Category Archives: Uncategorized

Who’s to blame for the Ministerial Veto?

The people to blame for our not being able to see Prince Charles’ lobbying correspondence with the government are not the judges – it’s the people who passed the FOI Act.

So, perhaps to no one’s great surprise, the judicial review application by the Guardian’s Rob Evans of the Attorney General’s ministerial veto has failed. As three of 11KBW’s array of brilliant information law advocates were instructed in the proceedings, I am sure we will see a Panopticon blog post shortly, and I wouldn’t try to compete with what will be the usual clear and percipient legal analysis (for which, also, see this excellent post from Mark Elliott). However, I wanted to address what I see as a potential misapprehension that this was an expression by the High Court that it agreed that the Attorney General was correct to issue a certificate vetoing disclosure of correspondence between Prince Charles and government departments. While the natural outcome of the court’s judgment is that the correspondence will not be disclosed, what was actually to be decided, and ultimately was decided in the Attorney General’s favour, was whether the exercise of his powers was lawful.

Under section 53(2) of the Freedom of Information Act 2000 (FOIA) a decision notice issued by the Information Commissioner (IC) (or later remade by a tribunal) ceases to have effect if an “accountable person” (effectively, either a Cabinet Minister or the government’s senior law officer) issues a certificate stating that he has “on reasonable grounds” decided that there was in fact no prior failure by the government department in question to comply with a request for information under FOIA. It is a power of executive override of a decision made by the statutory regulator (the IC). Its place in the statutory, and constitutional, scheme is what people should be objecting to, particularly in light of what the court in this case found.

The case dates back to the earliest days of the commencement of FOIA. Evans had requested correspondence between Prince Charles and various government departments, but those departments had refused to disclose. In a detailed and complex analysis the Upper Tribunal (the case having been transferred from the First-tier Tribunal) last September decided that, although the FOIA exemption (at section 37) relating to communications with the Royal Household was engaged, the public interest fell in favour of disclosure of the information (two points of note: first, the section 37 exemption, which was at the time of the request a qualified one, subject to the application of the public interest, has since been amended to make it absolute; second, there were other exemptions engaged, but the section 37 was the focal one). 

There was potentially further right of appeal, to the Court of Appeal and, ultimately, the Supreme Court. So why did the government not follow this route? The Campaign for Freedom of Information have issued a press release in which their Director Maurice Frankel says “Ministers should have to appeal against decisions they dislike and not be able simply to overturn them”. I agree (of course) but the reason the government departments did not appeal in this case is because any appeal would have had to have been on a point of law – the more senior courts could not have substituted different findings of fact, or decided whether an exercise of discretion should have been exercised differently. In short, I suspect the government did not appeal because they knew they would have been unsuccessful (or rather, their lawyers would presumably have advised, as lawyers do, that the chances of success were low).

Davis LJ, giving the leading judgment in the High Court, identified that

The underlying submission on behalf of the claimant is, in effect, that the accountable person is not entitled simply to prefer his own view to that of the tribunal

to which he countered

why not? It is inherent in the whole operation of s.53 that the accountable person will have formed his own opinion which departs from the previous decision (be it of Information Commissioner, tribunal or court) and may certify without recourse to an appeal. As it seems to me, therefore, disagreement with the prior decision…is precisely what s.53 contemplates, without any explicit or implicit requirement for the existence of fresh evidence or of irrationality etc. in the original decision which the certificate is designed to override. Of course the accountable person both must have and must articulate reasons for that view…[It] is for the accountable person in practice to justify the certification. But if he does so, and that justification comprises “reasonable grounds”, then the power under s.53(2) is validly exercised. Accordingly, the fact the certificate involves, in this case, in effect reasserting the arguments that had not prevailed before the Upper Tribunal does not of itself mean that it is thereby vitiated

 The power to issue a certificate exists under section 53(2), even if, as Lord Judge said, such a power “appears to be a constitutional aberration”. If it exists, it can be exercised, subject to it being done so lawfully. To admit of another interpretation, says David LJ, would be (taken with the claimant’s other arguments) to 

greatly [narrow] the ostensible ambit of s.53. As a matter of statutory interpretation I can see no justification for such a limitation, either on linguistic grounds or on purposive grounds

Parliament chose to enact s53, and any potential inherent constitutional imbalance or threat to the rule of law in its having done so is overcome by the availability of judicial review:

for the purposes of s.53 of FOIA, Parliament has provided the procedure by which this statutory provision is to be mediated. It is to be mediated, on challenge by way of judicial review, by the courts assessing whether the Secretary of State has certified “on reasonable grounds”. That involves no derogation from the fundamental principle of the rule of law: on the contrary, it is an affirmation of it.

