation on the law around sharing of personal information between public sector organisations. Law Commissioner Frances Patterson QC says:
“It could be that more data sharing would improve public services but, if that is so, we need to understand why data is not being shared. Is there a good reason to prevent data sharing? Or is the law an unnecessary obstacle? Are there other reasons stopping appropriate data sharing? These are the questions we want to answer in this consultation.”
The legalitie
s of data sharing is a subject which often confuses public sector officials. Local authorities, in particular, are often stumped by the “To Share or Not to Share” question, even if the sharing is for very good reasons (e.g. child protection or crime prevention). In some cases, even internal departments have felt constrained from updating each other about a change of a service user’s address.
More often than not, the Data Protection Act 1998 (DPA) is made the scapegoat for officials’ failure to fully understand the law. It is wrongly perceived as a barrier to data sharing despite offering a range of justifications (e.g. consent, legal obligation, protecting vital interests etc. (Schedule 2)).
Many attempts have been made to resolve this “problem”. In May 2011, the Information Commissioner published a statutory Code of Practice on data sharing. The code explains how the DPA applies to the sharing of personal data both within and outside an organisation. It provides practical advice to the public, private and third sectors, and covers systematic data sharing arrangements as well as one off requests for information. Under Section 52 of the DPA, the code can be used as evidence in any legal proceedings and can be taken into account by the courts and the Commissioner himself when considering any issue.
Despite the clear guidance in the code, the Government has sometimes toyed with the idea of new laws. Last year, according a story in the Guardian newspaper, proposals were to be published by the Cabinet Office minister, Francis Maude, which would make it “easier” for government and public-sector organisations to share confidential information supplied by the public:
“In May, we will publish proposals that will make data sharing easier – and, in particular, we will revisit the recommendations of the Walport-Thomas Review that would make it easier for legitimate requests for data sharing to be agreed with a view to considering their implementation,” said Maude, adding that current barriers between databases made it difficult for public sector workers to access relevant information.
“It’s clearly wrong to have social workers, doctors, dentists, Job Centres, the police all working in isolation on the same problems.”
The Guardian reported that the proposals are expected to include fast-track procedures for ministers to license the sharing of data in areas where it is currently prohibited, subject to privacy safeguards. I could not find the proposals on the web. Anybody know whether they were ever published?
Confusion around data sharing continues to reign! The tragic case of Daniel Pelka is one example. The recent report into the four-year-old’s death, published by the independent Coventry Safeguarding Children Board identified a number of missed opportunities where professionals across a number of agencies should have done more to protect Daniel. Amongst other things, it concluded that the sharing of information and communications between all agencies was not robust enough.
Ill informed comments about the current law (especially the DPA) do not help. In a recent Daily Telegraph article by Michael Gove, the Education Minister claimed that, whilst tying to understand the underlying causes of child exploitation, he discovered that OFSTED “was prevented by “data protection” rules, “child protection” concerns and other bewildering regulations from sharing that data with us, or even with the police.” There is nothing in the DPA which prevents this. Don’t just take my word for it. Read the Information Commissioner’s riposte to the learned Mr Gove.
Do we really need new laws on data sharing or a better awareness of the existing ones? My view is that the current law is adequate to regulate yet allow responsible data sharing. The DPA and the Data Sharing Code need to be properly understood. They can be a tool allowing responsible data sharing. Most public sector data sharing will be lawful if organisations comply with the Eight Data Protection Principles; particularly the First Principle which requires information to be processed fairly and lawfully. There are also numerous exemptions in the Act including where sharing is required for the purpose of prevention or detection of crime (section 29).
The Law Commission consultation runs until 16 December 2013 and the paper may be accessed at: http://lawcommission.justice.gov.uk/. Responses can be emailed to data.sharing@lawcommission.gsi.gov.uk or sent by post.
More Information: Read our article for a full explanation of the ICO Data Sharing Code or watch this free webinar. We also run full day Multi Agency Information Sharing workshops.
