Prince of Wales Correspondence Vetoed

In his post of 19 September 2012, Robin Hopkins commented on the decision of the Administrative Appeals Chamber of the Upper Tribunal in Evans v IC & Seven Government Departments [2012] UKUT 313 (AAC), in which Walker J held that it was in the public interest that the majority of the correspondence from The Prince of Wales to those Government departments to be disclosed.

Instead of bringing an appeal, the Attorney-General today announced that he was vetoing disclosure under s.53 FOIA. In a ten page Statement of Reasons the AG stated that he had taken account of the views of the Cabinet, former Ministers and the Information Commissioner (who had not supported disclosure). Of particular note is the reason given by the AG that “it is of very considerable practical benefit to The Prince of Wales’ preparation for kingship that he should engage in correspondence and engage in dialogue with Ministers“. Urging views upon Ministers comes, in the view of the AG, within the ambit of advising or warning the Government under the tripartite convention. The AG adds that the contents are very frank and concern The Prince’s deeply held personal beliefs, but contain nothing improper.

The veto is concerned only with the correspondence of The Prince of Wales at issue in the Evans case. It remains to be seen whether the ongoing FOIA litigation concerning access to the Duchy of Cornwall’s information will result in a similar response.

Update: Following the announcement of the Attorney-General’s veto, the Guardian (for which Mr Evans writes) has announced that it intends to seek judicial review of the decision under s.53. As far as I am aware, the small number of vetoes previously issued have not been challenged by way of judicial review (see Lamb v IC (EA/2009/0108) at [5]).

Christopher Knight

Board minutes of a public/private joint venture confidential and commercially sensitive

Joint ventures between the public and private sectors are increasingly common. They are often a focus for vigorous political debate over issues such as the costs involved, the savings to the public purse, the profit to the private sector partner, and allegations of conflicts of interest. While those are political arguments on which Tribunals take no view, they do point to the significant public interests that are engaged when considering access to information. So said the Tribunal in David Orr v IC and Avon and Somerset Police Authority (EA/2012/0077), a recent decision notable for grappling with access to information about such a public/private joint venture.

South West One Limited (“SW1”) is a company formed in 2007 as a joint venture by three West country public authorities (together owning 25% of the company) and IBM (75%) to create for their own use and promote and sell to other authorities IT support systems of various kinds. Given its membership of the board of SW1, the second respondent police authority held minutes of its board meetings. The requester asked for that information. The police authority refused, relying on ss. 41 (actionable breach of confidence) and 43(2) (prejudice to commercial interests) of FOIA. An important feature here was that the joint venture agreement contained confidentiality clauses, including one providing that “each of the parties… shall hold in confidence… any financial or other information in respect of the company or the business”. The Commissioner upheld the refusal, finding no evidence that the agreements were being used to circumvent FOIA improperly.

The Tribunal agreed. It rejected the requester’s argument that SW1 should be treated as a public authority for FOIA and EIR purposes. It also upheld reliance on s. 41. It found that redactions would not suffice to remove confidentiality:

“… removal of the name of the targeted purchaser might not conceal its identity from well – informed readers. More fundamentally, board minutes are, by their nature, confidential information. They record disagreements and minority opinions. They should frankly describe the inner workings of the company, whenever significant issues are discussed. It is important in the shareholders` interests, that board minutes fully reflect what has been transacted.”

As to the prospects of success for a public interest defence to an action for breach of confidence, the Tribunal noted the police authority’s sympathy with the requester’s position: “any loss of transparency or “democratic deficit” arising from the creation of SW1 was an inevitable consequence of joint ventures involving public and private sector entities working together through a limited company.”

The Tribunal approached the public interest defence as follows (paragraph 32):

“We have regard, on the one hand, to what is already in the public domain and, on the other, to the undoubted importance of transparency in the operation of joint ventures, in so far as that is consistent with the proper commercial interests of the company thereby created, here SW1. If a joint venture company has been formed for the specific purpose of frustrating the duties of disclosure enacted in FOIA; if public funds are being needlessly squandered in a badly – managed business; if serious conflicts of interest are or may be distorting the company`s operations, then there may be a strong case for disclosing information which reveals such facts.”