For the same reasons, any challenge as to whether the exercise of the veto (as applied to environmental information under the Environmental Information Regulations 2004) offends the relevant sections of the originating EC Directive and the Aarhus Convention (specifically, those that deal with the need to have a “review procedure”) could also be met by reference to the availability of judicial review (although one wonders, along with the Aarhus Convention Compliance Committee, whether judicial review meets the requirement to be not “prohibitively expensive”).

And ultimately, and  relatively straighforwardly, it fell to the court to

consider whether the Attorney General has shown in the present case reasonable grounds for certifying as he did…[and] the Statement of Reasons appended to the certificate, once carefully read and analysed, does indeed demonstrate such “reasonable grounds”. The views and reasons expressed as to where the balance of public interest lies are proper and rational. They make sense. In fact, I have no difficulty in holding them to be “cogent”. Indeed – especially given that the Attorney General’s reasons and conclusions are in many respects to the like effect as those previously provided by the Information Commissioner – it will be recalled that the Upper Tribunal had itself, in paragraph 4 of its decision, acknowledged that there are “cogent arguments for nondisclosure”

So, if you want to criticise the fact that the Attorney General was allowed to veto disclosure of Prince Charles’ correspondence with the government, don’t criticise the judges, don’t even criticise (too much, at least) the Attorney General himself – rather, criticise Parliament which passed the law.

UPDATE: 25 July 2013

The Guardian reports that permission has been granted to appeal to the Court of Appeal.

 

Leave a comment

Filed under Environmental Information Regulations, Europe, Freedom of Information, Information Commissioner, transparency, Uncategorized

CQC allegations and data protection

Data Protection laws have been said to be behind the decision not to name CQC officials alleged to have covered-up a damning internal report. Oh really? Well, yes, perhaps, I argue.

News bulletins today lead with the story that the Care Quality Commission apparently engaged in a cover-up of an internal review report critical of its oversight of University Hospitals Morecambe Bay in 2010, an NHS Trust now subject to investigations over the deaths of at least eight mothers and babies. The allegations of a cover-up were made by a whistleblower interviewed as part of an investigation by Grant Thornton, who were commissioned by CQC to look into its own activites. Potentially particularly damning are remarks at the time attributed to a senior manager at CQC regarding the alleged suppression on the original internal review report

Are you kidding me? This can never be in a public domain, nor subject to FOI

The Grant Thornton report, as published, has redacted the name of this senior manager and a colleague. And the Data Protection Act 1998 (DPA) is pleaded in defence of the redaction. As the Telegraph reports

The names of two individuals who ordered the destruction of evidence of the Care Quality Commission’s failure to investigate the University Hospitals of Morecambe Bay NHS Trust have been redacted from an official report…David Prior, the new chairman of the CQC, said that the names had been redacted because of “data protection concerns” and because the watchdog fears being sued…”to publish it with the names would breach the Data Protection Act.We would have been open to being sued on that basis”

As a number of people have pointed out, this is certainly questionable. Ben Bradshaw MP is reported by the Guardian as saying in Parliament that

the [Data Protection Act] allows exceptions in cases where protecting the public is an issue

and, in a thundering editorial, Health Policy Insight say the decision

is, quite simply, bullshit…Nor is it just a minor pellet of bullshit. This is epic, hog-whimpering and noxious bullshit…The Data Protection Act affords specific exemption at Section 55 2(d) “to a person who shows … that in the particular circumstances the obtaining, disclosing or procuring was justified as being in the public interest”…Moreover, the Information Commissioner’s Office, which enforces the Data Protection Act, is explicit in its advice on Principles One and Two (those dealing with an individual personal data) that fairness is crucial: “it depends on whether it would be fair to do so … personal data must not be processed for any purpose that is incompatible with the original purpose or purposes”

While I admire the level of polemic, HPI are rather mistaken in their analysis of the DPA. And I submit that it was not necessarily wrong for David Prior to be advised that disclosure of the name of the person might breach the DPA. I would stress that I am not suggesting that those responsible for failures at CQC should not be accountable for those failure, nor, if it is true that the original internal review report was suppressed, that those who did so should not also be accountable. What I do suggest is that, on the information currently available, there is perhaps a lack of hard evidence to establish to an appropriate level of certainty that the person or persons alleged to have suppressed the report did so, or did so in the way they are alleged to have done. For that reason, it could indeed be a breach of the DPA to disclose the names at this stage. I say this despite the parliamentary statement by the Secretary of State for Health, to the effect that he had not wanted the redactions, and that

There should be no anonymity, no hiding place, no opportunity to get off scot free for anyone at all who was responsible for this

(On this, we should perhaps remember the unlawful decision by Mr Bollocks [ed: Balls] peremptorily to require the dismissal of Sharon Shoesmith. Politicians are first and foremost politicians. They are not generally there to be lawyers or employers.)

