“ I asked for a copy of my data but some information has been withheld”.”
“(1) A request may be made to the Commissioner by or on behalf of any person who is, or believes himself to be, directly affected by any processing of personal data for an assessment as to whether it is likely or unlikely that the processing has been or is being carried out in compliance with the provisions of this Act. (2) On receiving a request under this section the Commissioner shall make an assessment in such manner as appears to him to be appropriate ... (3) ........ (4) Where the Commissioner has received a request under this section he shall notify the person who has made the request – a. whether he has made an assessment as a result of the request, and b. to the extent that he considers appropriate, having regard in particular to any exemption from section 7 applying in relation to the personal data concerned, of any view formed or action taken as a result of the request.” a. whether he has made an assessment as a result of the request, and b. to the extent that he considers appropriate, having regard in particular to any exemption from section 7 applying in relation to the personal data concerned, of any view formed or action taken as a result of the request.”
“I note that you seek to rely onsection 28 of the Data Protection Act 1998 in withholding certain information from .... It is not clear from your letter whether a certificate signed by a Minister of the Crown as described in sub-section 2 of section 28 is in existence. It would assist the Commissioner in considering ... request for an assessment of the processing if you could provide us with a copy of the certificate. In the absence of a Certificate the Commissioner would clearly have to give consideration to the question whether it would be appropriate to seek a copy of the information withheld by way of an Information Notice or whether there might be some other means by which he could be assured that proper reliance had been made upon the exemption. It is also not clear whether in fact you have informed .... of your reliance on section 28 and the existence of any Ministerial Certificate. As you know where a person is directly affected by the issuing of a certificate under sub-section 2 they may appeal to the Tribunal against the certificate. Clearly ....... would wish to consider this option.”
“Beyond this, and as I explained in my previous letter, because of the constraints imposed by section 28, we cannot comment further. I appreciate that this makes it difficult for you to form a judgment whether personal data has been unreasonably withheld. You have suggested there might be another way of exploring and progressing this assessment without recourse to the documents retained under section 28. I will be pleased to hear more about your approach.”
“As you are aware, section 28 of the Data Protection Act limits the extent to which we are able to assist you in this case. We will obtain a Ministerial Certificate signed by the Home Secretary should we be required to do so, but would first like to provide you with as much information as we possibly can given the limits imposed on us by the Act”
“Although we cannot supply you with copies of the full documents we can supply information from them beyond that supplied .... in response to .... subject to access request. I hope that this will be of some assistance to you in carrying out this assessment. Although certain parts of the text have been redacted, I hope that you will agree the remainder of the text not provided .... is not..... personal data and its disclosure was therefore not required when responding to ... request. Please do not disclose the information contained in “Annex A” to .... I hope that you find this letter and enclosed documents useful in conducting your assessment in this case. However should you still feel it to be necessary, we will provide you with a Ministerial Certificate. I look forward to receiving your further views on this matter.”
“Now therefore, I, the Rt Hon David Blunkett MP being a Minister of the Crown who is a member of the Cabinet in exercise of the powers conferred by section 28(2) of the Act to issue this certificate and certify that exemption is required from Part V (in particular, section 43) of the Act in respect of any personal data which would be disclosed by compliance with the Information Notice which will not already be disclosed to the Information Commissioner in the attached Schedule for the purpose of safeguarding national security.”
“Before issuing the certificate, the degree to which section 28 exemption applies has been reconsidered again. As a result of this the schedule to the certificate differs in certain respects from the document “Annex A” enclosed with my letter dated .... you will note that in the draft letter attached to the memorandum dated ..... the sentence in the third paragraph beginning...... is now disclosed to a greater extent than was the case before. In addition the names of individual ministers are now included in the memorandum dated .... and a letter dated ... However all the material previously held continues to remain subject to the exemption in section 28.”
“Personal data should be processed in accordance with the rights of data subjects under this Act.”
“1. Each member state shall provide that one or more public authority is responsible for monitoring the application within its territory of the provisions adopted by the Member States pursuant to this Directive. These authorities shall act with complete independence in exercising the functions entrusted to them. .... 3. Each of the authorities shall be endowed with: – Investigative powers, such as powers of access to data forming the subject matters of processing matters and powers to collect all the information necessary for the performance of it supervisory duties. ..... – Effective powers of intervention. ..... 4. Each supervisory authority shall hear claims lodged by any persons, or by an association representing that person, concerning the protection of his rights and freedoms in regard of the processing of personal data. The person concerned shall be informed of the outcome of the claim. Each supervisory authority shall, in particular, hear claims for checks on the lawfulness of data processing lodged by any person when the national provisions adopted pursuant to Article 13 of this Directive applies. The person shall at any rate be informed that a check has taken place. ....”
