The Government wants to get your PECR up

You – yes, you! – are entitled to FREE compensation! Our records – what records? Magic records! – show that you were missold PPI and can now claim thousands of pounds!

If you haven’t ever had a text message or a phone call along these lines, then you are either managing to live as a hermit or you are extraordinarily lucky. Most of us face spam texts and nuisance cold-calls as a daily fact of life. They are a regular source of irritation and annoyance. They are also blatantly illegal, particularly if you have signed up to the Telephone Preference Service. See: regs 22-23 of the Privacy and Electronic Communications Regulations 2003 (SI 2003/2426) (“PECR”), implemented under EU Directive 2002/21/EC.

Unfortunately, the nature of such communications means that it will not be very often that they are a source of “substantial damage or substantial distress”. Yet, that is the test which must be met in order for the Information Commisisoner to impose a monetary penalty notice (“MPN”): section 55A(1) of the Data Protection Act 1998 (implemented as the enforcement regime for PECR as well in a fit of slightly lazy ‘joined-up’ thinking).

As readers of this blog will know, the Upper Tribunal’s interpretation of the MPN regime as applied to PECR in Information Commissioner v Niebel [2014] UKUT 255 (AAC) has had the effect that it will be almost impossible for the ICO to establish substantial damage or distress in spam text message cases (see Anya Proops’ detailed comment here). It is certainly the case that the door remains more ajar in relation to nuisance calls – which by their nature are much more likely to cause genuine distress to some individuals – and the ICO is dealing with a couple of MPN appeals to establish how ajar, but Niebel casts a baleful shadow.

But, to the east, a new dawn may be rising. If the ICO’s war against the orc-like forces of spam is reminscient of the Battle of Helms Deep (and I think we can all agree that it is), then the Secretary of State for Culture, Media and Sport, Sajid Javid, is Gandalf, appearing with the remains of the Rohirrim on the morning of fifth day to turn the tide. For the DCMS has just launched a consultation exercise on amending PECR with a view to altering the test from “substantial damage or distress” to causing “annoyance, inconvenience or anxiety”. On its face, that change will be much more easily met and give PECR some teeth, as well as better implementing the Directive, which did not require anything so high as the section 55A test. The consultation paper can be found here, and the period for responding closes on December 7th. So once you have had fun allocating characters to the players in this area (Is Ed Vaizey Peregrine Took? Is Christopher Graham, the ICO, Aragorn? Is our own Robin Hopkins, counsel for Mr ‘Spamalot’ Niebel, Grima Wormtongue?), do respond to the consultation.

Update

Few areas of the law have such informed and coherent bloggers as information and data protection law, and not surprisingly, the PECR consultation has been grist to the commentariat mill. But at least one leading blogger, Jon Baines, has made the point that the Government’s (and the ICO’s) preferred option from the consultation is actually to remove the threshold entirely. He is right (and however formidable I may be – thanks Jon – I should have made that point). That is what the consultation paper says under option 3 (removing any harm threshold at all). Although it is also fair to say that it is slightly surprising that that is the preferred option, as the rest of the consultation paper appears to be drafted around the utility of adopting the “annoyance, inconvenience or anxiety” threshold. Not only is that what the Government says on the consultation page of its website, but paragraphs 16-20 of the paper (under the heading ‘The Proposal’) talk expressing in terms of the ‘annoyance’ threshold (and cross-refer to that being the test used by Ofcom). At paragraphs 44-45 of the paper the ICO appears to have provided evidence on the different actions it could have taken under an ‘annoyance’ test. Nowhere until the options are presented is it suggested that the talk of “lowering the threshold” might mean removing the threshold altogether. Which might just be an oversight. Or it might indicate that consulting on a preferred no harm option is one of those kite-flying efforts Sir Stephen Sedley warned of in the LRB. Either way, the reader is left less than clear as to what DCMS or the ICO really want.

(Apologies for the lack of LOTR references in this update. To make up for it, do enjoy this video of Ian McKellen explaining to schoolkids why they should revise for their exams. You’re welcome.)

Christopher Knight

Unforgettable that’s what you are – Google Spain revisited

The debates over whether the CJEU’s judgment in Google Spain represents an unjustified attack on free speech rights have raged for months now. Interestingly, it seems that some judges at the local level at least are proving somewhat resistant to this highly privacy-centred judgment. Thus, according to online reports, in recent weeks a Dutch preliminary court has apparently held that a man convicted of a serious offence dating back over some years could not rely on Google Spain to have the links to websites referring to the offence excised. According to reports about the judgment (which seems only to be available in Dutch), the court held that information revealing that someone has committed an offence has relevance notwithstanding its vintage and, as such, should not be de-indexed by Google (see here). Outside of Europe, a judge sitting in the Israeli magistrate’s court has apparently refused to countenance a claim against Google based on the so-called right to be forgotten. According to a report in the Israel Hayom online newspaper, the judge held that imposing an obligation on Google to de-index results, even if they were defamatory, would entail converting Google unjustifiably into a ‘super-censor’ (see the report here). It will be interesting to see how the English courts, with their strong tradition of upholding free speech rights, will in due course seek to navigate their way through the challenging jurisprudential landscape set by the CJEU in Google Spain.

