Category Archives: Information Commissioner

It’s our Right to Know, Mr ICO

On 29 August the Information Commisioner’s Office (ICO) served a monetary penalty notice (MPN) of £100,000 on Aberdeen City Council. MPNs can be served on a data controller under section 55A of the Data Protection Act 1998 (DPA) for a serious contravention of the Act of a sort likely to cause serious damage or serious distress. In this instance, the ICO explained

sensitive information relating to social services involvement with several individuals [was] published online. The information included details relating to the care of vulnerable children.

The circumstances under which this happened were

a council employee accessed documents, including meeting minutes and detailed reports, from her home computer. A file transfer program installed on the machine automatically uploaded the documents to a website

Many people in the field of information rights have concerns that there is a significant lack of understanding on the part of many about the risk of inadvertently disclosing personal data on the web. In view of this, I though I would simply ask the ICO, and the Council, what website was involved, in order to inform my understanding. So I tweeted

What “website” were the files uploaded to?

I reminded the ICO and the Council on several occasions about this, and pointed out it was a valid request under the Freedom of Information Act 2000 (FOIA) and Freedom of Information (Scotland) Act 2002 (FOI(S)A), even though I had really only wanted a quick factual reply. The Council have asked me to contact them separately to make the FOI(S)A request, and I’m aware the Scottish Information Commissioner takes a different view on tweeted requests to her counterpart for the rest of the UK, so I’ve banged in a request at WhatDoTheyKnow. The ICO, by contrats, did treat my tweet as a valid request (although I got no acknowledgment of this, contrary to their good practice guidance) and responded yesterday on the twentieth working day, with a link to their disclosure log

Those who know me will be unsurprised to know that I don’t accept the refusal, and also unsurprised to know that, on International Right to Know Day 2013 I’ve submitted a crashingly pompous request for ICO to conduct an internal review. Here it follows, in all said crashing pomposity:

Please review your refusal to disclose information.

On 29 August you served a Monetary Penalty Notice on Aberdeen City Council

“after a council employee accessed documents, including meeting minutes and detailed reports, from her home computer. A file transfer program installed on the machine automatically uploaded the documents to a website, publishing sensitive information about several vulnerable children and their families, including details of alleged criminal offences”

I asked, on 30 August, “What ‘website’ were the files uploaded to?”

You have refused to disclose, claiming the exemption at section 44 of the Freedom of Information Act 2000, which provides an exemption “if disclosure [of the information] (otherwise than under this Act) by the public authority holding it…is prohibited by or under any enactment”. You say disclosure is prohibited, because “the information was provided to the ICO in confidence as part of our regulatory activities” and that the provisions of section 59(1) of the Data Protection Act 1998 forbid disclosure. Section 59(1) says

“No person who is or has been the Commissioner, a member of the Commissioner’s staff or an agent of the Commissioner shall disclose any information which—

(a)has been obtained by, or furnished to, the Commissioner under or for the purposes of the information Acts [of which FOIA is one],

(b)relates to an identified or identifiable individual or business, and

(c)is not at the time of the disclosure, and has not previously been, available to the public from other sources

unless the disclosure is made with lawful authority”

I am happy to concede that a) and b) are met here, but not c). This is because section 59(2) explains what “with lawful authority” means. Firstly, and largely as an aside, section 59(2)(a) says that a disclosure is made with lawful authority if

“the disclosure is made with the consent of the individual or of the person for the time being carrying on the business”

I am surprised you do not feel that, in your role as a public authority but also as the regulator for Freedom of Information, it would be prudent and transparent simply to ask the Council whether it consents. Nonetheless, on a strict reading of the law, I concede that you do not have an obligation to do so.

Secondly (and I note you do not even address this important provision), section 59(2)(e) says that disclosure is made with lawful authority if

“having regard to the rights and freedoms or legitimate interests of any person, the disclosure is necessary in the public interest”

I would argue that analysis of whether this provision permits disclosure requires a two-fold test. Firstly, is disclosure necessary in the public interest? Secondly, if it is, do the rights and freedoms or legitimate interests of any person militate against this public-interest disclosure?

