R (M) v Chief Constable of Sussex [2019] EWHC 975 (Admin)
- Summary
- Citing
- Cited By
R (M) v Chief Constable of Sussex [2019] EWHC 975 (Admin) concerned a challenge by a 16-year-old vulnerable girl, through the Official Solicitor, to the lawfulness of data sharing between Sussex Police and a local Business Crime Reduction Partnership (BCRP). Mrs Justice Lieven dismissed the challenge to the information sharing agreement itself but held that disclosure of information about the claimant’s vulnerability to child sexual exploitation had breached data protection law.
M was a vulnerable teenager with convictions for shoplifting and assault who had been reported for more than 50 incidents of violence, theft or anti-social behaviour since October 2017. She had been assessed by the local authority as being at risk of child sexual exploitation. The BCRP, an organisation with more than 500 members including retailers, security firms, pubs and nightclubs, managed an exclusion notice scheme prohibiting persons from entering members’ commercial premises. In November 2017 M was made subject to a 12-month exclusion order. Police shared data about M with the BCRP pursuant to an Information Sharing Agreement. The Police and BCRP entered into an Information Sharing Agreement in November 2017 (ISA2017). The Data Protection Act 2018 came into force on 25 May 2018, replacing the Data Protection Act 1998. A further agreement was entered into in December 2018 (ISA2018).
M brought two challenges: first, that the agreements to share information lacked sufficient safeguards to prevent unlawful processing of her sensitive personal data, contrary to the Data Protection Act 2018 (Issue One); and secondly, that specific past disclosures of her sensitive personal data by the Defendant to the BCRP had been unlawful (Issue Two). Permission was granted by Lang J in December 2018, but the Defendant’s initial evidence and grounds of defence fell short of full disclosure. The Defendant applied late, in February 2019, to rely on further evidence including the BCRP Constitution, Code of Practice, Data Integrity Agreement and the ISA2018 itself, explaining the delay by poor communication between the BCRP and Police. The court allowed the additional evidence but observed that relevant material remained undisclosed and that this failure to comply fully with the duty of candour affected the weight that could be attached to the Defendant’s policy documents and submissions about safeguards.
The BCRP consisted of an Executive Committee, a Board of Management and the members. One of the Defendant’s Chief Inspectors sat on the Executive Committee. Members submitted incident reports, and once an individual reached a certain threshold their information including photographic image was shared via a secure intranet site and mobile application. The BCRP Constitution designated the Board of Management as data controller. The Code of Practice required all members to comply with data protection law, provided for training of BCRP employees, required vetting of persons employed by the partnership, and established that information provided by police under the partnership was for the prevention and detection of crime and must not be used for any other purpose. The Code also required third party employees to be disclosed data only on a case-by-case basis and subject to the Data Protection Act, and required audits of members to maintain appropriate standards of security and confidentiality. The Data Integrity Agreement required members not to disclose data to non-signatory members and to prevent unauthorised access.
The ISA2017 set out the types of information the Defendant would share with BCRP, including details of incidents relating to criminal or anti-social behaviour, details of missing persons, details of Community Behaviour Orders, bail conditions relating to known BCRP subjects, and photographs. Photographs could be exchanged after the BCRP received three reports of criminal or anti-social behaviour within eight months, or after one incident of violence or other serious offences. Information shared was required to be stored securely, not disclosed to third parties without written consent, and destroyed when no longer required. There was to be a clear audit trail. Photographs were to be treated as confidential, viewed only by appropriate staff, and not copied or altered. The agreement required that shared information only be used for the specific purpose for which it was requested. Data held was to be reviewed at least every 12 months for validity and relevance.
The ISA2018 was entered into in December 2018 to ensure compliance with the Data Protection Act 2018 and the General Data Protection Regulation 2018 (GDPR). It stated that the Police and BCRP were joint data controllers. It set out the legal basis for sharing, referring to Article 6(f) of the GDPR and noting that the necessity test may be overridden where the data subject is a child. Only if the BCRP manager or representative had been National Police Vetting level 2 (NPV2) vetted could they extract data directly. Information would not be shared to businesses outside the secure intranet. Security officers of BCRP members were required to hold valid licences from the Security Industry Authority and be DBS checked. Appendix 4 of the ISA2018 was headed “Policy for processing personal data on children and minors on the basis of legitimate interest” and set out the principles on protecting children’s rights, though it was primarily concerned with the decision whether to exclude children from premises rather than data sharing after exclusion. A separate Legitimate Interest Assessment document stated that the data to be processed comprised name, date of birth, photographic image, address and offences against BCRP members; bail conditions were not listed.
