"(1) A Bulk Personal Dataset… is a dataset that contains personal data about individuals, the majority of whom are unlikely to be of intelligence interest, and that is incorporated into an analytical system and used for intelligence purposes. Typically, such datasets are very large, too large to be processed manually. (2) The [Agencies] obtain and exploit BPD for several purposes: - to help identify subjects of interest or unknown people that surface in the course of investigations; - to establish links between individuals and groups; - or else to improve understanding of targets' behaviour and connections; - and to verify information obtained through other sources. (3) BPD obtained and exploited by the [Agencies] includes a number of broad categories of data. By way of example only these include: biographical and travel (eg passport databases); communications (eg telephone directory); and financial (eg finance related activity of individuals). (4) While each of these datasets in themselves may be innocuous, intelligence value is added in the interaction between multiple datasets. One consequence of this is that intrusion into privacy can increase. (5) BPD is operationally essential to the [Agencies] and growing in importance and scale of holdings. Examples of the vital importance of BPD to intelligence operations include… identifying foreign fighters [and] preventing access to firearms."
"44) MI5 acknowledges that it holds the following categories of BPD: [Law Enforcement Agencies]/Intelligence. These datasets primarily contain operationally focussed information from law enforcement or other intelligence agencies. Travel. These datasets contain information which enable the identification of individuals' travel activity. Communications. The datasets allow the identification of individuals where the basis of information held is primarily related to communications data, eg a telephone directory. Finance. These datasets allow the identification of finance related activity of individuals. Population. These datasets provide population data or other information which could be used to help identify individuals, eg passport details. Commercial. These datasets provide details of corporations/individuals involved in commercial activities. 45) A number of these datasets will be available to the public at large. Some of these publicly available datasets will be sourced from commercial bodies, and we will pay for them (as another public body or a member of the public could do). MI5 also acquired BPD from Government departments, from [MI6] and GCHQ and from law enforcement bodies. 46) MI5's holding of passport information is key to our ability to be able to investigate travel activity. Holding that data in bulk, and being able to cross-match this to other data and other BPD held, is what enables us to find the connection and 'join the dots.' That would simply not be possible if we did not hold the bulk data in the first place. Using travel data, for example, to try and establish the travel history of a particular individual will necessarily involve holding, and searching across a range of BPD and other data that we hold, and it is through fusing these that we are able to resolve leads and identify particular individuals, with high reliability, at pace and with minimum intrusion. 47) Holding the data in bulk (and holding data relating to persons not of intelligence interest) is an inevitable and necessary prerequisite to being able to use these types of dataset to make the right connections between disparate pieces of information. Without the haystack one cannot find the needle; and the same result cannot be achieved (without fusion/combination) through carrying out a series of individual searches or queries of a particular dataset (or a number of datasets). 48) It is also relevant to note that as BPDs are searched electronically there was inevitably significantly less intrusion into individuals' privacy, as any data which has not produced a 'hit' will not be viewed by the human operator of the system, but only searched electronically."
"(i) GCHQ, MI5 and MI6 collect and hold BPDs, on their respective analytical systems. (ii) BPDs consist of large amounts of personal data: The majority of individuals whose personal data is contained in a BPD will be of no intelligence interest. (iii) Multiple BPDs are analysed together to obtain search results. (iv) BPD may be acquired through overt and covert channels. (v) BPD can contain sensitive personal data as defined unders2 of the Data Protection Act 1998 and/or information covered by legal professional privilege, journalistic material and financial data. (vi) GCHQ, MI5 and MI6 share BPDs, and BPDs may be shared with their foreign partners and/or may be disclosed to persons outside the agencies, as described in their Handling Arrangements. (vii) MI5, GCHQ and MI6 each acquire BPDs from other Government departments. …GCHQ, MI5 and MI6 do not currently hold and have never held a BPD of medical records, although medical data may appear in BPDs. (viii) There have been instances of non-compliance with BPD safeguards at GCHQ, MI5 and MI6, as disclosed in the various Commissioners' Reports. (ix) There was no statutory oversight of BPDs by the [Intelligence Services] Commissioner prior to the March 2015 ISC Report. (x) Prior to the publication of that ISC Report, the holding of BPDs was not publicly acknowledged."
"continue to keep under review the acquisition, use, retention and disclosure by the [Agencies] of [BPDs], as well as the adequacy of safeguards against misuse [and to] assure himself that the acquisition, use, retention and disclosure of [BPDs] does not occur except in accordance with [the 1989 and 1994 Acts and to] seek to assure himself of the adequacy of the [Agencies'] handling arrangements and their compliance therewith."