On the first point, I am not aware of any direct authority on what “necessary” means in section 59(2)(e) of DPA, but I would argue that it imports the meaning adopted by leading European authorities. Thus, as per the high Court in Corporate Officer of the House of Commons v The Information Commissioner & Ors [2008] EWHC 1084 “‘necessary”…should reflect the meaning attributed to it by the European Court of Human Rights when justifying an interference with a recognised right, namely that there should be a pressing social need and that the interference was both proportionate as to means and fairly balanced as to ends”. It is my view that there is a pressing social need to recognise the risks of indavertent uploading to the internet, by public authorities and others, of sensitive personal data, especially when this is by automatic means. Other examples of recent incidents and enforcement action illustrate this. For instance, as your office is aware, there have been reports that a regional Citizens’ Advice Bureau has indavertently made available on the internet very large amounts of such data, probably because of a lack of technical knowledge or security which resulted in automatic caching by Google of numerous files https://informationrightsandwrongs.com/2013/09/24/citizens-advice-bureaucracy/. Also for instance, as you are aware, there have been many many examples of indavertent internet publishing of personal data in hidden cells in spreadsheets http://www.ico.org.uk/news/blog/2013/the-risk-of-revealing-too-much. There is a clear lack of public understanding of the risks of such indavertent disclosures, with a consequent risk to the privacy of individuals’ often highly sensitive personal data. Any information which the regulator of the DPA can disclose which informs and improves public understanding of these risks serves a pressing social need and makes the disclosure “necessary”.

On the second point, I simply fail to see what rights and freedoms or legitimate interests of any person can be engaged, let alone suffer a detriment by disclosing what public website the Council employee uploaded this to. If there are any, it would be helpful if your response to this Internal Review could address this. It may be that you would point to the information having been provided to you in confidence, but I similarly fail to see how that can be: was this an express obligation of confidence, or have you inferred it? In either case, I would question (per one the elements of the classic formulation for a cause of action in breach of confidence given by Megarry J in Coco v A.N.Clark (Engineers) Ltd [1969] R.P.C. 41) whether the information even has the necessary quality of confidence (this was a public website after all).

I hope you can reconsider your decision.

best wishes

1 Comment

Filed under Confidentiality, Data Protection, FOISA, Freedom of Information, human rights, Information Commissioner, monetary penalty notice, transparency

Must Try Harder

So, I managed to get a piece run on the Guardian Public Leaders network on the continuing incidents of or risks of exposure of sensitive personal data in pivot tables. I tried to argue that those in the know probably know about these risks, and that those not in the know don’t. I suggested the Information Commissioner’s Office (ICO) and the government could do more to alert the latter.

Although I got nice and positive feedback from friends/colleagues/fellow professionals, there appears to have been very little interest. Clearly it’s not a subject that interests lay people (or rather, it’s probably a subject which actually repels lay people). But that was rather my point: as long as the relevant regulators and policy-makers don’t take sufficient steps to issue warnings and guidance these and similar breaches of data security will continue to happen.

What I’m slightly surprised at is the lack of any response from the ICO. I noticed that Tim Turner asked the ICO twitter account if they had a response to the piece, but, unless it was off-line, he appeared to get no response. And I asked their press office, again, with no reply (maybe the press office was the wrong place to ask?).

In the article I also called on government departments to do more. That’ll be my next move. The problem of inadvertent internet disclosure of sensitive data, normally through ignorance of technology, continues, and it goes broader than pivot tables. As public authorities, in particular, are being required to open up more and more data to promote transparency and economic growth, this is going to become more and more serious. We can’t pretend the gulf between those ambitions and the technological knowledge of some of those doing the “opening up” is a minor problem. Authorities need guidance, and, where appropriate, warnings, and these need to be targetted at the right people within organisations. The ICO and government cannot always rely on, say, data protection officers to do this.

Leave a comment

Filed under Breach Notification, Data Protection, Information Commissioner, transparency

ICO – no Code of Practice for data protection and the press

On the 12th of August the Information Commissioner’s Office (ICO) announced that, following a period of consultation, it would not – contrary to previously-stated intentions – be issuing a Code of Practice on Data Protection and the Press. The proposed Code had been in response to Lord Justice Leveson’s recommendations that the ICO produce

comprehensive good practice guidelines and advice on appropriate principles and standards to be observed by the press in the processing of personal data

As the ICO’s Steve Wood says in the blogpost

Leveson did not stipulate a code but we proposed it as a possible vehicle for the guidance

Indeed they did, stating at the time that it was not

the ICO’s intention to purport to set ethical standards for journalists, or to interfere with the standards which already apply under relevant industry guidance, such as the Editors’ Code of Practice, the Ofcom Broadcasting Code, and the BBC Producers’ Guidelines. Nevertheless, the existing industry guidance does not consider the requirements of data protection law in any detail, and the ICO’s code will complement existing industry standards by providing additional coverage of this issue

