“It calls for a comparison of what the relevant law requires and what a policy statement says regarding what a person should do. If the policy directs them to act in a way which contradicts the law it is unlawful. The courts are well placed to make a comparison of normative statements in the law and in the policy, as objectively construed.”
“There is often no obligation in public law for an authority to promulgate any policy and there is no obligation, when it does promulgate a policy, for it to take the form of a detailed and comprehensive statement of the law in a particular area, equivalent to a textbook or the judgment of a court. Since there is no such obligation, there is no basis on which a court can strike down a policy which fails to meet that standard. … If the test were more demanding there would be a practical disincentive for public authorities to issue policy statements for fear that they might be drawn into litigation on the basis that they were not sufficiently detailed or comprehensive…the courts would be drawn into reviewing and criticising the drafting of policies to an excessive degree. In effect they would have a revising role thrust upon them requiring them to produce elaborate statements of the law to deal with hypothetical cases which might arise within the scope of a policy. Such a role for the courts cannot be justified.”
“It is the Claimant’s case that in issuing the MPS Policy, the Defendant was exercising statutory powers conferred by section 4(3) of the PRSRA (which places the metropolitan police force and the civilian staff of the metropolitan police force under the direction and control of the Defendant) and paragraph 4(1) of Schedule 4 of the PRSRA which provides that the Defendant “may do anything which is calculated or is conducive or incidental to, the exercise of the functions of the Commissioner” but that the Defendant failed to exercise those powers in accordance with the “policy and objects” of the statute and took into account irrelevant considerations while failing to take account of relevant considerations. The policy and objects of the PRSRA include the directing of officers and staff to comply with relevant legal obligations and to promote public confidence in policing. The legal obligations pertinent to police record keeping arise from the CPIA, DPA, FOIA, PRA, HRA and associated Codes of Practice.”
“The metropolitan police force, and the civilian staff of the metropolitan police force, are under the direction and control of the Commissioner of Police of the Metropolis.”
“The duty to retain material includes in particular the duty to retain material falling into the following categories, where it may be relevant to the investigation: crime reports (including crime report forms, relevant parts of incident report books or police officers’ notebooks); • custody records; • records which are derived from tapes of telephone messages (for example, 999 calls) containing descriptions of an alleged offence or offender; • final versions of witness statements (and draft versions where their content differs from the final version), including any exhibits mentioned (unless these have been returned to their owner on the understanding that they will be produced in court if required); • interview records (written records, or audio or video tapes, of interviews with actual or potential witnesses or suspects); • communications between the police and experts such as forensic scientists, reports of work carried out by experts, and schedules of scientific material prepared by the expert for the investigator, for the purposes of criminal proceedings; • records of the first description of a suspect by each potential witness who purports to identify or describe the suspect, whether or not the description differs from that of subsequent descriptions by that or other witnesses; • any material casting doubt on the reliability of a witness.” d. “5.6 The duty to retain material falling into these categories [i.e. in Code ¶5.4] does not extend to items which are purely ancillary to such material and possess no independent significance (for example, duplicate copies of records or reports).”
“4.1 If material which may be relevant to the investigation consists of information which is not recorded in any form, the officer in charge of an investigation must ensure that it is recorded in a durable or retrievable form (whether in writing, on video or audio tape, or on computer disk). 4.2 Where it is not practicable to retain the initial record of information because it forms part of a larger record which is to be destroyed, its contents should be transferred as a true record to a durable and more easily-stored form before that happens. … 4.4 Where information which may be relevant is obtained, it must be recorded at the time it is obtained or as soon as practicable after that time. This includes, for example, information obtained in house-to-house enquiries, although the requirement to record information promptly does not require an investigator to take a statement from a potential witness where it would not otherwise be taken.”