Evidence before the court showed that BCRP received incident reports from members via online reporting to a secure database. Once an individual reached a certain threshold their image, name, date of birth and type of offence were shared with BCRP members via the secure intranet. The Police might be asked to provide a photographic image. For minors the decision to share information was taken by a Board of Management of three people including at least one senior member. Out of 500 members, 239 had been granted access to the intranet. If members did not log on for six weeks they were automatically removed. Every six months members were locked out of the intranet and required to re-certify their adherence to the data integrity agreement before regaining access.
The Police shared the following data about M with BCRP: information that she had been observed in five incidents of assault, violence, affray, breach of bail, and assault on police officers, one of which occurred on 7 June 2018 and therefore fell under the 2018 Act. The Defendant also accepted it had shared M’s name, date of birth, photograph and bail conditions on four occasions. The photograph was biometric data and therefore sensitive personal data. The Police disputed that they had disclosed data stating that M was a person who was sexually vulnerable or at risk of sexual exploitation. M had gone missing on a number of occasions in August 2017. In October 2017 the Defendant emailed BCRP to report that M was missing, stating that this was concerning due to the company she was now keeping and referring to “intel for CSE risks” (child sexual exploitation risks). The BCRP replied that it would distribute to members via its website. In November 2017 local media reported that M was missing and that police were seriously concerned. The Defendant emailed BCRP asking for help to locate her. M was subsequently located and taken into interim foster care. In November 2017 the BCRP served M with an exclusion order by reference to numerous reports of her anti-social behaviour. In December 2017 the BCRP emailed the Defendant complaining about assaults by young people and stating that members were frustrated and that staff were afraid to come to work. The BCRP emailed an alert to members asking them to report any incidents concerning M and circulated a notice containing M’s photo and referring to reports of her involvement in criminal activity. The notice stated that the partnership was working very closely with partner agencies to ensure appropriate action was taken. A social worker with Children’s Services emailed the Defendant in December 2017 to express concern that alerts for missing girls including their names and photographs remained accessible online even after they had been found. The social worker warned that this protocol might well put young people at risk. In February 2018 M was arrested for assault and granted bail. An order was made under section 45 of the Youth Justice and Criminal Evidence Act 1999 prohibiting M’s identification. M’s solicitor became aware that BCRP was sharing M’s data by means of its app, including her full name and date of birth, her bail conditions, her status as a “top 10” offender, that she was known for theft or fraud, and that she was named in relation to Operation C, directed at vulnerable young women allegedly involved in anti-social or criminal behaviour. In March and April 2018 the Council raised concerns that M’s bail conditions had been revealed and were being posted on social media. In May 2018 M’s solicitors sent pre-action letters to the Defendant and BCRP requiring them to cease processing her personal data on the basis that the processing was contrary to the Data Protection Acts, article 8 ECHR, and the anonymity requirements of section 45 of the Youth Justice and Criminal Evidence Act 1999.
Part 3 of the Data Protection Act 2018 sets out the provisions for handling data. The Defendant was a competent authority and a data controller within the meaning of sections 30 and 32. Sections 34 to 40 set out the six data protection principles. Section 35 provides that processing must be lawful and fair and is lawful only if based on law and either the data subject has consented or the processing is necessary for the performance of a task carried out for a law enforcement purpose by a competent authority. Where the processing is sensitive processing, it is permitted only where the data subject has consented and the controller has an appropriate policy document in place, or where the processing is strictly necessary for the law enforcement purpose, meets at least one of the conditions in Schedule 8, and the controller has an appropriate policy document in place. Sensitive processing includes processing of biometric data for the purpose of uniquely identifying an individual. Schedule 8 conditions include where the processing is necessary for the exercise of a function conferred by an enactment and necessary for reasons of substantial public interest, necessary for the administration of justice, necessary to protect the vital interests of the data subject or another, and safeguarding of children or individuals at risk. Paragraph 4 of Schedule 8 provides that the safeguarding condition is met if the processing is necessary for protecting an individual from harm, the individual is under 18 or at risk, the processing is carried out without consent for one of the specified reasons, and the processing is necessary for reasons of substantial public interest. Section 40 sets out the sixth data protection principle that personal data must be processed in a manner that ensures appropriate security using appropriate technical or organisational measures.