The name of the person involved is clearly going to constitute “personal data” according the definition in section 1(1) of the DPA. And, for these purposes, the “data controller” (with whom lies the decision as to whether to disclose or redact, and to whom liability for a breach of DPA attracts) is CQC itself. HPI cite section 55(2)(d) of the DPA, which broadly provides that the offence of unlawfully obtaining personal data does not apply if it has been done in the public interest. This provision deals with a criminal offence of inter alia disclosing personal data without the consent of the data controller. This clearly does not apply here.

HPI are correct, however, in pointing to the first principle (as listed in Schedule One) of the DPA, and its reference to fairness (although they are talking nonsense when they refer to the first two principles being those “dealing with an individual personal data” [sic] – the whole of the DPA applies to an individual’s personal data). The first principle provides that the processing (and disclosure of a name will be “processing” under the DPA) of personal data must be fair and lawful.

When deciding whether names of public officials should be disclosed (albeit in response to a Freedom of Information request) the Information Commissioner (ICO) says

[the public authority] must decide whether disclosure would breach Principle 1 of the Data Protection Act (the DPA), ie whether it would be fair and lawful to disclose the information.

Whether the disclosure is fair will depend on a number of factors including:

the consequences of disclosure;

the reasonable expectations of the employees; and

the balance between any legitimate public interest in disclosure and the rights and freedoms of the employees concerned…

These are the factors CQC would need to take into account, and one can see that a balancing exercise would ensue. The consequences of disclosure – of what appear merely to be allegations – for the person or persons involved could be grave, and be an important factor in identifying what his or her rights and freedoms are. On the other side, there would be appear to be a clear public interest in disclosure, notwithstanding that, I repeat, these are mere allegations, on the basis that someone taking such a significant decision as to try (allegedy) to suppress publication of the adverse report should be accountable (as should the CQC as their employer) for such actions. The issue as to reasonable expectations is more difficult however. If the person or persons has been told in explicit terms that their name will not be disclosed, they may have very strong expectations that this will not happen. As to whether those expectations are reasonable, one would need to know the terms upon which any undertaking might have been given. Employment rights might well be engaged

Also to be considered is that the naming of the person or persons in circumstances in which it might subsequently transpire that the allegations were not true could give rise to a successful claim in defamation. Indeed, as Robin Hopkins has observed, DPA is increasingly used as a primary claim in actions involving defamatory publications.

I repeat, none of this is to defend the actions of CQC, nor, if the allegations are shown to be true, to defend the actions of anyone who suppressed the report. It is simply to say that the claim that the DPA might be engaged at this point, and potentially breached if disclosure of names happened. Disclosure, in a clearly fair and lawful way, might follow in due course.

I note that the Deputy Information Commissioner is reported tonight as saying

The Data Protection Act does not specifically prevent people being named publicly, but instead talks about using information fairly and considering what expectations of confidentiality people may have had when providing their personal information.

It is important the Data Protection Act is not used as a barrier to keep information out of the public domain where there is an overriding public interest in disclosure.

David Smith is a clever and astute man. He did not say the names should be revealed. That is revealing.

UPDATE 20.06.2013

My attention has been drawn to last night’s episode of BBC’s Newsnight on which David Smith’s boss, Information Commissioner Christopher Graham. As the BBC itself reports, he said

“This feels like a public authority hiding behind the Data Protection Act – it’s very common but you have to go by what the law says and the law is very clear.

“You have to process data fairly, you have to take into account people’s expectation of confidentiality.”

He said that was “obviously” the case with patient data in particular.

But when it came to officials, “there you have to apply a public interest test”, he added.

He said he was “not convinced” the CQC had been correctly advised.

He ended his short interview by saying “I think [the CQC] are going to have to look at this again”.

Fair enough. He’s right and I’m wrong then? Well, no – he still didn’t by any means say that disclosure now had to happen (and, in his role, he would have been be very ill-advised to have done so).