None of those concerns arose here, and an action for breach of confidence would not be defeated.

Similar considerations meant that reliance on s. 43(2) would also succeed here. On this issue, the Tribunal observed (paragraph 37) that even where a joint ventures is between public authorities alone (i.e. without the involvement of a private sector partner), the case for reliance on s. 43(2) may be equally strong.

For further analysis of this case, see the Local Government Lawyer.

Anya Proops represented the police authority.

Robin Hopkins

Charity served with monetary penalty notice

Today, the Commissioner served – for the first time – a monetary penalty notice on a charity. The charity in question, Norwood Ravenswood Ltd, is a social care charity. One of its social workers had attempted to deliver to the home of prospective adopters certain background reports containing highly confidential sensitive personal data on four young children. Finding the couple out, and unable to fit the package through the letterbox, the social worker left the package in a concealed area at the side of the house. When the prospective adopters returned home, the package had disappeared. It was never recovered.

At the time of the incident, the charity had no specific guidance on sending personal data to prospective adopters. Further, and in breach of the charity’s data protection policy, the social worker in question had not received any data protection training.

The Commissioner found that there had been a “serious contravention” of the seventh data protection principle (i.e. that appropriate technical and organisational measures shall be taken … against accidental loss … of … personal data). Perhaps unsurprisingly, the contravention was also found to be “of a kind likely to cause … substantial distress” (for the purposes of the second limb of the test, in s. 55A(1)(b) of the DPA). In addition, the Commissioner concluded that the charity knew or ought to have known that there was a risk that the contravention would occur, and that such a contravention would be of a kind likely to cause substantial distress, but failed to take reasonable steps to prevent the contravention within the meaning of s. 55A(3) of the DPA.

Although the Commissioner was not aware of any previous similar security breach, and the charity had voluntarily reported the incident to the Commissioner and had fully cooperated thereafter, the Commissioner nevertheless set the penalty at £70,000. Interestingly, the Commissioner does not appear to have taken the data controller’s charitable status to be a factor of any significance in this regard, on the basis that it had “substantial reserves”. Although the penalty is at the lower end of the spectrum of penalties awarded to date this year, it remains a substantial sum.

Overall, today’s decision serves as a useful reminder both of the potential consequences of inadequate data protection procedures and of the fact that even charitable bodies may face heavy penalties if serious contraventions occur.

There is still no monetary penalty case law to offer guidance. But, as regular readers of this blog may recall, the first appeal against a monetary penalty notice (brought by London Community Healthcare NHS Trust) is in the pipeline. It will be heard in December this year (with Tim Pitt-Payne QC and Anya Proops of 11KBW acting for the opposing parties).

One final thought, or, rather, question. The vast majority of the monetary penalty notices concern public authorities. Are public authorities really committing many more “serious contraventions” than private persons, or are they simply more likely to be reporting such contraventions to the Commissioner?

Ben Hooper

Cloud computing – new ICO guidance

Cloud computing is becoming an ever more pervasive feature of the technological world. Whether one is dabbling in social networking or purchasing goods online, the truth is that we all, to a greater or lesser extent, now have our heads in the virtual clouds. However, the use of cloud computing inevitably raises important information law issues, particularly in terms of the impact on privacy rights and also under the Data Protection Act 1998. So far as the DPA is concerned, issues which fall to be considered include:

  • who actually controls the data which is being processed via the cloud (i.e. who is liable under the DPA if things go wrong in data protection terms)

 

  • what steps a data controller may be required to take to safeguard against misuses of personal data within the cloud

 

  • the security implications of processing personal data through cloud computing and, in particular, whether the processing of data via the cloud is compliant with the seventh data protection principle

 

  • the legality of using clouds which operate transnationally and, hence, which may bring into play the application of the eighth data protection principle on cross-border data transfers

Importantly, the Information Commissioner has today issued guidance which is designed to help organisations navigate their way through the potentially complex DPA issues which may arise in the context of cloud computing. You can find the guidance here.