The 2013 Surveillance Commissioner Report – Key Points
The Chief Surveillance Commissioner published his 2013 annual report (covering the period from 1st April 2012 to 31st March 2013) on 18th July 2013. It is important reading for those public authorities who conduct surveillance under Part 2 of the Regulation of Investigatory Powers Act 2000 (RIPA).
The report details statistics relating to the use of Part 2 of RIPA by public authorities and information about how the Office of the Surveillance Commissioner (OSC) conducts its oversight role. Non-law enforcement agencies (including councils) authorised Directed Surveillance on 5,827 occasions. This continues a downward trend over the last few years.
The report highlights a number of important issues some of which are listed below:
- Common errors by RIPA authorities include miscommunication or failure to communicate the details of an authorisation; failure to conduct thorough reviews, renewals or cancellations; ignorance on the part of officers; or poor administration or processes.
- The Commissioner says that all public authorities have struggled with the use of the Internet for investigations, particularly social networking sites. At paragraph 5.7 he advises caution on conflating the offline word with the online world. There may be cases where RIPA authorisation is required when doing research about a person on the Internet. He goes on to say, “… it is important to bear in mind that it is not always possible to give a definitive answer as to whether a particular activity requires authorisation: facts are infinitely variable. Where there is doubt authorisation is prudent.” Act Now has developed a course on E-Crime and Social Networking Sites which examines all the relevant RIPA and wider legal issues.
- Too many tactics requested by investigating officers are unused. Authorising officers and Senior Responsible Officers should monitor whether applicants are lazily requesting tactics out of habit rather than necessity.
- Too many cancellations provide an insufficient record of surveillance actually conducted and the details of collateral intrusion. Rarely does guidance on the retention or destruction of product go beyond an inadequate reference to policy. It is vital that surveillance product that does not match the objectives stated in the authorisation is not retained on databases.
- At paragraph 5.5, the Commissioner reiterates his view that RIPA is permissive legislation and there may be occasions where surveillance outside the scope of RIPA may be required. He points to the recent IPT decision in BA and others v Cleveland Police (IPT/11/129/CH). This is in keeping with Ibrahim Hasan’s view as explained on this blog.
- Where there is an invasion of privacy and RIPA does not apply, due to all conditions not being met, then the Commissioner recommends use of a similar written authorisation mechanism where Article 8 issues (privacy) are considered.
- The Commissioner also considers the changes, which took effect on 1st November 2012; namely magistrates’ approval for council surveillance and a new six month threshold test for Directed Surveillance. On the whole they are working well. There were 142 approval requests made to a Magistrate in the reporting period of which only two were rejected.
- Finally the Commissioner fires a shot across the bows of those authorities who drag their feet in accepting his recommendations. At paragraph 5.18 he says, “I expect the recommendations of my reports to be followed whether or not individual officers agree with them. Continued failure to do so – especially on the ground that current practices have been unchallenged in court proceedings – may result in publication of my guidance or recommendations to a wider audience.”
Now is the time to consider refresher training for RIPA investigators and authorisers. Please see our full program of RIPA Courses which have been revised to take account of all the latest developments. We can also deliver these courses at your premises, tailored to the audience. Finally, if you want to avoid re inventing the wheel, our RIPA Policy and Procedures Toolkit gives you a standard policy as well as forms (with detailed notes to assist completion) for authorising RIPA and non-RIPA surveillance. Over 200 different organisations have bought this document (available on CD as well).
Disclosure of Staff Names under FOI
When considering request for information under the Freedom of Information Act 2000(FOI) public authorities often face a dilemma about disclosing names of staff.
Names are generally considered to be personal data, being information relating to living identifiable individuals (as defined by the Data Protection Act 1998 (DPA)). (Although one Information Tribunal (as it was known then) decision, Harcup v Information Commissioner and Yorkshire Forward (EA/2007/0058), ruled they are not. (See episode 11 of my FOI Podcasts for a full discussion of this decision). Therefore the exemption under section 40(2) (third party personal data) will have to be considered.