And, prompted by further coverage, and a comment below by Dr Chris Pounder, who probably knows more about Data Protection than the entire staff at the ICO (and that’s not intended as an insult to the latter), I now feel that two other factors might be at play. First, if the allegations quoted in the Grant Thornton report amount to allegations of possible criminal offences (e.g. misconduct in a public office) then there is an arguable need to avoid prejudice to any police investigation. Second, if the person or persons referred to in the report have already taken steps to challenge its veracity – either as a whole, or in respect of specific comments attributed to the whistleblower – then it would be prudent of CQC not to disclose until that challenge (whether it be made informally, or as part of or precursor to legal proceedings) has played out.

That said, when the combined forces of the government and the Information Commissioner are leaning on the CQC at least to review the decision not to disclose names, it would be a bold move to continue to resist. They will though, no doubt, be advised that there remain potential legal risks in doing so, unless they are completely satisfied about the veracity of allegations in the report.

UPDATE 2, 20.06.2013

The CQC has now published the names previously redacted. The letter to the Secretary of State makes clear that

We have reviewed the issues again with our legal advisers (and taken into account the comments of the Information Commissioner). In light of this further consideration, we have come to the view that the overriding public interest in transparency and accountability gives us sufficient grounds to disclose the names of the individuals who were anonymised in the report.

None of this changes my view that there was a clearly arguable legal basis for redaction. Data Protection is wrongly blamed for a lot of things but it was engaged in this instance.

This outcome also raises the rather interesting (if unlikely) possibility that the persons now named could complain to the ICO for a determination as to whether disclosure was in fact in breach of their rights under the DPA. Am I wrong to hope that happens?

14 Comments

Filed under Data Protection, Information Commissioner, Uncategorized

Information Rights and Wrongs Alternative Honours List

Martin Hoskins muses today on why – apart from those who’ve worked for the Information Commissioner’s Office – no data protection professionals have ever received royal honours. I can certainly think of a few information rights people whose selflessness and length of practice deserve recognition – Dr Chris Pounder, for instance, whose career in data protection spans five decades, or Maurice Frankel, without whom we might not even have an FOI Act. But, given that there’s little chance of this happening, I am today announcing an alternative

Information Rights and Wrongs Birthday Honours List

First up…

For services to the DfE, the Financial Times’ Chris Cook. Without Chris’s sterling efforts we would have little understanding of the devotion to the cause of ministers and SpAds at the Department for Education. Chris revealed that, such was this devotion, they spend much of their time and resources using their own home email accounts to do government work.

For services to public authorities in general, Alan M Dransfield, whose FOI campaigns mean there is now much greater clarity about how and when to treat FOI requests as vexatious.

For apparent defiance of in the face of the law, Jim Shannon MP, who – as well as holding the title of least sexy MP – does not appear to have been registered with the Information Commissioner for at least three years, despite the fact that processing personal data without a registration is a criminal offence (unless there is an exemption).

For donations to the legal profession Brighton and Sussex University Hospital Trust, who paid lawyers £178,000 in fees seeking to challenge an Information Commissioner monetary penalty, before withdrawing their appeal before it went to a hearing.

But there is one candidate which stands out above all others. A group honour, because no single individual could have (not) achieved all that they have (not) achieved. They are the inspiration behind a great new website, and they are the winner of the highest accolade, the Information Rights and Wrongs Arcana Imperii honour…

my_medal(1)

For sheer jaw-dropping contempt of the law, the Cabinet Office, who have decided to dispense with the need to observe the FOI Act. They are an inspiration for all of us and for as long as no effective enforcement is taken to ensure compliance, they will continue to be the shining beacon for all public authorities.

5 Comments

Filed under Uncategorized

Schools and Children’s Privacy

Parents, when confronted with the familiar complaint by a child that a parental decision “isn’t fair”, are entitled to say “I don’t care – what I say goes”.

Schools*, and their teachers, although acting in loco parentis, cannot necessarily do the same. Particularly in their role as public authorities they have obligations to act fairly and lawfully at common law, and under various statutes – not least the Human Rights Act 1998 (HRA). Article 8 of the European Convention on Human Rights, incorporated into domestic law by the HRA, famously provides everyone a qualified right

to respect for his private and family life, his home and his correspondence

Parents do not have to respect this in their dealings with their children: the latter cannot enforce the Article 8 right against a parent who demands access to their private correspondence, or who sends them to their bedroom for a spurious reason, or who uploads personal information to a dodgy cloud storage provider. Schools do have to respect the right – in loco parentis only goes so far.