Particular points to note about the guidance include the following:

  • the Commissioner has (unsurprisingly) confirmed that the DPA applies to any processing of personal data which takes place in the cloud

 

  • the guidance suggests that, when it comes to determining who is the ‘data controller’ in respect of data which is processed via the cloud, one should generally look to the purchaser of the particular cloud services (i.e. the cloud service customer). This is because it is typically the cloud customer who will determine the purposes for which and the manner in which the data is being processed (see further the definition of ‘data controller’ in s. 1(1) DPA). However, that is not to say that there will not be cases where the cloud provider itself has sufficient control over the data such that it can properly be designated as a ‘data controller’ under the Act

 

  • if two or more data controllers within a ‘community cloud’ intend to share data they should take time to clarify their roles and decide who is the controller in respect of which data

 

  • a data controller cannot simply assume that, because a cloud provider has a set of standard terms and conditions, those terms and conditions afford sufficient safeguards to guarantee compliance with the DPA. The data controller must itself take steps to ensure that the safeguards deployed by the particular cloud provider are fit for purpose, having regard not least to the sort of data in issue and how it is to be processed. This may well entail the data controller looking for cloud providers which can tailor their services to accommodate the data controller’s specific requirements

 

  • data controllers should ensure that they are only putting data into the cloud which actually needs to be there. Thus, data controllers should effectively ensure that they are sieving their data before putting it on the cloud and should create clear records of the sort of data they intend to move to the cloud

 

  • insofar as the particular cloud service results in the collection of meta-data about the data subject (e.g. information revealing transaction histories), data controllers should be aware that this may also constitute personal data to which the data protection principles apply

 

  • cloud customers should adopt strategies to limit the chances that the use of cloud computing will breach the data protection principles, such strategies should include:

 

  • conducting risk assessments

 

  • ensuring that appropriate written contracts are in place with the cloud provider

 

  • reviewing the quality and depth of the security arrangements offered by the cloud provider

 

  • ensuring that adequate security measures are applied to the data (e.g. via encryption, use of password access etc)

 

  • ensuring that the cloud provider has in place a suitable retention and deletion policy and querying what happens to any data on the cloud in the event that the cloud customer withdraws from the cloud

 

  • ensuring that the cloud provider’s own access to the data is suitably controlled and limited

 

  • taking measures to ensure that the cloud provider is not itself in a position to start adapting the purposes for which the data is being processed without the cloud customer’s authorisation

 

  • exploring with the cloud provider the extent to which the data may be transferred abroad (e.g. because the cloud straddles a variety of different jurisdictions) and, further, the quality of any data protection regime applicable in any foreign jurisdiction to which the data may be transferred

 

  • having policies in place which ensure that data subjects are properly informed about how their data is being processed

 

  •  monitoring data compliance once the cloud services have been obtained

All organisations which use or provide cloud services should, as a matter of urgency, familiarise themselves with this policy or else risk developing a stormy relationship with the Commissioner in future.

Anya Proops

Legal advice on Scottish independence: date set for appeal

In a decision notice of 6 July 2012, the Scottish Information Commissioner, Rosemary Agnew, ordered the Scottish Ministers to confirm or deny whether they had taken legal advice on the status of Scotland within the European Union should Scotland choose to break away from the UK. In essence, the underlying issue is whether or not an independent Scotland would retain EU membership or whether it would need to apply afresh. The Scottish Ministers have appealed against that decision, arguing that they were entitled under the Freedom of Information (Scotland) Act 2002 to refuse to confirm or deny whether they had taken such advice. The appeal is being fast-tracked, and has been listed for 18-19 December. In the meantime, here is Panopticon’s synopsis of the issues in the decision notice.

First, it is important to note how the ‘neither confirm nor deny’ (NCND) provision under s. 18 of FOISA works. Public authorities are entitled to issue a NCND response if the underlying informationm if held, would be exempt from disclosure (due to the balance of interest in maintaining a qualified exemption) and if the public interest in neither confirming or denying whether such information is held outweighs that in confirmation or denial.

The Scottish IC agreed with the Scottish Ministers on the first limb – but not the second.

