“3. The Appellant made a Data Subject Access Request on28th November 2022 for the evidence supporting an assertion regarding an earlier decision concerning the Appellant’s personal data that the Appellant understood to be incorrect and on the face of it the Commissioner’s representative was not in a position to make due to the Commissioner’s data retention policy. On5th January 2023 , he raised some questions about the information disclosed. Both sides worked collaboratively notwithstanding the various exemptions claimed to produce a mutually acceptable outcome. 4. As part of that email of5th January 2023 , the Appellant made his Freedom of Information Request in the following terms: “I would further like to request the ICO's internal case handling guidelines for DSAR's, ICO service complaints and case reviews to be provided to me under the FOIA. In order to minimise the work involved, I would be happy to receive the index/content to same at this stage and to advise which specific sections I require if that is more convenient.” 5. Upon receipt of the acknowledgement on9th January 2023 , he realised he had omitted the job descriptions of relevant staff from his request and asked the same day for those to be added to his existing request. It was intended to be the only one in this purported series of requests. 6. Instead the Commissioner processed the request for the job descriptions separately to avoid delay. The outcome was uncontentious. Following the equally uncontentious refusal of the remainder of the request under section 21, the Appellant again raised queries by way of his email of 18 th January 2023 in a similar fashion to the way he responded to the DSAR as he is perfectly entitled to do. 7. He had no intention whatsoever that this should amount to a further Freedom of Information Request or that his email should be interpreted as such. If anything, it should have been considered as a statement of non-compliance and a request for a review of the decision regarding his request of5th January 2023 . 8. The purported new request was rejected as being vexatious, a decision upheld at internal review and again by the Information Commissioner as Regulator.”
"The keeping it Clear guide" (referred to at P.76) "
“In my judgment the Upper Tribunal was right not to attempt to provide any comprehensive or exhaustive definition. It would be better to allow the meaning of the phrase to be winnowed out in cases that arise. However, for my own part, in the context of FOIA, I consider that the emphasis should be on an objective standard and that the starting point is that vexatiousness primarily involves making a request which has no reasonable foundation, that is, no reasonable foundation for thinking that the information sought would be of value to the requester or to the public or any section of the public. Parliament has chosen a strong word which therefore means that the hurdle of satisfying it is a high one, and that is consistent with the constitutional nature of the right. The decision maker should consider all the relevant circumstances in order to reach a balanced conclusion as to whether a request is vexatious. If it happens that a relevant motive can be discerned with a sufficient degree of assurance, it may be evidence from which vexatiousness can be inferred. If a requester pursues his rights against an authority out of vengeance for some other decision of its, it may be said that his actions were improperly motivated but it may also be that his request was without any reasonable foundation. But this could not be said, however vengeful the requester, if the request was aimed at the disclosure of important information which ought to be made publicly available...”
“Based on the information available to us it is our assessment that ARC Legal Services has infringed the Data Protection legislation, as it has failed to respond appropriately to your subject access request. It is our opinion that the exemption of Legal and Professional Privilege does not apply in this case. We have written to ARC Legal Services and advised the ICO’s position in this case. We have asked ARC Legal Services to revisit your SAR and consider what personal information you are entitled to without further delay.”
“We have considered the information regarding your complaint and it is my view that Trowers have handled your request reasonably. I recently wrote to Trowers about your concerns, specifically regarding the use of legal professional privilege. Where it appears you already have access to the information in question, it is unlikely the ICO would purse these concerns further. Trowers state you have already been provided with the information through your communications with Arc and therefore already have access to the data. I understand you believe the privilege shouldn’t apply because the ICO have previously reached a decision that the privilege didn’t apply in your complaint about Arc. Trowers still maintain the privilege applies between them and their client. The advice was provided by Trowers to Arc as their client and they still consider the information is subject to confidentiality and/or legal advice privilege. I do not believe it is suitable to instruct Trowers to release information they provided to their client based on this. As you have already been provided with this information I do not consider it appropriate or necessary for the ICO take any further action in this matter.”
“The reason we felt the information ought to be provided in RFA0809181 was because privilege had already been waived to part of the material involved. Whether or not you have a joint interest in the specific information being withheld is a factor we have considered in relation to whether or not Legal Professional Privilege (LPP) is able to apply to the information withheld from you in this case. We have investigated this aspect of this case already. We are satisfied that you do not have a joint interest in the specific information being withheld such that the claim of legal professional privilege for this advice between Trowers and Arc could be maintained in legal proceedings. We therefore consider the specific advice involved able to be withheld under LPP and do not consider you to be entitled to a copy of that information.”
“I would further like to request the ICO's internal case handling guidelines for DSAR's, ICO service complaints and case reviews to be provided to me under the FOIA. In order to minimise the work involved, I would be happy to receive the index/content to same at this stage and to advise which specific sections I require if that is more convenient.”
“To my request, I would also like to add the job description and person specification for the roles of Case Officer and Lead Case Officer and the full content of the internal guidance for handling DSAR cases and case reviews.”