“(1) Subject to the following provisions of this section and sections 8 and 9, an individual is entitled – (a) to be informed by any data controller whether the personal data of which that individual is the data subject are being processed by or on behalf of that data controller, (b) if that is the case, to be given by the data controller a description of – (i) the personal data of which that individual is the data subject , (ii) the purposes for which they are being or are to be processed, and (iii) the recipients or classes of recipients to whom they are or may be disclosed, (i) the personal data of which that individual is the data subject , (ii) the purposes for which they are being or are to be processed, and (iii) the recipients or classes of recipients to whom they are or may be disclosed, To have communicated to him in intelligible form (i). the information constituting any personal data of which that individual is the data subject and (ii). any information available to the data controller as to the source of those data …”
“Whereas the activities referred to in Titles V and VI of the Treaty on European Union regarding public safety, defence, State security or the activities of the State in the area of the criminal laws fall outside the scope of Community law, without prejudice to the obligations encumbent upon Member States under Article 56 (2), Article 57 or Article 100 (a) of the Treaty establishing the European Community; whereas the processing of personal data that is necessary to safeguard the economic well-being of the State does not fall within the scope of the Directive where such processing relates to State security matters;”
“Scope” ............. (2) This Directive shall not apply to the processing of personal data: - in the course of an activity which falls outside the scope of Community law, such as those provided for by Titles in V and VI of the Treaty on European Union and in any case to processing any operations concerning public security, defence, State security (including the well-being of the State when the processing operation relates to State security matters) and the activities of the State and areas of criminal law.” - in the course of an activity which falls outside the scope of Community law, such as those provided for by Titles in V and VI of the Treaty on European Union and in any case to processing any operations concerning public security, defence, State security (including the well-being of the State when the processing operation relates to State security matters) and the activities of the State and areas of criminal law.”
“Exemptions and Restrictions” 1. Member States may adopt legislative measures to restrict the scope of the obligations and rights provided for an Article 6, 10, 11(1), 12 and 21 when such restriction constitutes a necessary measure to safeguard; (a) national security; (b) defence (c) public security; (d) The prevention, investigation, prosecution of criminal offences or breaches of ethics for regulated professions…..”
“(1) If the Commissioner – a. has received a request under section 42 in respect of any processing of personal data or b. reasonably requires any information for the purpose of determining whether the data controller has complied or is complying with the data protection principles, he may serve the data controller with a notice (in this Act referred to as “an information notice”) requiring the data controller within such time as is specified in the notice, to furnish the Commissioner in such form as may be so specified, with such information relating to the request or to compliance with the principles as is so specified …….” a. has received a request under section 42 in respect of any processing of personal data or b. reasonably requires any information for the purpose of determining whether the data controller has complied or is complying with the data protection principles, he may serve the data controller with a notice (in this Act referred to as “an information notice”) requiring the data controller within such time as is specified in the notice, to furnish the Commissioner in such form as may be so specified, with such information relating to the request or to compliance with the principles as is so specified …….”
“22. The Respondent acknowledges that the core issue in this appeal is whether the information should be disclosed to the Appellant, who wishes to assess whether non-disclosure of the information to .... was necessary to safeguard National Security. 23. However, the respondent believes that the disclosure of the information to the appellant is unnecessary for the proper performance by the appellant of functions under the 1998 Act. The appellant’s functions do not include the making of such an assessment. The supervision under the 1998 Act of the respondent’s decisions about non disclosure for that reason are reserved to this tribunal by section 28 as intended by Parliament when passing the Act. Furthermore the Investigatory Powers Tribunal is the appropriate forum for any complaint by a member of the public that the respondent has made an erroneous decision to adhere to the “neither confirm nor deny” policy.”
“26. Consequently the precautionary principles underling the protection of national security required the respondent to regard the information as at risk of further disclosure .... (or other members of the public) once it has been disclosed to the appellant. 27. Therefore, as it is unnecessary under the 1998 Act to disclose the information to the appellant, and as none disclosure of the information to the appellant is necessary to ensure none disclosure of the information to .... (or other members of the public) which in turn is necessary for the safeguarding of national security, the respondent had reasonable grounds for signing the certificate which is the subject of this appeal.”
“Our conclusions are: (i) As the 1998 Act must be construed, so far as it is possible to do, so as to accord with the Directive .... and given the terms of Article 28(4) and Article 13 (which does not exclude Article 28(4)) The role of the supervisory authority (i.e. the Information Commissioner ....) cannot in our judgment be excluded on the ground of national security. In our judgment, within the context of Section 28 exemptions, the Commissioner and the Secretary of State each has a role to play. This view, it seems to us, is reinforced by section 51(1) of the Act (not a provision from which “personal data” are exempted by section 28) which extends the Commissioners duty “so as to perform his functions under the act as to promote the observance of the [its] requirements...” to all data controllers. ii) Various factors are relevant to any section 28 assessment as to whether exemption from any of the specified provisions is “required” for the purpose of safeguarding national security. Those factors include: a) the nature of the data – the spectrum of “security-sensitive” material is wide; to some material a significantly greater degree of sensitivity will be attached. b) the status and attributes of the entity it seeking in disclosure; c) the degree to which any “risk” attached to a particular disclosure can be “managed”; d) the terms of the specific provision(s) from which exemption is being considered: e) where information is sought by the Commissioner, the fact that he has a statutory role to play in the context of section 28 exemptions. iii. The assessment exercise relating to whether exemption is required for the purpose of safeguarding national security is to be conducted objectively both by the data controller and by the Commissioner in considering his Part V powers. In the event of disagreement, the data controller’s assessment will be subject to the procedures under the Act for the final determination of the question. (See below) iv. The terms of section 28(11) highlight the need for scrupulous observance of section 28(1). Exemption from one or more of the specified provisionary is only permissible where an exemption from that provision is required in all the circumstances of that case, for the purpose of safeguarding national security. Section 28(11) provides: “No power conferred by any provision of Part V may be exercised in relation to personal date which by virtue of this section are exempt from that provision.”