“It may become apparent to an investigator that some material obtained in the course of an investigation, either because it was considered to be potentially relevant, or because it was inextricably linked to material that was relevant, is in fact incapable of impacting on the case. It is not necessary to retain such material. However, the investigator should also exercise considerable caution in reaching that conclusion. The investigator should be particularly mindful of the fact that some investigations continue over some time. Material that is incapable of impact may change over time and it may not be possible to foresee what the issues in the case will be. The advice of the prosecutor may be sought where necessary. Ultimately, however, the decision on whether to retain material is one for the investigator, and should always be based on their assessment of the relevance of the material and the likelihood of it having any impact on the case in future.”
“This annex is intended to supplement the Attorney General’s Guidelines on Disclosure. It is not intended to be a detailed operational guide but is intended to set out a common approach to be adopted when seeking to obtain and handle digital material, whether that be from a suspect or from a complainant or witness.”
“No action should be taken which changes data on a device which may subsequently be relied upon in court.”
“…the MPS mandates officers to activate disappearing messages with the effect that information that may be relevant to an investigation will not be retained (in contravention of section 23(1) of the CPIA). The test of whether information may be relevant is exceptionally broad and includes information that has “some bearing on any offence under investigation or any person being investigated, or on the surrounding circumstances of the case, unless it is incapable of having any impact on the case” (SOFG [CB/42, §67]). In this sense the MPS Policy mandates unlawful conduct: the destruction of material that ought to be retained for CPIA review and potential disclosure.”
“If one simply asks whether a policy creates an unacceptable risk that an individual will be treated unfairly (which is to say, unlawfully), there is a danger that this could be taken as a freestanding principle distinct from that in Gillick Re A at paragraph 64. .”
“then the chat can be exported (see guidance in annex 1) and uploaded to Axon Capture, by the user, as soon as possible and all actions properly recorded on Connect.”
“Parliament must have conferred the discretion with the intention that it should be used to promote the policy and objects of the Act; the policy and objects of the Act must be determined by construing the Act as a whole…if the Minister…so uses his discretion as to thwart or run counter to the policy and objects of the Act, then our law would be very defective if persons aggrieved were not entitled to the protection of the court.”
“It is obvious that a public body cannot exercise any of its powers in a way which is contrary to other legislative provisions; but that is not because of the Padfield principle, which is, as Cavanagh J demonstrates by reference to the authorities, altogether narrower. I note that Padfield was not even cited to the court in the New London College case. No doubt at a very deep level the two limitations are underpinned by the same principle, namely that a public body must always act within the powers that Parliament intended it to enjoy…”
“Forces that don’t monitor the sensitive information officers and staff are viewing on force mobile phones create an exceptionally high risk for themselves. The use of encrypted apps can make monitoring harder. Forces need to reassure themselves that they understand all the risks of having encrypted apps on force-issue phones. They then need to take steps to mitigate those risks.” risks.”
“Fulfilling information related obligations where WhatsApp is used for police work. Police forces have legal obligations for information collation and storage. WhatsApp is not a police system and is not connected to police systems. WhatsApp chats may form a part of a police investigation file, which would require a process by which chats can be saved to the relevant file: an audit trail of relevant information. There are also legal obligations for accessibility, disclosure, processing and retention. The information obtained during this review suggests police forces need to put in place processes to ensure they fulfil these obligations.”
“The ICO identified the risks arising from auto-deletion and stated: “As far as reasonably practicable, you should always ensure that you use corporate channels for official business. Where this is not possible for whatever reason, you should make arrangements to store official information on your corporate systems as quickly as possible”
“Whilst it is recognised that there are significant benefits in the use of instant messaging. The use of WhatsApp for policing purposes, presents an information security risk with data being managed outside of the United Kingdom and the police service having no jurisdiction on the control of that data. You will also be aware of the CPIA implications to consider with the retention of relevant material stored within encrypted applications. …. In the interim to mitigate the risks associated with encrypted applications, we would encourage the use of the Microsoft O365 Teams Chat and TeamSpace functions which is auditable and replicates the functionality of WhatsApp.”