For this exemption to be engaged a public authority must show that disclosure of the name(s) would breach one of theData Protection Principles. Most cases in this area focus on First Principle and so public authorities have to ask, would disclosure be fair and lawful? They also have to justify the disclosure by reference to one of the conditions in Schedule 2 of the DPA (as well as Schedule 3 in the case of sensitive personal data). In the absence of consent, most authorities end up considering whether disclosure is necessary for the applicant to pursue a legitimate interest and, even if it is, whether the disclosure is unwarranted due to the harm caused to the subject(s) (condition 6 of Schedule 2)?
The seniority of the staff, whose names are being requested, will of course be a key factor in deciding whether disclosure is fair. The first Information Tribunal decision on this issue, back in 2007, (Ministry of Defence v Information Commissioner and Rob Evans (EA/2006/0027)) concerned a request made by a journalist for a staff directory which included the names and contact details of individuals working for the Defence Exports Services Organisation. The MoD refused to disclose the information citing, amongst others, the exemption under section 40(2).
The Tribunal ruled that that the MoD could only withhold names of staff if they are particularly junior (below Civil Service B2 Level), not immediately responsible for the requested information and their name is not already available elsewhere (or would be expected to be through their performing a public-facing duty); or there is a clear and demonstrable threat to that individual’s health and safety if their name is made public.
As is clear from the MoD decision, seniority is just one factor to be taken into account. Public authorities should avoid the blanket non-disclosure of the names of all officers below a certain level of seniority. When it comes to the disclosure of names, what matters is what work the individuals are doing, rather than their seniority or grade. If a person is in a front facing role and his/her name is already in the public domain, then it will be difficult to withhold it.
In 2008 another Tribunal decision (The Department for Business, Enterprise and Regulatory Reform v Information Commissioner and Friend of the Earth (EA/2007/0072) examined whether names of private sector employees attending a meeting should be disclosed as well as those of civil servants. The request was for information about meetings and correspondence between Ministers and senior civil servants in the Department of Business, Enterprise and Regulatory Reform and employees from the Confederation of British Industry. Some of the documents relevant to the request included references to individuals who had attended such meetings as spokespersons or as note takers or bystanders. The Tribunal summarised the position as follows:
a. Senior officials of both the government department and lobbyist attending meetings and communicating with each other can have no expectation of privacy. The officials to whom this principle applies should not be restricted to the senior spokesperson for the organisation. It should also relate to any spokesperson.
b. Recorded comments attributed to such officials at meetings should similarly carry no expectation of privacy.
d. In contrast junior officials, who are not spokespersons for their organisations or merely attend meetings as observers or stand-ins for more senior officials, do have an expectation of privacy. This means that there may be circumstances where junior officials who act as spokespersons for their organisations are unable to rely on an expectation of privacy;
e. The question as to whether a person is acting in a senior or junior capacity or as a spokesperson is one to be determined on the facts of each case.
f. The extent of the disclosure of additional information in relation to a named official will be subject to usual test i.e. is disclosure necessary for the applicant to pursue a legitimate interest, and, even if it is, is the disclosure unwarranted due to the harm caused to the individuals by disclosure? This will largely depend on whether the additional information relates to the person’s business or professional capacity or is of a personal nature unrelated to business.
In January 2011, the First Tier Tribunal (Information Rights) considered disclosure of names in Dun v IC and National Audit Office (EA/2010/0060). The disputed information concerned the NAO’s enquiry into the FCO’s handling of employee grievances of a whistleblowing variety. The Tribunal was clear that no blanket policy should apply, and that fairness depends on the particular responsibilities and information with which the case is concerned. This decision is discussed in detail in episode 21 of my FOI Podcasts.
Where there is a risk to staff safety if their names are disclosed, then the public authority will be right to err on the side of caution. In Wild v IC and Chief Constable of Hampshire Constabulary (EA/2010/0132) the Appellant requested the dates of pre-hunt meetings in the last five years and the names of police officers attending pre-hunt meetings with organisers of the Isle of Wight Hunt. The Police responded, providing dates, but refusing to disclose the names of the officers in attendance.
The Commissioner considered the section 40(2) exemption and concluded that the disclosure would result in a breach of the First Data Protection principle. He accepted that the disclosure may lead to the harassment of the officers identified and consequently the disclosure would be unfair to those officers. The Tribunal upheld the Commissioner’s decision.