Anya Proops

Local Government Transparency Code – Updated

Back in May 2014 the Secretary of State for Communities and Local Government issued the Local Government Transparency Code, and I briefly blogged about that here.

Now, an updated version of the Code dated October 2014 has been issued. Unaccountably, its publication appears to have been overshadowed by Kevin Pietersen’s autobiography, but it might perhaps be unfair to engage in a game of parallels, identifying for example who the “Big Cheese” would be at DCLG. The October 2014 Code is materially the same as its May predecessor (but fully replaces it) and it may assist if my earlier comments are set out again here (with amendments and updated cross-references).

The Code is issued in exercise of the Secretary of State’s powers under section 2 of the Local Government, Planning and Land Act 1980 to issue a Code of Recommended Practice as to the publication of information by local authorities about the discharge of their functions and other matters which he considers to be related.

The Code sets out in some detail in Part 2 the type of information held by local authorities which must be published (some of it annually). This is designed to replicate the requirements prescribed in the Local Government (Transparency) (Descriptions of Information) (England) Order 2014. Part 3 sets out the information which, in the view of the Secretary of State, ought to be published. A helpful Annex A provides the details in tabular form.

Paragraph 17 of the Code provides that: “Where information would otherwise fall within one of the exemptions from disclosure under the Freedom of Information Act 2000, the Environmental Information Regulations 2004, the Infrastructure for Spatial Information in the European Community Regulations 2009 or falls within Schedule 12A to the Local Government Act 1972 then it is in the discretion of the local authority whether or not to rely on that exemption or publish the data.” There is therefore no attempt to override the FOIA exemptions. But where a qualified exemption applies, the appearance of the requested information in one of the categories set out in the Code will have a role (possibly a significant role) in establishing the public interest in support of disclosure. Of course, where the Secretary of State as required – in Part 2 – information to be published, it should be published by the local authority. Any reliance on a qualified exemption will be doomed to fail. Information falling within the scope of Part 3 is also likely to face an uphill struggle to be withheld under FOIA/EIR, but it will be context dependent.

The main substantive difference between the May and October Codes is that the new one has added three datasets to the list of information which must be published: namely information about how the authority delivers waste services, use the parking revenue it collects and tackles fraud.

 

One development between May and October is that the DCLG have obviously been faced with a barrage of questions from concerned Councils. In an attempt to assist, DCLG has also published an accompanying FAQ Guide to the Code, which may help those attempting to practically apply the new Code with what the DCLG was trying to do in particular circumstances.

Christopher Knight

Assessing the FOIA veto power

For those of you still following the Prince of Wales correspondence veto saga, and who have access to law journals in print or online, you may be interested to read the casenote published in the latest issue of the Law Quarterly Review discussing the Court of Appeal judgment. The casenote is by 11KBW and Panopticon stalwart Chris Knight. The full reference is CJS Knight, ‘The Veto in the Court of Appeal’ (2014) 130 LQR 552.

Loss of personal data: £20k award upheld on appeal

If you breach your legal duties as regards personal data in your control, what might you expect to pay by way of compensation to the affected individual? The received wisdom has tended to be something along these lines. First, has the individual suffered any financial loss? If not, they are not entitled to a penny under s. 13 DPA. Second, even if they get across that hurdle, how much should they get for distress? Generally, not very much – reported awards have tended to be very low (in the low thousands at most).

All of that is very comforting for data controllers who run into difficulties.

That picture is, however, increasingly questionable. “Damage” (the precondition for any award, under s. 13 DPA) could mean something other than “financial loss” – other sorts of damage (even a nominal sort of damage) can, it seems, serve as the trigger. Also, provided the evidence is sufficiently persuasive, it seems that awards – whether under the DPA or at common law (negligence) – could actually be substantial.

These trends are evident in the judgment of the Court of Appeal of Northern Ireland in CR19 v Chief Constable of the Police Service of Northern Ireland [2014] NICA 54.

The appellant, referred to as CR19, was a police officer with the Royal Ulster Constabulary. Due to his exposure to some serious terrorist incidents, he developed Post-Traumatic Stress Disorder (PTSD); he also developed a habit of excessive alcohol consumption. He left the Constabulary in 2001. In 2002, there was a burglary at Castlereagh Police, apparently carried out on behalf of a terrorist organisation. Data and records on officers including CR19 were stolen.