“WhatsApp is a widely used app by a number of members of the public. The MPS requires to use the app to ensure that we can communicate with all members of our communities. It is also required to ensure MPS colleagues can use it to engage with each other and prevent them from using it on their personal devices for work purposes. If WhatsApp is used in line with our proposed use, it is not foreseen that there will be a high level of risk in relation to the sharing of any MPS data.”
“This updated draft DPIA seeks to respond to the ICOs helpful commentary and is updated with changes to the planned operation model. Significantly, it was originally envisaged that LBM might capture routine incoming and outgoing WhatsApp traffic and in effect produce a central ‘data lake’ which could be interrogated to deal with rights of access under both DPA18 and FOIA2000 legislative provisions. However whilst nothing escapes the purview of LBM there will be no comprehensive recording of all messages i.e. no comprehensive central record. On the basis of sensitivity, the operating model for LBM will not be detailed herein but will be confined to the relevant LBM DPIA”
“WhatsApp messages are stored on the end user’s device rather than in any corporate repository which is centrally located. WhatsApp may also be configured to back up the messages to cloud storage. The issues of retention, review, and deletion and ensuring that records find their way into the appropriate repository are significant. For example, the MPS would not be able to comply with a data subject statutory rights unless it can ascertain whether personal data relating to the individual exists. The same is true in respect of whether the MPS holds information related to a particular subject unless likewise this can be searched for. It is therefore recommended that the MPS ensures that: A base retention period is set by the MPS to meet business need and to curtail excessive retention. That there is a mechanism in place which ensures that messages reaching end of life are automatically deleted unless there is a reason for further retention and that deletion is from devices and any backups. A mechanism is developed to deliver a capability of comprehensive central searching of WhatsApp messages at least (but not exhaustively) by topic, dates, MPS sender/recipient, and personal information held. This will enable core rights and obligations to be upheld. These include DPA 18 rights of access and rights to be forgotten etc.; FOIA 2000;Public Inquiries Act 2005 ; etc. That mechanisms and policies are reviewed to ensure that material which should be transferred into some other form of corporate storage for the purposes are identified and transferred. For example that intelligence is moved into the intelligence system and records relevant to CPIA is moved into case files.”
“At this stage of development and without sight of scope and policy in respect of usage; and of mitigations to risk, it is impossible to adequately assess residual risk. As such the residual risks to the rights and freedoms of individuals must be assumed to remain high. This DPIA should therefore be further developed to the extent that the processing risks and mitigations can be fully described and reviewed again at that point. Mandatory referral to the ICO is only required before processing commences where risks cannot be mitigated below high.”
“We do have some other questions around the DPIA, however, and I’d like to raise these here for your consideration and response when appropriate: Paragraph 19 – what form will the Lawful Business Monitoring take? How is this done via individual devices and will this require that the WhatsApp messages are copied to, and retained on, other MPS systems? If so, what access controls and governance will secure that information? Is there any risk of collateral intrusion into messages received from the public, eg are these stored in MPS servers somewhere? Para 23 – esp deletion. I note the messages are intended to auto-delete at 90 days, and transferred to other police systems if retention is required. What mechanism will the MPS put in place to respond to a deletion request received within the 90 day period? Similarly, what measures will control how a subject access or FOI information request is responded to if received within the 90 day period? See also para 26 and 27 re retention under Lawful Business Monitoring – what measures will be in place to give effect to individuals’ rights, and the right of access under FOIA?” raise these here for your consideration and response when appropriate: Paragraph 19 – what form will the Lawful Business Monitoring take? How is this done via individual devices and will this require that the WhatsApp messages are copied to, and retained on, other MPS systems? If so, what access controls and governance will secure that information? Is there any risk of collateral intrusion into messages received from the public, eg are these stored in MPS servers somewhere? Para 23 – esp deletion. I note the messages are intended to auto-delete at What mechanism will the MPS put in place to respond to a deletion request received within the 90 day period? Similarly, what measures will control how a subject access or FOI information request is responded to if received within the 90 day period? See also para 26 and 27 re retention under Lawful Business Monitoring – what measures will be in place to give effect to individuals’ rights, and the right of access under FOIA?”