However, the latest announcement – that the ICO is “looking to produce a guidance document” rather than carrying through with the issuing of a Code of Practice – is accompanied by the publishing of a summary of consultation responses to the draft Code of Practice. In fairness to the ICO, those who responded appeared not to want a Code, and, as any public authority will be aware, a consultation in name only (e.g. one with a predetermined outcome) is unlikely to be a lawful one. We are not told specifically who these responses were from, but that they were from “several media companies, individuals, regulators and representative bodies” (although there were only 16 responses overall, a figure which perhaps shames us all, or, alternatively, supports a view that not that many people were particularly aware of or bothered about the consultation). Seven responses specifically rejected the idea of a Code of Practice, with some concerns being

a code of practice implies a new set of rules or regulations;
risk of the ICO becoming a ‘mainstream de facto regulator of the press’;
risk of a proliferation of codes; and
risk of potential confusion with existing codes such as the Editors’ Code.

After pausing to note that the now-proposed ICO guidance will apparently be issued in draft (for further consultation) before the end of the year, which is a long, long way from meeting Leveson’s recommendation that any guidance be implemented within six months of his report,  it might be helpful to look at just why some respondents might have been unhappy with a Code of Practice, as opposed to “mere” guidance.

As is well-known, there is a very broad exemption, at section 32, from most of the obligations of the Data Protection Act 1998 (DPA) where:

(a)the processing is undertaken with a view to the publication by any person of any journalistic, literary or artistic material,
(b)the data controller reasonably believes that, having regard in particular to the special importance of the public interest in freedom of expression, publication would be in the public interest, and
(c)the data controller reasonably believes that, in all the circumstances, compliance with that provision is incompatible with the special purposes [emphasis added]

This, broadly, means that, as long as personal data is processed with a view to journalistic publication (note: not that it has to be published) it is exempt from effectively all of the DPA (although not the 7th “security” principle) as long as the press body “reasonably believes” publication would be in the public interest. This has generally been taken to mean that it will be extremely difficult for a data subject to enforce her rights against, or for the ICO to regulate the activities of, the press. And, indeed, instances of successful DPA claims, or successful enforcement, against the press, are rare (privacy cases against the press, where they have included DPA claims, have tended to see the latter sidelined or dropped in favour of meatier claims in tort – see e.g. Douglas v Hello [2005] EWCA Civ 595 (where the DPA claim did succeed in the first instance, but only resulted in nominal damages) and Campbell v MGN [2002] EWCA Civ1373 (where, by contrast, the section 32 defence succeeded)). As Leveson LJ says

the effect of the development of the case law has been to push personal privacy law in media cases out of the data protection regime and into the more open seas of the Human Rights Act [page 1070 of Leveson Report]

 As everyone knows, the press kicked back strongly against parliament’s proposal of a Royal Charter for the press (that proposed Charter itself being the result of a rowing back by the political parties from Leveson’s proposal for some form of direct statutory underpinning of any regulatory scheme (“Guaranteed independence, long-term stability, and genuine benefits for the industry, cannot be realised without legislation”)). Both proposed Charters (the parliamentary-backed one and the Pressbof-backed one ) are to be considered by the Privy Council.

What has perhaps not been so widely-known, or widely-understood was that an ICO Code of Practice, if it had been designated by the Secretary of State (by means of an Order pursuant section 32(3)(b) of the DPA), would itself have constituted a form of statutory underpinning. This is because a Code designated in this way could have been taken into account by a court, or by the ICO, when determining whether personal data had been processed (for the special purposes) by the data controller in the reasonable belief that it had been in the public interest. The now-proposed “mere” guidance will not have the same status.

This might seem a minor point, and perhaps it is (bear in mind that there are already other Codes of Practice designated pursuant to section 32(3)(b), including the Press Complaints Commission Code of Practice) but, although we don’t know specifically who responded to the ICO’s consultation, it is safe to say that those who did included in their number organisations strongly opposed to (and alive to the threat of) any form of what they perceive to be statutory regulation of the press.

In this post I draw heavily on previous posts by Chris Pounder, on his Hawktalk blog, and if, as he suggested earlier this year, the then-proposed ICO Code raised the prospect of enhanced protection for ordinary data subjects, it is perhaps the case that the dropping of the proposal means no such enhanced protection.