“The correspondence between the Claimant and the Commissioner’s representatives and his disclosures pursuant to the Claimant’s DSARs which are in the possession of the Commissioner, including the job description and person specification for the Case Officer, Lead Case Officer and Reviewing Officer who represented the Commissioner and his internal casework guidance are the key documents upon which the Claimant proposes to rely in his claim against the Commissioner”
“Thank you for your helpful reply to my FOIA request. There are some issues that arise following your response: In regards to the "ICO Operations Directorate Service guide: How we use public concerns, self-reported incidents and complaints to improve information rights practice V4 24/11/16" linked to in your email and available on the ICO website: This is clearly out of date - is there a revised version or an equivalent or successor document? Kindly disclose or point me to it if available. If not, how are Caseworkers and other staff made aware of what they need to know to do their jobs? I would also like copies of the latest versions of the documents referred to therein or to their successors/equivalents as follows: "The keeping it Clear guide" (referred to at P.76) "Opportunity assessment framework" (p.22, 77) "Policy delivery knowledge base"; "Policy delivery legal group, Retention and disposal - preservation criteria - casework"; and the "Security manual" (all referred to on p.77) "Security manual - use of email" (p.53) the "need some policy advice? pages on ICON" and "policy delivery legal group pages on ICON" referred and linked to on p. 60 I would also like a copy of "Your personal information concerns (Request for Assessment) process" referred to at p. 10 of "Ways to progress a complaint case" in the disclosure log as linked to in your email. If these documents no longer exist or are outdated, how are ICO staff to be made aware of the type of information they contain(ed)? Can you confirm the ICO's policy on whether it will ask a data controller who seeks to rely on the disclosures of another data controller (NB: not processor) to meet its own DSAR obligations or fails to disclose personal data on the grounds that it reasonably believes it is already known to a data subject, to disclose the data it holds (i.e. whether these are acceptable reasons to fail to comply with a DSAR) and what criteria would influence such a decision? Kindly provide any relevant ICO documents that address these scenarios? Further to my email of09/01/2023 , 22:25, can you confirm for the avoidance of doubt that your response has dealt fully with my request for "the full content of the internal guidance for handling DSAR cases and case reviews"? I am still awaiting "the job description and person specification for the roles of Case Officer and Lead Case Officer" and, if different, Reviewing Officer also. Thank you for taking the time to provide the information requested. I am happy to clarify my requests if that would be of assistance. I look forward to your further reply.”
“I note that we have responded to three recent information requests from you, two made in January and one in November 2022, in which you make repeated and overlapping requests for copies of policy documents, job descriptions etc relating to the way that the ICO handles certain complaint matters, which appear to relate directly to our handling of past complaints that you have made to us. We have done our best, in responding to your previous requests, to provide you with the information that you require to assist you in understanding how we have dealt with your concerns and how the ICO handles complaints in general as part of our role as a regulator. However, the pattern of your correspondence indicates that your aim is to keep us engaged in perpetual dialogue with you with no intention of reaching a reasonable and satisfactory conclusion. This is evidenced by your latest request in which you have trawled through a piece of guidance that we have provided to you, compiled a list of further documentation referred to in it and made a further request for that documentation. It seems highly unlikely after reviewing this list that you have any genuine interest in this information and no doubt should we provide it, you would find reason to make further requests based on that information. Your contention that ICO staff are not properly trained because of the age of a piece of guidance provided to you is unfounded and not credible, ICO staff learn how to do their jobs in many ways including through training modules and on the job support from managers etc. That the guidance provided is not the sole source of training and guidance for ICO staff is a matter that we should not need to explain. Your enquiries on this point indicate that this series of requests is aimed more at finding an avenue to make unfounded statements about the competency of ICO staff and express dissatisfaction with the way that we have dealt with your past complaints, than to obtain information that you genuinely require. With regards to the last part of your request, the ICO does not hold such detailed and extensive guidance that it would specifically cover every possible scenario that may arise in a complaint case, such as the one that you have outlined. It would be unworkable for us to do so and instead we handle complaints on a case-by-case basis with reference to the legislation and general principles set out in our guidance etc. Continuing to make such specific requests appears to be a means for you to continue to create work for our staff when we have already provided you with enough information for you to understand how we handle complaints. We are therefore of the view that complying with this request would cause disruption and irritation which is entirely disproportionate to its value, and we are refusing it in line with s.14(1) FOIA.”
“I will therefore close this case. If you’re content for me to do so you don’t have to take any action and, if we don’t hear from you by27 April 2023 , it will be closed. Please note, section 50(2)I of FOIA states that the “Commissioner shall make a decision unless it appears to him that the application for a decision is frivolous or vexatious.”
“Can you confirm the ICO’s policy on whether it will ask a data controller who seeks to rely on the disclosures of another data controller (NB: not processor) to meet its own DSAR obligations or fails to disclose personal data on the grounds that it reasonably believes it is already known to a data subject, to disclose the data it holds (i.e. whether these are acceptable reasons to fail to comply with a DSAR) and what criteria would influence such a decision?”
“With regards to the last part of your request, the ICO does not hold such detailed and extensive guidance that it would specifically cover every possible scenario that may arise in a complaint case, such as the one that you have outlined. It would be unworkable for us to do so and instead we handle complaints on a case-by-case basis with reference to the legislation and general principles set out in our guidance I.”