The first qualified exemption relied on was s. 29(1)(a) FOISA (formulation or development of government policy. The Commissioner took the view “that “formulation” of government policy suggests the early stages of the policy process where options are identified and considered, risks are identified, consultation takes place and recommendations and submissions are presented to the Ministers. “Development” suggests the processes involved in reviewing, improving upon or amending existing policy; it can involve piloting, monitoring, analysing, reviewing or recording the effects of existing policy” (paragraph 15). The Commissioner accepted that this exemption was engaged would be engaged with respect to the underlying legal advice (if any were held). She rejected the requester’s argument that policy (here: achieving independence for Scotland) is one thing, but advice on the legal effects of that policy (here: EU membership) was a different and separate matter.

The second qualified exemption relied on was s. 30(c), which applies “would otherwise prejudice substantially, or be likely to prejudice substantially, the effective conduct of public affairs”. The Commissioner said (paragraph 22): “This is a broad exemption and the Commissioner expects any public authority citing it to show what specific harm would be caused to the conduct of public affairs by release of the information, and how that harm would be expected to follow from release.”

Again, she was satisfied that the exemption would be engaged. See paragraph 26: “The Commissioner accepts the Ministers’ arguments that disclosure of any such advice at this stage could be obstructive to future dialogue and negotiations with other parties and stakeholders concerning a matter of sensitivity, importance and significance.”

The requester argued that, if such legal advice was held, one could scarcely think of information in which there was a stronger public interest in disclosure. In contrast, the Ministers advanced arguments based on the need for a safe space, the risk of a chilling effect on communications, and the risk that disclosure of such information at the time of the request would create substantially misleading impressions. The Commissioner agreed that these factors were significant and that, if such information were held, the public interest would favour the maintenance of the exemptions. She added that “… in September 2011, the independence referendum was still some years away. In her view, the urgency of the need to understand the consequences of any legal advice obtained by the Ministers would be considerably less at that time (or even now) than it would be as the referendum approached” (paragraph 44).

That, however, only got the Ministers part of the way to an NCND position. The Commissioner found that the public interest favoured confirming or denying whether the Ministers had taken legal advice on this issue. At paragraph 52, she concluded that:

“In the Commissioner’s view, the role of FOISA is important not only in enabling transparency in information held by public authorities, but also in enabling transparency in information about process. In this case, whilst the Commissioner has concluded that, if the advice existed and was held by the Ministers, they would have been entitled to issue a refusal notice under section 16(1), the Commissioner considers that it is in the public interest to know the type of information that the Ministers were taking into account in developing policy in relation to such a significant issue as independence.  While it is a matter for Ministers to take the approach they consider appropriate, this would enable interested parties to form their own opinions on the way in which Ministers develop policy and take decisions.”

The appeal will be extremely interesting both for its importance and for its analysis of the mercurial concept of the public interest which lies at the heart of information rights legislation.

Robin Hopkins

Chagos Refugees Group in the First-Tier Tribunal: some key points

The Chagos Archipelago forms part of the British Indian Ocean Territory (“BIOT”). In the late 1960s and early 1970s, the inhabitants of the Chagos Islands were required to leave those islands. At or around that time, a US military base was established on Diego Garcia, the largest of the Chagos Islands. The removal of the “Chagossians” has been a matter of considerable political and media debate, as well as complex legal proceedings. Two legal challenges are ongoing: Chagos Islanders v UK before the European Court of Human Rights, and Bancoult (No 3) before the domestic courts.

In 1999, the then Foreign Secretary commissioned a feasibility study concerning the possible resettlement of some of the islands. A preliminary study was conducted, followed a “phase 2B” study conducted by external consultants. The final report of the phase 2B study was made public. There was some ministerial correspondence about the studies.

In April 2010, representatives of the Chagossians sought information from the Foreign & Commonwealth Office about these studies. In particular, they asked for any draft versions of the phase 2B study (and any accompanying reports), as well as related ministerial correspondence.

The FCO disclosed some information, but withheld one note to a minister (Baroness Amos). As regards the draft reports, it claimed that – if these existed at the time of the request – they were held by the external consultants who authored them. The FCO maintained that the consultants did not hold that information “on behalf of” the FCO for the purposes of the Environmental Information Regulations 2004. The Commissioner upheld the FCO’s position.

