“police will only disclose information to the local Partnership where there is a clear legal basis to do so and under the terms of the agreed Information Sharing Agreement. Information provided under partnership arrangements by police is for the prevention and detection of crime and prosecution of offenders and must not be used for any other purpose.”
“personal data which are, by their nature, particularly sensitive in relation to fundamental rights and freedoms merit specific protection, as the context of their processing could create significant risks to the fundamental rights and freedoms.”
“The possibility to collect those data only in connection with other data on the natural person concerned, the possibility to secure the data collected adequately, stricter rules on the access of staff of the competent authority to the data, and the prohibition of transmission of those data.”
“The risk to the rights and freedoms of natural persons, of varying likelihood and severity, may result from data processing which could lead to physical, material or non-material damage, in particular: where the processing may give rise to discrimination, identity theft or fraud, financial loss, damage to the reputation… where data subjects might be deprived of their rights and freedoms or from exercising control over their personal data; where personal data are processed which reveal racial or ethnic origin, political opinions, religion or philosophical beliefs or trade union membership; where genetic data or biometric data are processed in order to uniquely identify a person or where data concerning health or data concerning sex life and sexual orientation or criminal convictions and offences or related security measures are processed…where personal data of vulnerable natural persons, in particular children are processed; or where processing involves a large amount of personal data and affects a large number of data subjects.”
“The controller in relation to personal data is responsible for, and must be able to demonstrate, compliance with this Chapter.”
“Implement appropriate technical and organisational measures to ensure, and to be able to demonstrate, that the processing of personal data complies with the requirements of [Part 3 of the DPA 2018].”
“(1) … the processing of personal data for any of the law enforcement purposes must be lawful and fair. (2) The processing of personal data for any of the law enforcement purposes is lawful only if and to the extent that it is based on law and (a) the data subject has given consent to the processing for that purpose, or (b) the processing is necessary for the performance of a task carried out for that purpose by a competent authority. (a) the data subject has given consent to the processing for that purpose, or (b) the processing is necessary for the performance of a task carried out for that purpose by a competent authority. (3) In addition, where the processing for any of the law enforcement purposes is sensitive processing, the processing is permitted only in the two cases set out in subsections (4) and (5). (4) The first case is where – (a) the data subject has given consent to the processing for the law enforcement purpose as mentioned in subsection 2(a), and (b) at the time when the processing is carried out, the controller has an appropriate policy document in place (see section 42). (5) The second case is where— (a) the processing is strictly necessary for the law enforcement purpose, (b) the processing meets at least one of the conditions in Schedule 8, and (c) at the time when the processing is carried out, the controller has an appropriate policy document in place (see section 42).”
“1. Statutory etc. purposes This condition is met if the processing a) is necessary for the exercise of a function conferred on a person by an enactment or rule of law, and b) is necessary for reasons of substantial public interest. 2. Administration of Justice This condition is met if the processing is necessary for the administration of justice. 3. Protecting Individual’s vital interests This condition is met if the processing is necessary to protect the vital interests of the data subject or of another individual. 4. Safeguarding of children and of individuals at risk This condition is met if a) is necessary for the exercise of a function conferred on a person by an enactment or rule of law, and b) is necessary for reasons of substantial public interest. This condition is met if (i). protecting an individual from neglect or physical, mental or emotional harm, or (ii). protecting the physical, mental or emotional wellbeing of an individual (b). The individual is – (i) aged under 18, or (ii) aged 18 or over and at risk. (c). The processing is carried out without the consent of the data subject for one of the reasons listed in sub-paragraph (2) and (d). The processing is necessary for reasons of substantial public interest. (2).
“(a) explains the controller’s procedures for securing compliance with the data protection principles (see section 34(1)) in connection with sensitive processing in reliance on the consent of the data subject or (as the case may be) in reliance on the condition in question. (b) explains the controller’s policies as regards the retention and erasure of personal data processed in reliance on the consent of the data subject or (as the case may be) in reliance on the condition in question, giving an indication of how long such personal data is likely to be retained.”
“Personal data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.”
“a duty to put in place a system of measures to safeguard data that are appropriate having regard to the operations of the data controller and the nature of the data for which he is responsible. What is appropriate will vary from case to case.”
“… “appropriate” sets a minimum standard as to the security which is to be achieved. This is expressly subject to both the state of technological development and the cost of measures. Thus, the fact that a degree of security may technologically be achievable, which has not been implemented, does not of itself amount to failure to reach an appropriate standard … a balance has to be struck between the significance of the cost of preventative measures and the significance of the harm that might arise if they are not taken. This is itself intended to be a combination of the nature of the harm in itself and the importance of the data to be safeguarded from that harm”
“[the Respondent] is required to implement the “appropriate technical and organisational measures” required under Part 3, including the requirement to demonstrate compliance (s.56); to implement the principles in an effective manner, and to integrate the safeguards necessary (s.57(1)); and to ensure that personal data is not made accessible to an indefinite number of people without an individual’s intervention (s.57(5)).”
“Section 6 of the Crime and Disorder Act 1998 , the common law duties and core functions of the police, to prevent and detect crime and disorder provide the legal basis to share sensitive personal data to the extent that it is necessary for these purposes.”
“the information to be supplied is proportionate for the needs of this agreement. The information is shared on a case-by-case basis, with only the minimum amount of information necessary, for the purposes of identifying and monitoring individuals within the [BCRP] area.”
“Until the threshold for exclusion is reached information will not be shared with members. Upon reaching the threshold, consideration will be given to whether exclusion from all venues is required/appropriate. If not, information will only be shared with the relevant members. All members sign a binding data integrity agreement which prevents them from sharing information with third parties who are not Members of the BCRP. If the data integrity agreement is breached, procedures are in place to identify the guilty party and act accordingly.”
“If you conduct sensitive processing for a number of different LE purposes you do not need a separate policy document for each condition or processing activity – one document can cover them all. You may reference policies and procedures which are relevant to all the identified processing.” [Emphasis supplied].
“No matter relating to any child or young person concerned in proceedings to which this section applies shall while he is under the age of 18 be included in any publication if it is likely to lead members of the public to identify him as someone concerned in the proceedings”
“no matter relating to any person concerned in the proceedings shall while he is under the age of 18 be included in any publication if it is likely to lead members of the public to identify him as a person concerned in the proceedings.”
“personal data processed for any of the law enforcement purposes must be so processed in a manner that ensures appropriate security of the personal data, using appropriate technical or organisational measures (and, in this principle, “appropriate security” includes protection against unauthorised or unlawful processing and against accidental loss, destruction or damage).”