1 Comment

Filed under Data Protection, human rights, Information Commissioner, journalism, Leveson

Pivot tables and databreaches

About a year ago I first became aware of reports of disturbing inadvertent disclosures of personal data (often highly sensitive) by public authorities who had intended only to disclose anonymous and/or aggregate data. These incidents were occurring both in the context of disclosures under the Freedom of Information Act 2000 (FOIA) and in the context of proactive disclosure of datasets. Mostly they were when what had been disclosed was not just raw data, but the spreadsheet in which the data was presented. Spreadsheet software is often very powerful, and not all users necessarily understand its capabilities (I don’t think I do). By use of pivot tables data can be sorted, summarised etc, but also, from the uninitiated or unwary, hidden. If the person who created or maintained a spreadsheet containing a pivot table is not involved in the act of publicly disclosing it it is possible that an apparently innocuous disclosure will contain hidden personal data.

Clearly such errors are likely to constitute breaches – sometimes very serious breaches – of the Data Protection Act 1998 (DPA) Those of us who were aware of a number of these inadvertent breaches were also aware that, if public authorities were not alerted to the risk a) the practice would continue and b) potentially large numbers of “disclosive” datasets would remain out in the open (in disclosure logs, on WhatDoTheyKnow, in open data sets etc). But we were also aware that, if the situation was not managed well and quietly, with authorities given the opportunity to correct/withdraw errors, inquisitive or even malicious sorts might go trawling open datasets for disclosures which could potentially be very damaging and distressing to data subjects.

It was with some relief, therefore that, following an earlier announcement by WhatDoTheyKnow, the Information Commissioner’s Office (ICO) finally gave a warning, and good guidance, on 28 June (although this relief was tempered by finding out, via Tim Turner, that the ICO had known about, and apparently done nothing about, the problem for three years). At the same time the ICO announced that it was “actively considering a number of enforcement cases on this issue”.

It appears that, according to an announcement on its own website, Islington Council is the first recipient of this enforcement. The Council says it has

accepted a £70,000 fine from the Information Commissioner’s Office (ICO) after a mistake led to personal data being released

after it

responded to a Freedom of Information (FOI) request asking for information including the ethnicity and gender of people the council had rehoused. The response, in the form of Excel spreadsheet tables, included personal information concealed behind the summary tables

Fair play to Islington for acknowledging this and agreeing immediately to pay the monetary penalty notice. And if some of the other reported breaches I heard about were as bad as they sounded £70,000 will be at the lower end of the scale.

(thanks to @owenboswarva on twitter for flagging this up)

UPDATE:

The ICO has now posted details of the MPN, and this clarifies that the disclosure was made on WhatDoTheyKnow and was only identifed when one of their site administrators noticed it.

Leave a comment

Filed under Breach Notification, Data Protection, Freedom of Information, Information Commissioner, monetary penalty notice, transparency

Academic Freedom and FOI

Pointed observations in a judgment which are not directly related to the matters pleaded are usually worth noting. Those in a recent case involving the PACE trial and Queen Mary, University of London, are essential reading for academics and support staff who deal with FOI

In a ruling handed down this week the First-tier Tribunal (Information Rights) (“FTT”) has upheld the Information Commissioner’s (IC) decision that Queen Mary, University of London, was entitled to rely on the exemption at section 36(2)(b)(1) and (2) of the Freedom of Information Act 2000 in refusing to disclose minutes of the Trial Steering Committee and Trial Management Groups of the Pace Trial. The trial had been set up to compare and test the effectiveness of four of the main treatments currently available for people suffering from chronic fatigue syndrome (CFS), also known as myalgic encephalomyelitis (ME), but it attracted considerable criticism from some quarters. In the words of the FTT

There has been a storm of comments about this study. There had been deeply wounding personal criticisms of individuals concerned and over the years individuals in this field of research and treatment have withdrawn from research in the face of hostile irrational criticism and threats.

The FTT found that the exemption was engaged:

it is pellucidly clear that the progress and conduct of research in this area would be hampered by the publication of minutes of meetings such as sought by this request because individuals would be less willing to engage in research, participate in steering committees, provide guidance, debate issues about the conduct of research as fully and frankly as they otherwise would; as fully and frankly as would most benefit the research and the patients it is intended to help

and the public interest favoured maintaining the exemption:

the appellant’s arguments in favour of disclosure of the minutes when so much has been made available publicly in relation to this research and been subjected to such high levels of independent scrutiny do not outweigh the considerable weight to be given to the public interest in maintaining the safe space for academic research

But the FTT then made wide-ranging and significant observations about the concept of academic freedom and its relation to FOI. The decision cites Article 13 of The Charter of Fundamental Rights of the European Community:

Freedom of the arts and sciences The arts and scientific research shall be free of constraint. Academic freedom shall be respected.