I make this observation in light of research published by SafeGov.org and Ponemon Institute into the views of school staff on the use of cloud services in the education sector and the potential risks to student privacy. Among generally encouraging results (rejection of data-mining, seeing threats to student privacy as the top risk of cloud) was something less happy

Some schools admit to a conflict of interest regarding student privacy…47% say they might be tempted to trade student privacy for lower costs

If I were a child, or a parent, I would be tempted, in turn, to say “my (or my child’s) privacy is not yours to trade”. Rather, it is the school’s duty to protect that privacy, to the extent required by the law. Levels of privacy protection should not be related to cost (or only to the limited extent permitted by the second part of Article 8). Relatedly, the seventh principle of Schedule One of the Data Protection Act 1998 (DPA) requires a school, as data controller, to take

Appropriate technical and organisational measures…against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data

I would query whether a decision to adopt a software provider at lower cost, at the expense of student privacy, would be compliant with a school’s obligations under the DPA, or the HRA.

*I am talking about non-independent state schools

Leave a comment

Filed under Data Protection, human rights, Privacy, Uncategorized

NO THANK YOU I DON’T WANT TO REGISTER

The other day I was in town, and popped in to a shop to look at an interesting item. I was rather annoyed to be greeted by a shop assistant waving a large banner which obscured everything. He said he’d put the banner down if I handed over my contact details so he could send me marketing guff in the future. He only got out of the way when I kneed him in the Edwards.

Not strictly true of course. However – you wouldn’t run a physical shop this way, so why run web scripts that have the same effect?

bfp

I don’t want to register for your website – I just want to dip in for a quick look then leave (that still counts as a page view for you to quote to advertisers) and I’d suggest that’s pretty standard practice for the large majority of internet users.

I confidently state that no one, ever, in recorded history, has thought, when they got a pop-up inviting them to register their details, “Oo, how helpful that was. Thank you for obstructing my journey to what I really wanted”.

And I know I could probably configure a pop-up blocker to bypass them, but I don’t (often) walk around town accompanied by a bouncer. So just stop it, everyone who does this.

3 Comments

Filed under Uncategorized

A Howitzer of an FOI Exemption

A recent decision by the Information Commissioner shows that the House of Commons is able, under the FOI Act, to apply a blanket provision preventing disclosure of information of potential public interest, from which there is no appeal. If I were a cynical adviser to the House, I’d suggest using it more often.

The Freedom of Information Act 2000 (FOIA) contains a few howitzers with which a relevant public authority can obliterate an otherwise valid request for information. The most familiar of these is at section 53, whereby, in relation to a Information Commissioner (IC) decision notice served on a government department requiring them to disclose information, a Cabinet minister can issue a veto, from which there is no right of appeal.

Less well-known are the certificates which can be served under sections 23 and 24, by ministers, to be conclusive evidence that information requested was supplied by or relates to national security bodies, or is exempt from disclosure for reasons of national security. (These are appealable, either by the IC or by the applicant, under section 60 of FOIA).

Less well-known still is a section which allows the Speaker of the House of Commons (or the Clerk of the Parliaments) to issue a certificate which provides conclusive evidence that disclosure would or would be likely to cause prejudice to the effective conduct of public affairs. This is section 36(7) and, read with section 2(3)(e), it provides an absolute exemption to disclosure, which the IC is duty bound to accept. In effect, it is a means whereby the Houses of Parliament can prevent FOIA disclosure, with no right of appeal.

Thus, in a decision notice published this week about a request for information relating to the tax treatment of residential accommodation provided by the House of Commons, the IC says

Given the nature and provenance of the certificate, the Commissioner is obliged by section 36(7) FOIA to accept the certificate as “conclusive evidence” that the opinion is reasonable in both process and substance and that the alleged inhibition would be likely to occur; therefore, the Commissioner accepts that section 36(2) FOIA is engaged and that the withheld information is exempt

Any appeal of this decision would have the same outcome: if a properly-made certificate states that the exemption applies, then it does, and no regulator or court can say different. So, despite what appears to be a potentially high degree of public interest in the information requested, about, in the applicant’s words

issues of principle… the provision of residential accommodation is a substantial benefit, and its tax treatment is of legitimate interest to the public

we will not get to see it.