The Constabulary admitted both negligence and a breach of the seventh data protection principle (failure to take appropriate technical and organisational measures). The issue at trial was the amount of compensation to which CR19 was entitled.

Note the losses for which CR19 sought compensation: he claimed that, as a result of the stress which that data loss incident caused him, his PTSD and alcohol problems worsened, he lost out on an employment opportunity and that his house had been devalued as a result of threats to the property and the package of security measures that had been implemented for protection.

The trial judge heard evidence from a number of parties, including medical experts on both sides. He found some aspects of CR19’s evidence unsatisfactory. Overall, however, he awarded CR19 £20,000 (plus interest) for the Constabulary’s negligence. He did not expressly deal with any award under s. 13 of the DPA.

CR19 appealed, saying the award was too low. His appeal was largely dismissed: the trial judge had been entitled to reach his conclusions on the evidence before him.

Further, the s. 13 DPA claim added nothing to the quantum. The Court of Appeal considered the cases of Halliday (a £750 award) and AB (£2,250) (both reported on Panopticon) and concluded as follows (para. 24):

“In this case we have earlier recorded that three eminent psychiatrists gave professional evidence as to the distress sustained by CR19 as a consequence of the break-in. While accepting that the breach and its consequences in this case are of a different order to the matters considered in Halliday or AB, we conclude that the damages for distress arising from the breach of the Data Protection Act must be considered to be subsumed into the judge’s award which, while rejected as too low by the appellant, was by no means an insignificant award. The assessment took account of the distress engendered by the breach of data protection. We cannot conceive of any additional evidence that might be relevant to any additional damages for distress in respect of breach of section 4. Accordingly, we affirm the award of compensation made by the learned trial judge. However, in view of Arden LJ’s reasoning in Halliday, we conclude that the appellant must in addition be entitled to nominal damages of £1.00 to reflect the fact that there was an admitted breach of section 4 of the Data Protection Act.”

Whilst it is not strictly correct to read the CR19 judgment as affirming a DPA award for £20,000 (that award was for negligence), the judgment is nonetheless interesting from a DPA perspective in a number of respects, including these:

(i) While it was conceded in Halliday that nominal damage suffices as “damage” for s. 13(1) purposes, that conclusion looks like it is being applied more widely.

(ii) One problem in Halliday (and to an extent also in AB) was the lack of cogent evidence supporting the alleged damage. The CR19 case illustrates how evidence, including expert medical evidence, can be deployed to effect in data breach cases (whether based on negligence or on the DPA).

(iii) Unlawful acts with respect to individuals’ personal information can, it seems, lead one way or another to a substantial award. The DPA may aim to offer relatively modest awards (so said the Court of Appeal in Halliday), but serious misuse or loss of personal data can nonetheless be very damaging, and the law will recognise and compensate for this where appropriate.

Robin Hopkins @hopkinsrobin

Closed proceedings in FOIA appeals – new FTT checklist

The question of how far tribunals should go in terms of allowing evidence and submissions to be dealt with on a closed basis in FOIA appeals is one that looms large for all FOIA practitioners. Judge Nicolas Warren, the President of the First-Tier Tribunal (Information Rights) has now drafted and circulated to all FTT judges a checklist for dealing with closed proceedings under rule 14 of the Tribunal rules. Not being one to keep the public in the dark about such judicial guidance, Judge Warren has kindly agreed to the checklist being reproduced in full on the blog – see further below:

General Regulatory Chamber (Information Rights) – Rule 14 Check list

  1. Has Rule 14 been correctly applied so far?  Should any closed material be made open?
  2. Is it necessary to hold part of the hearing in closed or do the closed written submissions suffice?
  3. Explain purpose of closed hearing to requestor.
  4. Ask requestor if there are any questions he or she particularly wants the Tribunal to put.  If requestor legally represented then the questions should be in writing.
  5. Is the hearing recorded?  If so, the closed session must also be recorded but separately and with the cd sealed and a note that it must not be opened with the permission of the Tribunal or the UT.
  6. During the closed session, keep a running note of anything new that is said which could properly be said in open session.
  7. At the conclusion of the closed session, agree with the representatives what is to be said to the requestor on return to open by way of:- (a) a gist of what must remain closed. (b)anything new that could have been said in open.
  8. In draft decision include an account of the procedure adopted and indicate what use if any was made of the closed material.

It is clear that this guidance is intended to increase the rigour and care with which tribunals approach the issue of closed hearings and, hence, to intensify compliance with natural justice principles. For further discussion of closed procedures in the information tribunal see further my previous posts on the Court of Appeal case of Browning here and here.

Anya Proops