and section 202 of the Education Reform Act 1988 which places an obligation on the University Commissioners to

ensure that academic staff have freedom within the law to question and test received opinion, and to put forward new ideas and controversial or unpopular opinions, without placing themselves in jeopardy of losing their jobs or privileges they may have their institutions

and the FTT stresses the “profound importance” of academic freedom, noting that the IC has an obligation, as an emanation of the state, to give effect to Article 13. The judgment notes that the purpose of universities is to disseminate and generate knowledge and that disclosure of information is their primary purpose (“the activity which imbues the University with its moral significance”). In rather remarkable terms, the seeking of and disclosure of information (from academic institutions) under FOIA is unfavourably compared to this academic dissemination:

A parallel process of dissemination through FOIA is unlikely to be as effective or robust as the process of lectures, seminars, conferences and publications which are the lifeblood of the University. They are likely to be a diversion from the effective evaluation, publication and scrutiny of research through the academic processes. All too often such requests are likely to be motivated by a desire not to have information but a desire to divert and improperly undermine the research and publication process – in football terminology – playing the man and not the ball

One might pause to question whether this unfairly overplays the likelihood of FOIA requests being detrimental to academia, and also overstates the amount of information which is disseminated to the general public through academic research. Part of the reason for FOIA is that it enables the public to access information that public authorities specifically choose not to proactively disclose. One sees similar arguments at play in the apparent prioritising of the “transparency agenda” over FOIA disclosure.

There follows, though, a sensible suggestion for what researchers might consider at the outset of projects. With a view to the obligation to publish and maintain a publication scheme, institutions are advised that

it might well be worth considering at the start of a major project such as this setting out a publication strategy identifying what materials will be produced in the course of the project, which materials will be published and when (this will enable s22 to be considered if FOIA requests are received for such material), and which are unlikely to be published under FOIA as exemptions may be engaged

and the IC is (again with a nod to his Article 13 obligations) prompted to issue guidance on this.

Finally, the judgment suggests that the University missed a trick with this specific request

properly viewed in its context, this request should have been seen as vexatious- it was not a true request for information-rather its function was largely polemical and as such in the light of recent Upper Tribunal judgements might have been more efficiently and effectively handled if treated as vexatious

The Tribunal Judge, Christopher Hughes, has a wealth of experience in the field of academic and medical research. These are crucial observations about the relationship between FOI and academia. We already have a new exemption on its way specifically for academic research (by way of clause 19 of the Intellectual Property Bill) but this decision appears to reinforce the protection that academic research and associated information will be given from FOIA disclosure.

Postscript:

The BMJ has an article on this judgment (behind the paywall, but letters in response are here (thanks to Zuton who has commented below for drawing this to my attention).

8 Comments

Filed under Freedom of Information, Further education, Information Commissioner, Information Tribunal, Uncategorized

Monetary penalties – focus on the breach, not the incident

The Information Tribunal’s judgment in the successful appeal by Scottish Borders Council shows that the ICO needs to focus on the contravention itself, not an incident which might arise from it

looking at the facts of the case, what did happen was in our view a surprising outcome, not a likely one

Sections 55A-E of the Data Protection 1998 (DPA), inserted by the Criminal Justice and Immigration Act 2008, provide for the Information Commissioner (IC) to serve a data controller with a monetary penalty notice (MPN) to a maximum of £500,000 if

  • he is satisfied that there has been a serious contravention of the controller’s obligations to comply with the data protection principles in Schedule One of the DPA, and
  • the contravention was of a kind likely to cause substantial damage or substantial distress, and
  • the contravention was either deliberate or the controller either knew or ought to have known that there was a risk that the contravention of its occurring and that it would be of a kind likely to cause substantial damage or substantial distress, but failed to take reasonable steps to prevent the contravention.

In its judgment, handed down today, on what is effectively* a successful appeal by Scottish Borders Council, the First-tier Tribunal (Information Rights) (“FTT”) has given guidance on, what is required in order for the IC to be satisfied that a serious contravention was likely to cause substantial damage or substantial distress. In particular, the FTT has clarified that, where the DPA talks about a “serious contravention”, the IC must focus on that, and not on any incident which might follow.

The Monetary Penalty Notice

The events giving rise to the original MPN (still currently on the IC’s website) are laid out by the FTT in the first two paragraphs of the judgment

Outside Tesco in South Queensferry there are some bins for recycling waste paper. They are of the “post box” type. On 10 September 2011 a member of the public found that one of the bins was overflowing. The material at the top, easily accessible, consisted of files containing pension records kept by a local authority (“Scottish Borders”). It turned out that a data processing company had transferred the information from hard copy files to CDs at Scottish Borders’ request. The data processor had then disposed of about 1,600 manual files in the post box bins at Tesco and at another supermarket in the town.

