“Please may you provide me with: The Agendas of any and all meetings of Castle Point Borough Council committees, Castle Point Borough Council sub-committees, or meetings of any other formal decision-making body made up of Castle Point borough councillors, that took place at the Castle Point Borough Council Offices in Kiln Road, between the dates of15th August 2022 and30th August 2022 . The Minutes of any and all meetings of Castle Point Borough Council committees, Castle Point Borough Council sub-committees, or meetings of any other formal decision-making body made up of Castle Point borough councillors, that took place at the Castle Point Borough Council Offices in Kiln Road, between the dates of15th August 2022 and30th August 2022 . The subject titles of any and all reports presented to any and all meetings of Castle Point Borough Council committees, Castle Point Borough Council sub-committees, or meetings of any other formal decision-making body made up of Castle Point borough councillors, that took place at the Castle Point Borough Council Offices in Kiln Road, between the dates of15th August 2022 and30th August 2022 .”
“The principles of data protection should apply to any information concerning an identified or identifiable natural person. Personal data which have undergone pseudonymisation, which could be attributed to a natural person by the use of additional information should be considered to be information on an identifiable natural person. To determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used, such as singling out, either by the controller or by another person to identify the natural person directly or indirectly. To ascertain whether means are reasonably likely to be used to identify the natural person, account should be taken of all objective factors, such as the costs of and the amount of time required for identification, taking into consideration the available technology at the time of the processing and technological developments.”
‘Are those interests overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data?’
“At paragraph 52 of its decision the FTT treated the approach to disclosure under FOIA and that under the DPA as being the same. This is incorrect. The observations of Lord Rodger of Earlsferry in Common Services Agency v Scottish Information Commissioner[2008] 1 WLR 1550 at [68], which the FTT relied upon, do not support any such equivalence. In the same case at [7] Lord Hope said of the DPA and the EU Directive which it implemented, “the guiding principle is the protection of …[the] right to privacy with respect to the processing of personal data”
“…the balancing process in the application of the Goldsmith questions “is different from the balance that has to be applied under, for example, section 2(1)(b) of FOIA” (see GR-N v Information Commissioner and Nursing and Midwifery Council[2015] UKUT 449 (AAC) at paragraph 19). Furthermore FOIA stipulates that the section 40(2) exemption applies if disclosure would contravene the data protection principles enshrined in the DPA, so it is the DPA regime which must be applied. There is no obvious reason why the general transparency values underpinning FOIA should automatically create a legitimate interest in disclosure under the DPA.”.” “…the balancing process in the application of the Goldsmith questions “is different from the balance that has to be applied under, for example, section 2(1)(b) of FOIA” (see GR-N v Information Commissioner and Nursing and Midwifery Council[2015] UKUT 449 (AAC) at paragraph 19). Furthermore FOIA stipulates that the section 40(2) exemption applies if disclosure would contravene the data protection principles enshrined in the DPA, so it is the DPA regime which must be applied. There is no obvious reason why the general transparency values underpinning FOIA should automatically create a legitimate interest in disclosure under the DPA.”.”
“The correct approach to the application of section 1(1)(b) This was referring tosection 1(1)(b) of the Data Protection Act 1998 , which was in force prior to the DPA, and which set out the definition of ‘personal data’ for the purposes of the 1998 Act. to disclosure of anonymised data was addressed by the House of Lords in Common Services Agency v Scottish Information Commissioner[2008] 1 WLR 1550 . That decision was discussed by the Administrative Court in R (Department of Health) v Information Commissioner [2011] EWHC1430 (Admin). Cranston J explained that the House of Lords had decided that, even though the data controller holds the key to identification of individuals to which the data relates, whether it is personal information when disclosed depends on “whether any living individuals can be identified by the public following disclosure of the information” (paragraph 52). In Information Commissioner v Magherafelt District Council [2013] AACR 14 the Upper Tribunal said that the decision in Department of Health meant that the proper approach to whether anonymised information is personal data within section 1(1)(b), for the purposes of a disclosure request, is to consider whether an individual or individuals could be identified from it and other information which is in the possession of, or likely to come into the possession of a person other than the data controller after disclosure. In the Department of Health case Cranston J said at paragraph 66 that the assessment of the likelihood of identification included “assessing a range of every day factors, such as the likelihood that particular groups, such as campaigners, and the press, will seek out information of identity and the types of other information, already in the public domain, which could inform the search.”
“37 …A ‘motivated intruder’ was ‘…a person who starts without any prior knowledge but who wishes to identify the individual or individuals referred to in the purportedly anonymised information and will take all reasonable steps to do so.’. The question was then one of assessment by a public authority as to ‘… whether, taking account of the nature of the information, there would be likely to be a motivated intruder within the public at large who would be able to identify the individuals to whom the disclosed information relates.’ While not expressly adopting that test, the approach of the Upper Tribunal in that case was consistent with it. A similar approach was taken by the Court of Session (Inner House) in Craigdale Housing Association v The Scottish Information Commissioner[2010] CSIH 43 at paragraph 24: “…it is not just the means reasonably likely to be used by the ordinary man on the street to identify a person, but also the means which are likely to be used by a determined person with a particular reason to want to identify the individual…using the touchstone of, say, an investigative journalist…”.” “assessing a range of every day factors, such as the likelihood that particular groups, such as campaigners, and the press, will seek out information of identity and the types of other information, already in the public domain, which could inform the search.” “37 …A ‘motivated intruder’ was ‘…a person who starts without any prior knowledge but who wishes to identify the individual or individuals referred to in the purportedly anonymised information and will take all reasonable steps to do so.’. The question was then one of assessment by a public authority as to ‘… whether, taking account of the nature of the information, there would be likely to be a motivated intruder within the public at large who would be able to identify the individuals to whom the disclosed information relates.’ “…it is not just the means reasonably likely to be used by the ordinary man on the street to identify a person, but also the means which are likely to be used by a determined person with a particular reason to want to identify the individual…using the touchstone of, say, an investigative journalist…”.”
“processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data...”
“If there is another way of satisfying [the requestor’s] legitimate interests without disclosing the information, then disclosure is not necessary”
“a measure would not be necessary if the legitimate aim could be achieved by something less”