In CLG v Chief Constable of Merseyside Police [2015] EWCA Civ 836 the Court of Appeal held that the seventh data protection principle relates to the implementation of appropriate systems for ensuring the protection of personal data and imposes a duty to put in place a system of measures to safeguard data that are appropriate having regard to the operations of the data controller and the nature of the data. In Various Claimants v WM Morrisons Supermarket Plc [2017] EWHC 3113 (QB) Langstaff J held that “appropriate” sets a minimum standard as to the security to be achieved, subject to both the state of technological development and the cost of measures, and that a balance has to be struck between the significance of the cost of preventative measures and the significance of the harm that might arise if they are not taken. On appeal in Morrisons the Court of Appeal observed that under the 2018 Act the data controller must take reasonable steps to ensure the reliability of employees who have access to personal data, and that the Act expressly recognises the potential liability of a data controller for the wrongful processing of data by his employees, but instead of imposing vicarious liability it imposes a primary liability on the employer restricted to taking reasonable steps to ensure the reliability of employees. Section 42 requires the controller to have an appropriate policy document in place explaining the controller’s procedures for securing compliance with the data protection principles in connection with sensitive processing and explaining the controller’s policies regarding retention and erasure of personal data. Chapter 4 of Part 3 sets out the general obligations of controllers and processors. Section 56 requires each controller to implement appropriate technical and organisational measures to ensure and to demonstrate that processing complies with Part 3. Section 57 requires each controller to implement appropriate technical and organisational measures designed to implement the data protection principles in an effective manner and to integrate into the processing the necessary safeguards. Section 59 provides that the controller may only use a processor who provides guarantees to implement appropriate technical and organisational measures sufficient to secure that the processing will meet the requirements of Part 3 and ensure the protection of the rights of the data subject, and that the processing by the processor must be governed by a contract in writing setting out specified matters. Section 66 requires each controller and processor to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risks arising from the processing of personal data.
The court held that the burden of showing compliance with the 2018 Act falls on the Defendant under section 34(2). The court rejected the Defendant’s argument that the agreement is only unlawful where it would give rise to a serious risk of breach of the Act, observing that there is a requirement on the data controller to show compliance with the data principles under section 43(3) and a legal requirement to have in place a system with appropriate safeguards that meets the terms of the 2018 Act. The court held that it was not necessary to decide whether the Defendant remained the data controller after sharing the data with BCRP or whether they were joint data controllers or BCRP became a data controller on its own, as the Defendant was undoubtedly the data controller at the point it passed the information to BCRP and the duties in section 32(2) applied. The Defendant therefore had duties to implement appropriate technical and organisational measures under Part 3 to ensure that processing of personal data complies with Part 3, to implement the data protection principles in an effective manner and the necessary safeguards, to ensure that personal data is not made accessible to an indefinite number of people, and to ensure a level of security appropriate to the risks. The court held that these duties have to be interpreted in the light of recital 50 of the Law Enforcement Directive, which refers to specific safeguards in respect of vulnerable natural persons such as children, and also in line with the individual’s article 8 right to privacy, particularly the need to protect the article 8 rights of children.
The court considered four factors in deciding whether the safeguards were sufficient to meet the statutory requirements: the nature of the data that can be shared; the provisions as to who it can be shared with and control over onward sharing; the requirements for the training and vetting of recipients of the data; and the degree to which the specific interests of children are factored into the proportionality exercise. In deciding whether the sharing is proportionate the court also took into account the reason or justification for the sharing. On the nature of the information shared, the court noted that under ISA2018 the only information which could be shared according to Box J of the Legitimate Interest Assessment was name, date of birth, photographic image, address and offences against BCRP members, excluding bail conditions. The court found that this restriction was unsatisfactory because it was not set out in the ISA itself nor in Appendix 4, and
R (Quark Fishing Ltd) v Secretary of State for Foreign and Commonwealth Affairs [2002] EWCA Civ 1409
Graham v Police Service Commission [2011] UKPC 46
CLG & Ors v Chief Constable of Merseyside Police [2015] EWCA Civ 836
Various Claimants v WM Morrisons Supermarket Plc [2017] EWHC 3113
El-Gizouli v Secretary of State for the Home Department [2019] EWHC 60
Gillick v West Norfolk Health Authority [1986] 2 AC 112
Munjaz v Merseyside NHS trust [2006] 2 AC 148
ZH (Tanzania) v Secretary of State for the Home Department [2011] 2 AC 166, [2011] UKSC 4
R (on the application of Bancoult (No.2)) v Secretary of State for Foreign and Commonwealth Affairs [2016] UKSC 35