There could, I imagine, potentially be an application for judicial review of the decision to issue the certificate, in the same way that the ministerial veto at section 53 is potentially amenable to judicial review, but this would have to be on the classic public law grounds, and would be a very difficult challenge.

One rather wonders why this provision has not been used more often. It has been used in the past to prevent disclosure of information relating to names and salaries of MPs’ staff, and to prevent disclosure of information about the claiming of parliamentary privilege. But when requests were made for disclosure of MPs’ expenses information, the exemption claimed was the one relating to personal data. A section 36(7) certificate would, it seems to me, have rendered those requests dead in the water. Did the House of Commons miss a cynical trick?

Leave a comment

Filed under Freedom of Information, Information Commissioner, Uncategorized

ICO Bares Teeth at Nuisance Callers

I know a retired chap whose daily life is blighted by nuisance marketing phone calls. Some are from charities he donates to, and I’ve told him he’s entitled to donate and still opt out of receiving these. But others are entirely unsolicited, and despite the fact that about a year ago I got him to register with the Telephone Preference Service (TPS) the calls continue.

Now I remember when I signed up with the TPS a few years ago it was remarkably successful in stopping all nuisance calls, especially when, if one got through, I’d threaten to complain. However, my retired friend won’t complain because, he says, “it wouldn’t achieve anything”. Until recently, I’d have tended to agree with him, but it is good to see the Information Commissioner’s Office (ICO) showing that it does have teeth when it comes to enforcement of the Privacy and Electronic Communications Regulations 2003 (PECR). The ICO have today announced that a monetary penalty notice of £90,000 has been served on a Glasgow company for a breach of the PECR.

DM Design, based in Glasgow, has been the subject of nearly 2,000 complaints to the ICO and the Telephone Preference Service (TPS). The company consistently failed to check whether individuals had opted out of receiving marketing calls – in clear breach of the law – and responded to just a handful of the complaints received.

In one instance an employee refused to remove a complainant’s details from the company’s system and instead threatened to “continue to call at more inconvenient times like Sunday lunchtime”

And it is interesting to note that the ICO say they intend to issue similar “fines” against two other companies.

Of course, this kind of robust enforcement action can only really happen if people complain about this type of call, either to the ICO or to the TPS. I will be encouraging my retired friend to do so, in the knowledge that it might actually achieve something.

Leave a comment

Filed under Uncategorized

The Right to Unknown Information

It is important to note that there is no requirement in the FOIA that those intending to make requests for information have any prior knowledge of the information they are requesting.

These words of the Information Commissioner (IC) in, Decision Notice FS50465008, are an important statement about the role of the Freedom of Information Act 2000 (FOIA) in investigative journalism and activism. They establish that, at least in the IC’s view, FOIA requests may be made on a speculative basis, without a knowledge of the specific contents of documents.

To many users and practitioners they are probably also an obvious statement about the right to information conferred by FOIA. If someone is asking for information from a public authority, it is self-evident that, at least in the large majority of cases, they do not know what the information specifically consists of – otherwise, why request it? As the IC goes on to say

The idea of a requirement of prior knowledge that the relevant information exists is itself contrary to the very purpose of the legislation, let alone prior knowledge as to what it comprises

The request in question, made – as those who followed the “Govegateimbroglio might have guessed – by the impressively dogged journalist Christopher Cook (who has given me permission to identify him as the requester), was to the Cabinet Office for

the last email received by the [Prime Minister] personally on government business via a private non-GSI account. I also want the last government email sent by the PM via such an account

It was made in the context of suspicions that attempts might have been made to circumvent FOIA by conducting government business using private email accounts. For obvious reasons Chris was unlikely to be able to identify the specific type of information he sought, and the Cabinet Office knew this, telling the IC that

he has no idea of the nature of the information that may be contained in such emails, if indeed such emails even exist…For a request for a document to be valid, it needs to describe (if it would not otherwise be apparent) the nature of the information recorded in the document. The Cabinet Office does not accept that asking a public authority to undertake a search for emails without any subject matter, or reference to any topic or policy, sent using a particular type of account can satisfy the requirement on the application to ‘describe the information requested’

However, the IC rejected this, splendidly demolishing the Cabinet Office’s position with an argument by analogy

a request for the minutes of the last Cabinet meeting would clearly describe the information requested, even though it does not describe the content by reference to the matters discussed

I think this decision is particularly important because it accepts that, sometimes, a person contemplating requesting information from a public authority might not have a fully-formed view of what it is she wants, or expects to get. Authorities sometime baulk at requests which they see as “fishing expeditions”, but the practice of investigative journalism (in de Burgh‘s classic formulation “…to discover the truth and to identify lapses from it in whatever media may be available…”) will often involve precisely that, and the IC recognises this

Whilst public authorities might find such requests irritating, the FOIA does not legislate against so-called ‘fishing expeditions’

 The Cabinet Office must now treat Chris’s request as properly-made under FOIA. That does not mean that they will necessarily disclose emails from the PM’s private email account (in fact I’d be amazed if they did), but no one ever suggested the trade of investigative journalism was easy.