Don’t forget condition 6 of schedule 2 of the DPA. A public authority will have to consider whether disclosure of a name is necessary for the applicant to pursue a legitimate interest, and, even if it is, whether the disclosure is unwarranted due to the harm caused to the individual by the disclosure.
A more recent Tribunal decision (January 2013), McFerran v IC (EA/2012/0030) involved a police search of a property owned by Shropshire County Council. At the police’s request, two junior council officers were present, but they had not been involved in any of the decision-making. The requester wanted the names of the council officers as well as their immediate superior. The council refused, relying on s. 40(2).
The Commissioner ordered disclosure of the name of the more senior officer, but not of the two juniors. The Tribunal agreed with this decision and dismissed the requester’s appeal, observing that:
“although… there is clearly a legitimate public interest in transparency of activity by public authorities, which impinges on the personal freedom of householders, there is insufficient information provided to add significant weight to the general public interest in transparency in public affairs. The Appellant has not satisfied us, either, that his attempts to have the matter investigated are being thwarted by the absence of the names of the individuals in question. If there is sufficient information about the event to interest those responsible for an investigation the absence of names will not deter them.”
This decision illustrates that, when it comes to junior officials, the requestor will have to show that there is legitimate interest in knowing the names of officers where they are junior. A general argument about openness and transparency will not suffice.
In Armit v IC and Home Office (EA/2012/0041) the UKBA redacted the names of the officials in a document entitled ‘Tourist Selection Indicators and Selection Techniques’ which fell within the scope of the request. The Tribunal agreed with this approach, taking account of the requester’s failure to identify a legitimate interest in public disclosure of the names of those officials:
“We do not accept the argument that the officials would not have expected their names within the document to be made public and were not given compelling evidence of this. We were given no information as to their specific grading but they were described in the document as ‘lead contributer’ and ‘lead postholder’. They clearly have some responsibility in relation to the work. We were given no compelling evidence that disclosing their names would result in victimisation, insult or any form of danger. However, we do accept that the officials would prefer not to have their names identified and that might in itself represent a certain right and freedom or legitimate interests in itself. In any event, to process personal data, it needs to be necessary to pursue the purposes of legitimate interests pursued by others. In this case, we do not find that the Appellant has shown any legitimate interest in the names of the officials being disclosed to the public under FOIA. We conclude that the information is therefore exempt from disclosure.”
Another recent Tribunal decision on the disclosure of names is Roberts v IC and Dyfed Powys Police Authority (EA/2012/0032).
The issue of disclosure of names pursuant to an FOI request is a difficult one. As can be seen from this discussion of Tribunal decisions, a number of different factors have to be weighed in the balance. A blanket approach will not work.
Whilst on the subject of names, does an FOI requestor have to give his/her real name? Read the answer here as well as a really bad joke!
Ibrahim Hasan will be discussing this and other recent FOI decisions in the FOI Update workshop on 13th March 2013.
Do you want an international recognised qualification in FOI? The ISEB Certificate in Freedom of Information starts in Birmingham on 26th March 2013.
Proposed EU Data Protection Regulation and Research
David Erdos believes a bid to tighten European data protection will have a chilling impact on social science and humanities research. He writes:
Even with the advent of Web 2.0, data protection law is still often seen as technical and only narrowly applicable. Technical abstruseness aside (and data protection’s reputation here is certainly deserved), this understanding could not be more wrong. The existing European data protection framework really is breathtaking in scope. It applies to anything done electronically with any information about an identified or identifiable person – possibly including the dead. According to the European Union, even innocuous details in the public domain are protected (perhaps even the title of an author’s book). Moreover, if the information reveals the particulars of, for example, a person’s ethnic origin, political opinions, religious belief, trade union membership, health or criminality, then it is classed as “sensitive” and subject to even tighter controls. The European data protection framework is not only broad but often onerous. Barring specific exceptions (including a liberal one that can be invoked for journalism, literature and the arts), there is a presumption that individuals will be informed about the processing of data about them and given a right to object, that the processing of “sensitive” personal information will be banned and that no personal information will be transferred outside the European Economic Area without “adequate protection”.