The police took into their possession all those files which they could reach. They then secured the bins and, with the cooperation of Scottish Borders, it was ascertained that the files concerned had now either been pulped without manual intervention or were now back in the safe keeping of the council.

The IC imposed an MPN of £250,000, finding that there had been a serious contravention of the obligation to comply with the seventh data protection principle (DPP7) which states that

Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.

and that, where, as here, processing of personal data is carried out by a data processor on behalf of a data controller, the latter must choose as the former one who provides sufficient guarantees in respect of its data security measures, and ensure that such processing is carried out under a suitable written contract (I paraphrase).

The contravention here was the failure by the Council to ensure that it engaged an appropriate data processor (to dispose of the pensions records) in an appropriate way (by means of an adequate contract, properly monitored and adequately evidenced in writing).

The IC said that contravention was likely to cause substantial damage or substantial distress (query, which?) to those whose confidential data was seen by a member of the public and that

If the data has been disclosed to untrustworthy third parties then it is likely that the contravention would cause further distress and also substantial damage to the data subjects such as exposing them to identity fraud and possible financial loss

Arguments and findings

The FTT found that there was a contravention. The Council had a long-standing (some 25-30 years) agreement with the data processor but it appears that the contractual arrangement was largely based on informal agreements and assurances. Although it was to an extent evidence in writing, this was still inadequate. Accordingly

the arrangements made by Scottish Borders for processing pension records in July and August 2011 were in contravention of the DPA

Further, the FTT was satisfied that the contravention was serious

the duties in relation to data processing contracts in paras 11 and 12 of schedule 1 are at the heart of the system for protecting personal data under DPA. It is fundamental that the data controller cannot be allowed to contract out its responsibilities [and] the contravention was not an isolated human error. It was systemic

However, counsel for the IC, the redoubtable Robin Hopkins, reminded the FTT that they must focus on the contravention which gave rise to the MPN. In this case, this was distinguishable from the events described in the first two paragraphs of the judgment: the contravention was the breach of DPP7, not the discovery of the data. On this basis, the FTT did not accept that the contravention had been of a kind likely to cause substantial damage or substantial distress. Evidence was taken from David Smith, Deputy IC, and the IC developed an argument focusing on the risks of identity theft, but the FTT seems to have felt that the evidence was either unconvincing (regarding the likelihood of identity theft) or still focused wrongly on what it calls the “trigger point” (the disposal/finding of the files in the bin) rather than the contravention itself. As to the latter

it seems to us that the fact that the data processor was a specialist contractor with a history of 25-30 years of dealings with Scottish Borders carries weight. He was no fly by night. The council had good reason to trust the company.

And, therefore

Focussing on the contravention we have been unable to construct a likely chain of events which would lead to substantial damage or substantial distress. What did happen was of course startling enough. Again, though, looking at the facts of the case, what did happen was in our view a surprising outcome, not a likely one.

This illustrates a fundamental point, but one, it seems, of great significance. It will, no doubt, be seized upon eagerly by any data controller in receipt of a notice of intent to serve an MPN. (It was also, I should acknowledge, anticipated by observations by Tim Turner and Andrew Walsh, both former ICO employees). However, the FTT do stress that although this case did not involve a contravention of a kind likely to cause substantial damage or substantial distress

No doubt some breaches of the seventh DPP in respect of some data might be of such a kind

What now?

I said earlier this was “effectively a successful appeal”. It was in fact an appeal on a preliminary issue (on the liability of the Council to pay an MPN) and under the Data Protection (Monetary Penalties) Order 2010 the FTT may either allow the appeal or substitute such other notice or decision which could have been served or made by the IC. The FTT’s concerns about the Council’s procedures in relation to data processing contracts were “too serious” for them simply to allow the appeal, and they are – pending discussions between the IC and the Council – considering whether to issue an enforcement notice.

Notwithstanding the outcome of those discussions, this is an important judgment to be read alongside the unsuccessful MPN appeal by the Central London Community Healthcare NHS Trust. Until an MPN case gets appealed further we will not have binding authority, but the lines are perhaps becoming a bit clearer for data controllers, and, indeed for the ICO.

There were some interesting comments and observations by the FTT on “other issues canvassed in the course of [the] appeal but which it has not been necessary to resolve”. I hope to post a follow-up about these in due course.

Leave a comment

Filed under Data Protection, enforcement, Information Commissioner, Information Tribunal, monetary penalty notice

Data Protection audits in the NHS

Do the results of an anonymous survey into data protection practices and attitudes of junior doctors provide justification for compulsory audits?

