Implementing the GDPR in the UK: lessons from Germany?

As we all know, the GDPR is all about the harmonisation of data protection across Europe – hence its form as a regulation (directly effective) rather than a directive (domestic implementing legislation needed). Yes, but: the GDPR leaves an awful lot to member states to implement. For example: exemptions to data subjects’ rights, mechanisms for reconciling data protection and freedom of expression, and the machinery of enforcement by supervisory authorities. Until we have domestic implementing legislation, we can’t fully understand how data protection will work after 25 May 2018. Continue reading

103-year old files correctly withheld under FOIA

Is it plausible that information over a century old could be withheld under FOIA on the grounds of national security and/or endangerment of health and safety? The answer is evidently ‘yes’. That was the outcome of a request for information on informants in the Jack the Ripper investigations (see Marriott v IC EA/2010/0183). A request for information on police informants involved in Irish secret societies over the period 1890-1910 has met the same outcome. Continue reading