5 Comments

Filed under Cabinet Office, enforcement, Freedom of Information, Information Commissioner, transparency, Uncategorized

Human Rights and Wrongs

“The first major law to curtail the rights of Jewish German citizens was the “Law for the Restoration of the Professional Civil Service” of April 7, 1933, according to which Jewish and “politically unreliable” civil servants and employees were to be excluded from state service” (source: wikipedia)

I was talking to a friend with Jewish heritage yesterday who is researching his family history. His success at tracing his German and Polish ancestors using the superb JewishGen site was – as has happened to some many thousands of Jewish genealogists – desperately and sickeningly curtailed by the events of the 1930s and 1940s. People die, or disappear, and lineages that go back centuries are broken by something that happened within our fathers’ lifetimes.

“[in 1935 the] “Nuremberg Laws” excluded German Jews from Reich citizenship and prohibited them from marrying or having sexual relations with persons of “German or German-related blood.” Ancillary ordinances to these laws deprived them of most political rights. Jews were disenfranchised and could not hold public office” (source: wikipedia)

We speculated on how his family members in 1930s Berlin might have responded to the erosion of their rights during this period. Why didn’t they leave when they could? They were affluent and well-connected. They may even have had the opportunity to emigrate. Philip Roth’s novel The Plot Against America imagines an alternative American history under the leadership of the Fascist-sympathising Charles Lindbergh. It is chilling precisely because it shows how gradual the process of erosion might be, and how difficult it must have been for my friend’s ancestors to accept that their country, and their neighbours and friends, were capable of destroying them, and attempting to annihilate their racial and religious identity.

“Persecution of the Jews by the Nazi German occupation government, particularly in the urban areas, began immediately after the invasion. In the first year and a half, the Germans confined themselves to stripping the Jews of their valuables and property for profit, herding them into ghettoes and putting them into forced labor in war-related industries”(source: wikipedia)

We spoke of how two of his relatives appear to have died on successive days in 1939, and how this might have happened. Though this was after Kristallnacht history shows that that was but one spike in a relentless process of denial of freedom of thought, conscience, religion and expression, of inhuman and degrading treatment or punishment, of forced and compulsory labour in ghettoes, of forcing people to live in unbearably cramped and oppressive conditions, with no respect for family or privacy. Though some might have tried to resist, all rights to freedom of assembly would have gone. Others of his relatives simply disappear from the records, and we had little doubt this would have been after an arbitrary deprivation of liberty with no right to any court hearing.

“Extermination camps (or death camps) were camps built by Nazi Germany during World War II (1939–45) to systematically kill millions of people by gassing and extreme work under starvation conditions. While there were victims from many groups, Jews were the main targets” (source: wikipedia)

And my friend found a record indicating the death of one relative in 1942. The place of death was not known, but by that time the Nazi regime was pursuing a state program of genocide, of mass deprivation of life.

“The rights of every man are diminished when the rights of one man are threatened” (source: John F Kennedy)

The development of the European Convention of Human Rights, with its proclamation of the universality of the rights it described, was born out of an acknowledgment and experience that a state can change its own laws, and depart from acknowledging and protecting human rights. If governments can (and they can) derogate themselves from the obligations of their own laws, then a system of international jurisdiction over the protection of human rights was essential. David Maxwell-Fyfe, a future United Kingdom Attorney General and Home Secretary was a key figure in the drafting of the Convention.

“A country is considered the more civilised the more the wisdom and efficiency of its laws hinder a weak man from becoming too weak and a powerful one too powerful” (source: Primo Levi, If this is a Man)

This morning I read reports that the Home Secretary will announce that a majority Conservative government would withdraw from the European Convention.

1 Comment

Filed under human rights, Uncategorized

Smeaton v Equifax overturned

The Court of Appeal has overturned what had seemed an important, if controversial, judgment on the legal duties owed by Credit Reference Agencies to those about whom they hold records and issue reports.