“As you have detailed, the use of WhatsApp within MPS should be accompanied by clear policies to manage the associated risks, especially regarding external groups and the potential lack of oversight. Staff should exercise caution while using WhatsApp due to its known security vulnerabilities, such as the minimal requirements for registration and user identification. Just to further highlight the importance that sharing of personal data on the platform should be limited, WhatsApp use should primarily focus on administrative and logistical purposes. We would recommend that internal guidance is very clear and explicit as to the limits of acceptable use.” accompanied by clear policies to manage the associated risks, especially regarding external groups and the potential lack of oversight. Staff should exercise caution while using WhatsApp due to its known security vulnerabilities, such as the minimal requirements for registration and user identification. Just to further highlight the importance that sharing of personal data on the platform should be limited, WhatsApp use should primarily focus on administrative and logistical purposes. We would recommend that internal guidance is very clear and explicit as to the limits of acceptable use.”
“Further, DC Archer’s described practice in relation to her WhatsApp communications with the complainant, her practice in relation to “chat” exports and her practices in relation to saving media (i.e. material sent in addition to “chat” content) underline the Claimant’s case that the Commissioner’s Policy on WhatsApp and instant messaging (“the MPS Policy”), especially those elements that (i) mandate reliance upon disappearing messages, (ii) permit interaction with complainants/witnesses/suspects and (iii) propose a means for evidential export, is incapable of ensuring sufficient compliance with the CPIA regime. The MPS Policy is therefore unreasonable and unlawful.”
“A system does not fail the rationality test simply because its design or day-to-day operation is capable of improvement in some respects, RAMFEL at [67] [SAB/1374 (pdf 1378)]. A system does not become unlawful because it creates an unacceptable risk that an individual would be treated unlawfully, A v SSHD at [65C-D] [CAB/191]. Those are the high hurdles. The Claimant’s example of one is incapable of surmounting that high hurdle.”
“As you have detailed, the use of WhatsApp within MPS should be accompanied by clear policies to manage the associated risks, especially regarding external groups and the potential lack of oversight. Staff should exercise caution while using WhatsApp due to its known security vulnerabilities, such as the minimal requirements for registration and user identification. Just to further highlight the importance that sharing of personal data on the platform should be limited, WhatsApp use should primarily focus on administrative and logistical purposes. We would recommend that internal guidance is very clear and explicit as to the limits of acceptable use.” accompanied by clear policies to manage the associated risks, especially regarding external groups and the potential lack of oversight. Staff should exercise caution while using WhatsApp due to its known security vulnerabilities, such as the minimal requirements for registration and user identification. Just to further highlight the importance that sharing of personal data on the platform should be limited, WhatsApp use should primarily focus on administrative and logistical purposes. We would recommend that internal guidance is very clear and explicit as to the limits of acceptable use.”
“Failure to disclose to the defence material evidence, which contains such particulars which could enable the accused to exonerate himself or have his sentence reduced would constitute a refusal of facilities necessary for the preparation of the defence, and therefore a violation of the right guaranteed in art.6(3)(b) of the Convention.”
“The Court recalls that, in this case, the decision regarding the undisclosed evidence was, presumably, made in the course of the pre-trial investigation without providing the defence with the opportunity to participate in the decision-making process. In the present case the Court further notes that the contested measure stemmed from a defect in the legislation, in that it failed to offer adequate protection to the defence, rather than any misconduct of the authorities, who were obliged by law, in force at the time, to destroy the impugned recordings. The Court observes that in the Government Bill for the amendment of the Coercive Measures Act it was considered problematic that information supporting the innocence of the suspect could be destroyed before the resolution of the case.”
“The Claimant has not pointed to any part of the chat itself that was relevant material.”