So the popular perception of data protection is woefully inaccurate – which leads to a radical underestimation of the threat these regulations pose to the enjoyment of other fundamental rights and the pursuit of legitimate activities. Nowhere is this more the case than in social science and humanities research. Since the advent of the EU’s framework in the 1990s, researchers have witnessed dramatic restrictions on their freedom to use “sensitive” data and to deploy covert methods. Coupled with the growth of sometimes intrusive “ethical review” policies, the barriers and burdens placed in the way of even ordinary, innocuous, yet socially beneficial research and on researchers have become considerable.
It might have been hoped that the proposed EU Data Protection Regulation would provide an opportunity to reverse this. But if the European Parliament’s recently published draft amendments are anything to go by, the converse is true.
This article was originally published in the 14-20 February 2013 edition of Times Higher Education and is published with the author’s permission. You can also read it on the Constitutional Law website.
The draft EU DP Regulation will be examined in our forthcoming 1 hour Data Protection Update Webinar : http://www.actnow.org.uk/courses/930
Leveson: What future for Data Protection?
The Leveson Report has finally been published.
The Report recommends that a tougher form of self-regulation backed by legislation should be introduced to uphold press standards. Much has already been written (http://www.bbc.co.uk/news/uk-20543936) and will continue to be written about this central recommendation and whether it is good or bad for democracy and a free press. But amid the furore about whether the Prime Minister should or should not accept the central recommendation, it is easy to forget that the report will also have implications for Data Protection Act and the Information Commissioner.
One of the areas that Lord Justice Leveson was required to consider was ‘the extent to which the current policy and regulatory framework has failed, including in relation to data protection’.
I started writing a blog post on the way back from London, and got as far as the above, when an e mail from the good people at 11KBW (Panopticon Blog) landed in my inbox.
On well if you can’t beat them, read them! Here is their excellent analysis of the DP recommendations of Leveson:
I was only training round the corner and passed the QE2 centre where LJ Leveson was giving his press conference. Perhaps, I should have camped out overnight to beat the Panopticon Team?
Privacy Conference – Call for Papers
The Fifth Northumbria Information Rights Conference will take place on Wednesday 1 May 2013 at the Centre for Life, Newcastle Upon Tyne, UK. The theme of the conference will be “Changing notions of privacy”.
The aim of the conference is both to explore developing understandings of privacy, and the tensions that exist between privacy, openness and freedom of expression. The following topics will be explored within the overall theme, and papers will be grouped for presentation accordingly:
- What is privacy?
- Privacy v freedom of expression
- Technology and the challenges of protecting privacy
- Privacy in a commercial context
- Privacy and the Freedom of Information Act 2000
- Privacy or openness
- Privacy and the Data Protection Act 1998
The university will also consider abstracts which do not fall within these themes but which are nonetheless relevant to the overall theme.
This call is open to academics, postgraduate students and practitioners from all disciplines, but particularly law, politics, information science and records management. Ibrahim Hasan presented a paper to this conference last year examining the Government’s proposals to change RIPA and whether they were a sledgehammer to crack a nut. We would urge our readers to get involved.
Those interested in presenting a paper are invited to submit abstracts to the conference administrator Maureen Cooke: email maureen.cooke@northumbria.ac.uk. Abstracts should be submitted by 7th December 2012. They should not exceed 300 words. Submission must be by Word document e-mail attachment at the email address shown above and should include, in addition to the abstract, your title, name and organisation/institutional affiliation and your email address for correspondence.
All proposals will be reviewed, and successful applicants will be notified at the latest by 21st December 2012. Please contact maureen.cooke@northumbria.ac.uk for any general enquiries about the conference or telephone 0191 243 7597.
RIPA, CHIS and the IPT
A recent legal case about undercover police officers’ activities whilst investigating protest groups, has raised the importance of RIPA forms being completed correctly and care being taken when authorising them.