I blogged in May last year  about a high court claim for damages under section 13 of the Data Protection Act 1998 (DPA). The claimant, Mr Smeaton, successfully argued that, as a result of processing inaccurate data about his credit history, the Credit Reference Agency (CRA) Equifax was in breach of the fourth data protection principle, and that Equifax’s obligations under the DPA as a data controller meant that it owed a duty of care to Smeaton in tort. Accordingly, damages were owed (to be assessed at a later date).

The case has now been comprehensively overturned in the Court of Appeal. Primarily, the appeal succeeded because the judge’s findings on causation (i.e. had the inaccuracy in Mr Smeaton’s credit record led to the detriment pleaded?) were not sustainable. Lord Justice Tomlinson, giving the lead judgment, was highly critical of the judge’s approach

the judge’s conclusion that the breaches of duty which he identified caused Mr Smeaton loss in that they prevented Ability Records from obtaining a loan in and after mid-2006 is in my view not just surprising but seriously aberrant. It is without any reliable foundation and completely unsupported, indeed contradicted, by the only evidence on which the judge could properly rely (¶11)

That effectively dispensed with the claim for damages, but Equifax, clearly concerned about the implications of the original findings regarding a breach of the DPA and consequent breach of a duty of care, asked the Appeal Court to consider these points as well.

Was there a DPA breach?

Tomlinson LJ held that the procedures which obtained at the time of the alleged DPA breach, regarding the annulment (and communication thereof) of bankruptcy orders, had never been the subject of the expression of any concern by either the Information Commissioner or the Insolvency Service. In the first instance the judge had observed that inaccurate personal data could be “particularly damaging”. Tomlinson LJ did not demur, but said that

it is necessary to put this important principle into context and to maintain a sense of proportion. In the context of lending, arrangements have been put in place to ensure that an applicant for credit should not suffer permanent damage as a result of inaccurate information appearing on his file (¶59)

Those arrangements are described in guidance both published by or approved by the Information Commissioner, and include the fact that, in the event of a failed credit application

[the] lender must tell a failed applicant by reference to the data of which CRA an application was declined, if it was, and the failed applicant, like any consumer, has the right to obtain a copy of his file from a CRA on payment of £2.00

and mistakes can thus be corrected.

Moreover, CRAs must, by reference to the Guide to Credit Scoring 2000, not decline a repeat application “solely on the grounds of having made a previously declined or accepted application to that credit grantor”. This, and other guidance, were inbuilt safeguards against the kind of detriment Mr Smeaton claimed to have suffered. Ultimately

Equifax did take steps to ensure that its bankruptcy data was accurate. It obtained the data from a reliable and authoritative source in the form of the [London] Gazette, it transferred the data accurately onto its data bases from that source and it amended its data immediately upon being made aware that it was inaccurate…the judge was wrong to conclude that Equifax had failed to take reasonable steps to ensure the accuracy of its data (¶81)

Was there a co-extensive duty of care in tort?

Here Tomlinson LJ considered the “traditional three-fold test of foreseeability, proximity and whether it is fair, just and reasonable to impose a duty” and held comprehensively that there was not. He agreed with counsel for Equifax’s argument that

(1)It is doubtful whether it was reasonably foreseeable that the recording of incorrect data on Mr Smeaton’s credit reference would cause him any loss…
(2)It would also not be fair, just or reasonable to impose a duty. In particular, imposing a duty owed to members of the public generally would potentially give rise to an indeterminate liability to an indeterminate class…
(3)It would also be otiose given that the DPA provides a detailed code for determining the civil liability of CRAs and other data controllers arising out of the improper processing of data
(4)Parliament has also enacted detailed legislation governing the licensing and operation of CRAs and the correction of inaccurate information contained in a credit file in the CCA 1974. This provides for the possibility of criminal sanctions, but does not create any right to civil damages. In such circumstances it would not be appropriate to extend the law of negligence to cover this territory (¶75)

The third of these seems to make it clear that the courts will be reluctant to allow for a notion of an actionable duty of care on data controller to process personal data fairly and lawfully. (This is in contrast, interestingly, with the situation in Ireland, whereby a statutory provision (section 7 of the Data Protection Act 1988) states that such a duty of care is owed (at least to the extent that “the law does not so provide”)).

My post on the first instance case has been one of the most-read (it’s all relative, of course – there haven’t been that many readers) so I think it only correct to post this update following the Court of Appeal judgment.

2 Comments

Filed under Data Protection, Information Commissioner, Uncategorized