Continue reading

4 Comments

Filed under Data Protection, Information Commissioner, NHS

Take the train(ing)

IG policies are essential, but not much use if you don’t comply with them

In NHS and Social Care settings a standard requirement is that all staff are trained in information governance (a large component of which is data protection): “Information Governance awareness and mandatory training procedures are in place and all staff are appropriately trained” (IG Toolkit v11) and “Ensure all staff are trained, updated and aware of their responsibilities” (Local Government Data Handling Guidelines). If an organisation suffers a serious breach of data security, and the Information Commissioner’s Office (ICO) investigates, one of the first things they will look at is whether staff were appropriately trained. If they weren’t, enforcement action, possibly in the form of a monetary penalty notice, is highly likely.

It is vital, therefore, that all organisations have a policy that all relevant staff are trained (and in some organisations – like the NHS and local authorities – that will normally mean all staff).

But, policies only work if they are implemented, enforced and monitored. The ICO has recently published an Undertaking (the “last chance saloon” before formal enforcement action) signed by the Northern Health and Social Care Trust. This arose following an incident which

involved confidential service user information being faxed from a ward in Antrim Hospital to a local business in error. The information was intended for the Trust’s Community Rehabilitation Team. The referral form contained sensitive clinical data

Although the Trust had a “fax policy” (good) it wasn’t complied with (bad) but also 

The Commissioner’s investigation into the Trust revealed that despite the Trust having introduced what should have been mandatory Information Governance training for all staff, the majority of staff involved in these incidents had not received this training. This highlighted a potentially serious failing in respect of staff awareness of Information Governance policies. In particular, the failure to monitor and enforce staff completion of training was a concern.

This failure constituted a breach of the seventh data protection principle (“Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data”). It is highly likely that, if training requirements had been complied with, no action would have been (or would have been able to be) taken, because there would have been no breach.

Put simply, if a data controller can show it has complied with the seventh data protection principle, and there is an accidental data security breach – however horrendous – then (providing there are no breaches of other principles) no sanctions will arise.

It’s in every data controller’s interests not only to require appropriate data protection training for staff, but also to ensure that it has been taken.

Leave a comment

Filed under Data Protection, employment, Information Commissioner, monetary penalty notice

Small Council, Big Burden

“Parish Councils are the smallest unit in our system of elected government…In rural areas their jurisdiction typically extends to a single village or perhaps two or three, depending on size…Their budget generally runs to a few thousand pounds a year…They generally employ one part – time clerk to perform secretarial and administrative tasks… Their income derives from their precept – usually a small fraction of the Council tax. Most Parish Councils probably have little experience of FOIA requests for information.”  (EA/2013/0022)

When judgment was handed down earlier this year in the key case on vexatious requests under the Freedom of Information Act 2000 (FOIA), Wikely J said

It may be helpful to consider the question of whether a request is truly vexatious by considering four broad issues or themes – (1) the burden (on the public authority and its staff); (2) the motive (of the requester); (3) the value or serious purpose (of the request) and (4) any harassment or distress (of and to staff).

The first of these comes into important focus in a recent decision by the First-tier Tribunal (Information Rights) (FTT). In Harvey v ICO and Walberswick Parish Council (EA/2013/0022) the Council had received nearly five hundred FOIA requests (from various requesters) in a two-year period  (by way of contrast, county councils (which are hugely better-resourced) will perhaps have received about 2000-3000 over a similar period). It is not clear how many of these were made by the applicant, but the judgment says she was one of four residents who made the majority of them (which appear to stemmed from planning issues). At some point the Council had ill-advisedly purported to exclude requesters from making further requests. This in itself had only generated more requests. At one point all the parish councillors resigned as a result of the stress, tension and acrimony.

The request here was of a type often called a “meta-request” (a request about a previous request). It was for information about fifty previous requests refused on the grounds of cost. This meta-request was also refused, on the basis that, per section 14(1) of FOIA, it was vexatious. The FTT noted the dicta of Wikely J to the effect that

The purpose of section 14 must be to protect the resources (in the broadest sense of that word) of the public authority from being squandered on disproportionate use of FOIA.

and applied this to the fact that the public authority in this case was a small parish council

Parish councils are not equipped to handle a torrent of FOIA requests and, we suppose, very rarely do so. If WPC was failing to handle such matters efficiently, to bombard it with an unending further stream of requests and demands seems an odd way of helping it to improve its service […] the grossly excessive burden placed upon the resources of WPC by the flood of requests, of which this was one, is the decisive consideration in any assessment as to whether it was vexatious.