Ten women have launched a legal action claiming they were tricked into forming “deeply personal” relationships with undercover police officers acting as a Covert Human Intelligence Source (CHIS) under Part 2 of the Regulation of Investigatory Powers Act 2000 (RIPA). The case is the first civil action to be brought before a court.
Three of the women referred to in court had intimate relationships with Mark Kennedy, who spent seven years living as an environmental campaigner. Kennedy’s deployment was made public last year after activists worked out he was a police spy.
Lawyers for the police are currently applying to have the case moved from the High Court to “a secret Tribunal”. Normally cases involving a breach of RIPA are heard by the Investigatory Powers Tribunal (IPT). Most cases heard by the Tribunal are in private and not open to the media. Very few judgements are published. Most cases are about conduct by, or on behalf of, the Intelligence Services (MI5, MI6and GCHQ). The Tribunal has the power to award damages to complainants and to quash or cancel any authorisation to do the surveillance.
Not surprisingly, the IPT is the forum of choice for the police in this case. According to a report in The Guardian:
“Monica Carrs Frisk QC, representing the police, said their argument was not about denying the women remedy, but determining the correct forum for determining their claims.The police argue the case should be heard in the investigatory powers tribunal, as it was set up specifically to consider allegations of unjustifiable surveillance by the state.They also argue they may be unable defend the case because they have a long-established policy of neither confirming nor denying the identity of undercover police officers.”
When the Kennedy case came to light, Her Majesty’s Inspectorate of Constabulary (HMIC) conducted a report into the circumstances. It concluded that, whilst undercover officers deployed into protest communities gathered intelligence which enabled the police to prevent acts of serious violence, there was serious intrusion into the lives of others, and this risk needs to be better managed in the future.
More will come about these cases especially if (as is likely) the civil case remains in the High Court. The circumstances shows the importance of all public authorities, not just the police, considering the applicability of Part 2 of RIPA , especially the CHIS provisions, very carefully when engaging staff to “go undercover”. In addition to the usual considerations of necessity and proportionality, the CHIS authorisation form requires a risk assessment to be done, together with a need to have a separate CHIS Handler and a Controller. Detailed records also need to be kept in accordance with the RIPA (Source Records) Regulations 2000 (SI 2000/2725). If these roles were carried out correctly then abuses of RIPA, as in this case, would be very rare.
Of course local authorities are very infrequent users of the CHIS process (and they certainly do not authorise CHIS operations involving sleeping with the targets!). Any potential for abuse has been minimised even further by the Protection of Freedoms Act 2012 (sections 37 and 38) which came into force on 1st November 2012. This changes the procedure for the authorisation of local authority surveillance under RIPA. From 1st November, local authorities have been required to obtain the approval of a Magistrate for the use of any one of the three covert investigatory techniques available to them under RIPA namely Directed Surveillance, the deployment of a Covert Human Intelligence Source and accessing communications data. On 5th November, Gateshead Council received (what could be) the first Magistrates’ approval.
The case of Mark Kennedy (and others) does beg the question; Is it time the police were required to seek judicial approval for surveillance under RIPA? Should we even stop there? What about surveillance abuses by the press which have come to light as a result of the Leveson Inquiry? Is it time to RIPA it up and start again?
Act Now can help you prepare for the new RIPA process. We have an update course in December in London. If you would like advice on what needs to be done or customised in house training, please get in touch.
Finally all RIPA authorities need to revise their guidance and policy documents. See our RIPA Policy and Procedures Toolkit.
Nobody cares for me. Signed DC.
| Dear Mr xxxxxxxx,
As a registered user of www.tpexpress.co.uk we are legally required under the Data Protection Act 1998 to contact you with the information outlined below. Please note: This is not a marketing communication and does not affect your opt-in/out preferences for marketing emails. What is changing? What does this mean to you? |
Can anyone tell me which section of the Act requires a Data Controller to inform a data subject of a change of data controller? Or is it just good business practice? Or just plain “we don’t know what we’re doing”?
Answer on a postcard please to
DPO, Customer Relations, Some Train Operator, Leaves on the line, Adelstrop.


