Secretary of State for Home Department, R (on the application of) v The Information Tribunal

[2006] EWHC 2958 (Admin)

Case details

Case citations
[2006] EWHC 2958 (Admin) · [2008] 1 WLR 58 · [2007] 2 All ER 703
Court
High Court (Administrative Court)
Judgment date
23 November 2006
Judgment text

This feature is available to zoomLaw Pro members.

Subjects
Administrative Data protection National security exemptions
Keywords
Data Protection Act 1998 section 28 certificate Information Commissioner national security information notice judicial review Information Tribunal right of appeal
Outcome
application dismissed
Judicial consideration

This feature is available to zoomLaw Pro members.

Summary

The Information Commissioner has a statutory role in assessing whether a national-security exemption under Data Protection Act 1998, section 28, has been properly claimed. A ministerial certificate does not prevent the Commissioner from investigating or serving an information notice before the exemption is finally determined. The Commissioner is directly affected by a certificate because it restricts the exercise of his statutory functions, and may appeal against it. The question whether disclosure to the data subject would endanger national security is distinct from whether disclosure to the Commissioner would do so. The latter issue must be addressed separately, with appropriate safeguards under the Tribunal’s procedural rules.

Factual background

An individual sought access to personal data held by the Home Department. The Information Commissioner began an assessment under section 42 of the Data Protection Act 1998 and served an information notice under section 43. The Secretary of State then issued a national-security certificate under section 28(2), claiming exemption from Part V of the Act.

The Information Tribunal allowed the Commissioner’s appeal under section 28(4) and quashed the certificate. The Secretary of State sought judicial review, arguing that the Commissioner had no role in testing the exemption and no right of appeal. The central issue was whether section 28 excluded the Commissioner from investigating the claim before the exemption had been finally determined.

Held

  1. Application dismissed. The Tribunal had correctly quashed the certificate because the Secretary of State had proceeded on the mistaken basis that the Commissioner had no statutory role in relation to the section 28 exemption.
  2. Section 51(1) of the Data Protection Act 1998, read with Article 28(4) of the Directive, entitled, and if appropriate required, the Commissioner to check whether an exemption under section 28 had been properly claimed. That function included seeking sufficient information to assess whether the data controller had complied with the Act.
  3. Section 28(11) prevented the exercise of Part V powers only in relation to personal data which were properly exempt from the relevant provision. It did not prevent the Commissioner from seeking information or serving a section 43 notice before the exemption had been determined. The certificate mechanism and the Tribunal’s appeal procedures provided the means by which the issue could ultimately be resolved.
  4. The Commissioner was directly affected by a section 28(2) certificate because the certificate restricted the exercise of his statutory functions under section 51(1). He therefore had a right of appeal under section 28(4), independently of whether his section 42 assessment could ultimately proceed.
  5. The question whether disclosure to the data subject would compromise national security was distinct from the question whether disclosure to the Commissioner would do so. The Secretary of State had to consider the latter question separately. If disclosure to the Commissioner presented a security risk, the Tribunal could address that issue under the Information Tribunal (National Security Appeals) Rules 2005.
  6. The Directive did not require a different result. Article 3(2) provided the underlying exclusion, while Article 13 permitted national-security restrictions and Article 28(4) contemplated mechanisms for testing whether such restrictions had been properly claimed.

The court’s approach to earlier authorities

This feature is available to zoomLaw Pro members.

Appellate history

  • Information Tribunal: allowed the Commissioner’s appeal under section 28(4) of the Data Protection Act 1998 and quashed the Secretary of State’s certificate.
  • High Court (Administrative Court): dismissed the Secretary of State’s judicial review application and upheld the Tribunal’s conclusion.

Key cases cited

This feature is available to zoomLaw Pro members.

Cases citing this case

This feature is available to zoomLaw Pro members.