A hero emerges from the judgment (no doubt the four requesters do not see her in this light): Mrs Gomm, the parish clerk. Before she arrived “FOIA issues –and probably other council functions – were not efficiently handled” but, in far exceeding her hours and “left at one stage to her own devices and with no authorised source of income for her services” she wrote “admirably clear and courteous responses, which accurately addressed the issues of law involved”, in the face of “relentlessly agressive” correspondence.

(I wonder if Mrs Gomm might have been behind the rather odd outcome to the events, whereby the parties agreed the pragmatic step of disclosing the information just before the appeal hearing (this was not, said the FTT, an acknowledgment that the request had not been vexatious).)

The judgment shows that – although all public authorities have the same obligations under FOIA-  the smaller they are, the greater the burden, and that this can come into play on an analysis of whether a request has been vexatious. The judge ends with an odd but memorably alliterative observation:

Remorseless repetition of regressive requests is not a sensible way to improve performance

Leave a comment

Filed under Freedom of Information, Information Commissioner, Information Tribunal, vexatiousness

The loophole to avoid enforcement?

Cabinet Office, FOI, Financial Times, Christopher Graham, blah blah blah

To recap. The Financial Times recently ran a resounding editorial on FOI, the ICO and the Cabinet Office, lauding the first, criticising the second’s lack of enforcement against the first, and lambasting the third. The Information Commissioner himself, Christopher Graham, replied in rather hurt tones, defending his office. Both Paul Gibbons (FOIMan) and Tim Turner have blogged on this. Here are my oar-sticking-in-coattail-hanging observations.

A key measure used by the Information Commissioner’s Office (ICO) to assess public authorities’ compliance with the Freedom of Information Act 2000 (FOIA) is the percentage of requests which are responded to within the statutory twenty day timescales. The guidance on this says

The ICO is may contact authorities [sic] if…(for those authorities which publish data on timeliness) – it appears that less than 85% of requests are receiving a response within the appropriate timescales.

Let’s ignore the obvious and worrying point that this is an encouragement not to publish such data. Fortunately for our purposes, government departments do commit to doing so, and quarterly reports covering the whole of central government are published. I can’t actually find them all on one page, so here are the reports for the last four quarters

April-June 2012
July-September 2012
October-December 2012
January-March 2013 

If you scroll through those datasets you’ll see that, over the last four quarters, the Cabinet Office has managed to respond to FOI requests within the statutory time limit or with a permitted extension in 92, 93, 95 and 86% of cases. Pretty good eh? This keeps them out of reach of the ICO radar. And, in fact, just prior to this, the Cabinet Office had been monitored by the ICO, and been required to sign an undertaking to improve, after appalling previous statistics had showed compliance in only 42 and 55% of cases in two quarters. After this monitoring period (the MoD were also monitored) the ICO announced

Both authorities have now improved their response times with over 85% of information requests being answered within the time limit of 20 working days and are working hard to deal with outstanding requests where responses have been unduly delayed. The ICO will continue to offer support and advice to help both Departments to ensure that outstanding requests are cleared as soon as possible.

However, what does “with a permitted extension” mean? It means, that in complex cases where a public authority needs more time to consider whether the public interest favours disclosure, it can disapply the twenty-working-day deadline and extend its time for compliance indefinitely, subject to reasonableness (although the ICO says it should be no more than an extra 20 days, he cannot enforce that). So let’s go back to those figures and see how the Cabinet Office would do if there wasn’t this potential loophole. If one simply asks “what percentage of requests were responded to within 20 working days?”, the figures are in fact 77, 77, 79 and 74%. Of course, without access to individual cases it is impossible to say whether these multiple extensions to consider public interest were made legitimately or not. However, the Cabinet Office appears to claim the extension much more than most other departments (the Foreign and Commonwealth Office has similar figures, however).

I am sure the Cabinet Office will claim that the reason it does this is because it has to deal with more complex cases. Maybe that’s the case, but it would be nice if someone could look into it. And, of course, the ICO could. The guidance on how authorities are selected for monitoring doesn’t stop at the 85%-compliance measure. It also says they may contact authorities if 

our analysis of complaints received by the ICO suggests that we have received three or more complaints citing delays within a specific authority within a six month period [or if there is] Evidence of a possible problem in the media or other external sources.

To which I say, ICO, the evidence is clear (look at Tim’s analysis, look at Paul’s, even look again at Chris Cook’s). Compliance stats are not the only measure (and even then they may hide the true picture). The triggers for enforcement are there, but is there a will?

And finally.

3 Comments

Filed under Cabinet Office, Freedom of Information, Information Commissioner, transparency