"157. …the rules governing the use of [BPDs] are not defined in legislation. Instead, the [Agencies] derive the authority to acquire and use [BPDs] from the general powers to obtain and disclose information (in support of their organisation's functions) that are afforded to the heads of each of the [Agencies] under theIntelligence Services Act 1994 … and theSecurity Service Act 1989 … 160. In terms of independent review, the Intelligence Services Commissioner has non-statutory responsibility for overseeing the [Agencies'] holdings of [BPDs]… The Commissioner explained to the Committee that he retrospectively reviews the [Agencies'] holdings of [BPDs] as part of his six-monthly inspection visits. This includes reviewing the intelligence case for holding specific datasets, necessity and proportionality considerations, the possible misuse of data and how that is prevented… Internal controls 161. The Agencies have told the Committee that the acquisition and use of [BPDs] is tightly controlled, and that the HRA 'triple test' (ie for a lawful purpose, necessary and proportionate) is considered both at the point of acquisition, and also before any specific searches are conducted against the data (which is when they consider the principal intrusion into an individual's privacy to occur). 162. Senior staff are responsible for authorising the acquisition of Bulk Personal Datasets. The Director General of MI5 explained: …there are datasets that we deliberately choose not to reach for, because we are not satisfied that there is a case to do it, in terms of necessity and proportionality… The Agencies each have a review panel, chaired by a senior official, which meets every six months to review the [BPDs] currently held by the Agency… Datasets that are found not to have sufficient operational value are deleted. 163. The Agencies have said that they apply strict policy and process safeguards to control and regulate access to the datasets…. These controls include: i) Training, audit and disciplinary procedures… ii) Heightened safeguards for sensitive categories of information… We note that while these controls apply inside the Agencies, they do not apply to overseas partners with whom the Agencies may share the datasets…"
"In response, GCHQ conducted a detailed review of the processes and procedures governing decisions to share data in bulk with foreign partners and then implemented measures to bring about improvements. In the future, this area will be covered as part of our regular oversight and inspection arrangements. The main outcomes of GCHQ's review are as follows: Sharing of bulk data with foreign intelligence partners is now incorporated into our regular oversight and inspection processes; The review has brought new standardisation. Decisions and permissions to share are captured on a Data Sharing Permission (DSP) form and stored electronically in a central location; Each DSP records the necessity and proportionality of sharing a type of bulk data with the partner in question and how the partner safeguards operational data, confirms that the relevant [BPD] warrant permits overseas sharing, and also details the accesses covered and equity considerations; Each foreign partner has provided written assurance in relation to their handling of shared bulk data; A dedicated team is the formal coordination point and record keeper of DSPs for the sharing of bulk data with Five Eyes and other foreign partners; and GCHQ has invested in the development of a workflow tool to automate the DSP process by marrying operational data sharing in their systems to the DSPs. This provides a double-check capability that mitigates the risk of sharing without permission. An additional feature is the ability automatically to match warrants to operational purposes, thus reducing the burden on those checking that the appropriate operational purpose/s are present and correct. We anticipate that the measures taken by GCHQ including the automated workflow tool, when implemented, will improve compliance in this area. They will provide a centralised record of what data is shared with whom, where and why. The decisions about sharing will be accessible by GCHQ staff as required, by our inspectors and, when necessary, by the IPT and will meet the requirements described in the Tribunal's CLOSED [2018 judgment]. Bulk personal data (BPD) Overall, administration of bulk personal datasets (BPDs) within GCHQ is to a high standard. During this reporting period GCHQ introduced a clear and auditable process when considering the classification of BPD. All decisions and details of the datasets are collated internally and recorded in an auditable manner. We intend to review this material at future BPD inspections."
"This assessment depends on all the circumstances of the case, such as the nature, scope and duration of the possible measures, the grounds required for ordering them, the authorities competent to authorise, carry out and supervise them, and the kind of remedy provided by the national law."
"[a determination] whether the procedures for supervising the ordering and implementation of the restrictive measures are such as to keep the 'interference' to what is 'necessary in a democratic society…'"
"(1) the nature of the offences which may give rise to an interception order; (2) a definition of the categories of people liable to have their telephones tapped; (3) a limit on the duration of telephone tapping; (4) the procedure to be followed for examining, using and storing the data obtained; (5) the precautions to be taken when communicating the data to other parties; and (6) the circumstances in which recordings may or must be erased or the tapes destroyed."
"Having regard to the safeguards against abuse in the procedures as well as the more general safeguards offered by the supervision of the Commissioner and the review of the IPT, the impugned surveillance measures, insofar as they may have been applied to the applicant… are justified under art 8(2)."