The Tribunal (chaired by Andrew Bartlett QC) upheld the Chagossians’ appeal in part. A disclaimer to the following analysis: I appeared for the Information Commissioner. The post below is not a commentary on the case, but (with my Panopticon hat on) I highlight some of the points of general interest to FOIA and EIR practitioners. For a broader commentary on the case, see the excellent post from David Hart QC on One Crown Office Row’s UK Human Rights Blog.

The Tribunal in Chagos Refugees Group in Mauritius and Chagos Social Committee (Seychelles) v IC and FCO (EA/2011/0300) agreed with the FCO that information held by the consultants was not, at the date of the request, held “on behalf of the FCO” for EIR purposes. The Tribunal applied the guidance on the approach to “held” from University of Newcastle v IC and BUAV [2011] UKUT 185 (AAC), [2011] 2 Info LR 54 (see paragraphs 59-67). Generally, whether information is “held” will be a question of fact, but the Tribunal added that “we would also wish to qualify the proposition in McBride v IC and Ministry of Justice (EA/2007/0105) that whether information is held on behalf of a public authority is “simply a question of fact”. In some cases it will be important to determine the exact nature of the legal relationship between a person holding information and the public authority, or to determine the legal structure pursuant to which information was created and held” (paragraph 61).

The Tribunal analysed both the factual and legal relationship between the FCO and the consultants in reaching its conclusion. Its decision should be given careful attention when considering whether information is “held on behalf of” a public authority.

On the adequacy of the FCO’s own searches, the Tribunal said this at paragraph 70:

“… we consider it is relevant to draw attention also to the Tribunal’s remarks in the context of a FOIA request in Muttitt v IC (EA/2011/0036) (31 January 2012) at [68], to the effect that a search should be conducted intelligently and reasonably, and that this does not mean it should be an exhaustive search conducted in unlikely places: those who request information under FOIA will prefer a good search, delivering most relevant information, to a hypothetical exhaustive search delivering none, because of  the cost limit.”

As to the Baroness Amos note, the Chagossians were largely successful in their appeal: disclosure was ordered, bar a few redactions. In its analysis, the Tribunal considered the time at which the public interest was to be assessed. It has become almost trite in FOIA and EIR cases that the answer to this question is “at the time of the request or, at the latest, the date at which the public authority ought to have responded”. This question is, however, not altogether settled. In this case, the Tribunal was content to assess matters up to the date of the conclusion of the FCO’s internal review (see paragraphs 22-29). On a similar point, the UpperTribunal in Evans (see my earlier post on this) by no means considered it beyond doubt that matters should only be assessed at or shortly after the date of the request.

The Tribunal considered that weighty public interests would be served by disclosure of the contents of the Baroness Amos note, despite that being only a small amount of information. At paragraph 112 it said this:

“The amount of information in a potentially disclosable document is without doubt a material matter to take into account. At the same time, it is important not to discount unduly the significance, in the public interest, of the disclosure of small amounts of information. Publicly useful freedom of information requests are generally limited in scope. If too broad, they face the obstacle under FOIA of the costs limit, and under the EIR of the proportionality requirement. If the Tribunal were to take an unduly minimalist view of the value of the publication of relatively small amounts of information on matters of considerable legitimate public interest, this would materially reduce the effectiveness of the legislation. We would regard this as tending to conflict with the general purpose of  the legislation, as seen in the authoritative remarks in Sugar v BBC [2012] UKSC 4 at [76]-[77], which in our view apply with equal force to the EIR, particularly in view of the presumption in favour of disclosure found in EIR regulation 12(2).”

This outweighed the public interest in maintaining the exception for internal communications. Timing was key to the ‘safe space’ argument advanced by the FCO and the Commissioner. The Tribunal endorsed the approach taken in the Department of Health (NHS risk registers) case, whereby policy formulation can “dip in and out” of the need for a safe space. The Tribunal in this case concluded that (paragraph 123):

“We acknowledge the prospect that at some future date – perhaps in 2013, perhaps later – after the final conclusion of the two pending pieces of litigation, the resettlement policy is likely to be the subject of reconsideration. In our view that was at all material times, and remains today, a very weak reason for maintaining the confidentiality of a document written in entirely different circumstances in 2002.”

Robin Hopkins