"349. …the importance of supervision and review will be amplified, because of the inherent risk of abuse and because the legitimate need for secrecy will inevitably mean that, for reasons of national security, States will often not be at liberty to disclose information concerning the operation of the impugned regime. 350. Therefore, in order to minimise the risk of the bulk interception power being abused, the Court considers that the process must be subject to "end-to-end safeguards", meaning that, at the domestic level, an assessment should be made at each stage of the process of the necessity and proportionality of the measures being taken; that bulk interception should be subject to independent authorisation at the outset, when the object and scope of the operation are being defined; and that the operation should be subject to supervision and independent ex post facto review. In the Court's view, these are fundamental safeguards which will be the cornerstone of any article 8 compliant bulk interception regime…"
"Each stage of the bulk interception process – including… onward transmission… of the intercept material – should also be subject to supervision by an independent authority and that supervision should be sufficiently robust to keep the "interference" to what is "necessary in a democratic society"
"…the transfer… to a foreign intelligence partner… would only give rise to an issue underArticle 8 of the Convention if the intercepting State did not first ensure that its intelligence partner, in handling the material, had in place safeguards capable of preventing abuse and disproportionate interference, and in particular, could guarantee the secure storage of the material and restrict its onward disclosure."
"(i) There must not be an unfettered discretion for executive action. There must be controls on the arbitrariness of that action. We must be satisfied there exist adequate and effective guarantees against abuse. (ii) The nature of the rules fettering such discretion and laying down safeguards must be clear and the ambit of them must be in the public domain so far as possible; there must be an adequate indication or signposting, so that the existence of interference with privacy may in general terms be foreseeable. (iii) Foreseeability is only expected to a degree that is reasonable in the circumstances, being in particular the circumstances of national security, and the foreseeability requirement cannot mean that an individual should be enabled to foresee when the authorities are likely to resort to secret measures, so that he can adapt his conduct accordingly. (iv) It is not necessary for the detailed procedures and conditions which are to be observed to be incorporated in rules of substantive law. (v) It is permissible for the Tribunal to consider rules, requirements or arrangements which are "below the waterline" ie which are not publicly accessible, provided that what is disclosed sufficiently indicates the scope of the discretion and the manner of its exercise. (vi) The degree and effectiveness of the supervision or oversight of the executive by independent Commissioners is of great importance, and can, for example, in such a case as Kennedy be a decisive factor."
"At the hearing a point was also raised by Mr de la Mare about the consequences for sharing arrangements with foreign agencies and others. This was a topic which was dealt with by the Tribunal in its [2018 judgment]… Mr de la Mare accepted that this is one of those topics which will have to be considered at a later stage in these proceedings."
"● Follow the principles and approach set out in our respective handing arrangements and policy/guidance ● Take into account the nature of the BPD/BCD that was due to be disclosed ● Take into account the nature/remit of the body to which we were considering disclosing the BPD/BCD ● Take into account the approach taken by any other [intelligence agency] who may have shared bulk data and have regard to any protocols/understandings that the other agencies may have used/followed ● Depending on the individual circumstances seek assurances that the BPD/BCD in question would be handled in accordance with RIPA safeguards… ● If relevant to the particular circumstances, seek assurances that its use was in accordance with the UK's international obligations. ● Any data shared with the organisation would be shared on the basis that it must not be shared beyond the recipient organisation unless explicitly agreed in advance or approved through the Action-on process. Action-on is a process which is used by each of the Agencies."
"(i) The fact that errors occur in the handling of data does not necessarily establish that safeguards or oversight were not effective; no oversight can be expected to prevent any errors occurring. (ii) The mere fact that errors are reported, or are detected by internal or external audit, may be evidence that the oversight system is working, not that it is defective. (iii) There is a duty on the Agencies… to report to the Commissioner anything that is material for the Commissioner to know in order to perform his oversight function properly; if there has been a failure to report a material use of data of which the commissioner might not be aware… then that is to be treated as a failure… to ensure proper safeguards and oversight. (iv) A Commissioner has a considerable margin of appreciation as to what resources he needs to perform his functions correctly, and there are no grounds for criticism of his decisions as to how he applies those resources; it is not the function of the Tribunal to audit the performance of a Commissioner's functions; the fact that a new Commissioner might take a different view on an issue does not establish that there were not adequate and effective arrangements before. (v) The question may well be capable of being resolved by reference to whether there has been a systemic failure in oversight arrangements, not whether in particular respects the performance of the Agencies can be criticised."
"As for the position under EU law, in relation to transfer of intelligence out of the EU to foreign agencies, that must obviously await the outcome of the Reference to the CJEU."