Summary
A data controller must demonstrate that its arrangements comply with the Data Protection Act 2018 and must implement appropriate technical and organisational safeguards. The statutory requirement concerns the system of safeguards, not merely whether there is a serious risk of an individual breach. Proportionality is relevant when assessing whether safeguards are sufficient. The assessment should consider the nature of the data, who may receive it, onward disclosure, training and vetting, the interests of children, and the public protection purpose. A child’s interests require particular weight, but the Act does not require separately listed safeguards for children. Information about a child’s vulnerability to sexual exploitation requires specific and careful assessment before disclosure.
Factual background
The claimant, a vulnerable 16-year-old, challenged Sussex Police’s arrangements for sharing personal data with a Business Crime Reduction Partnership and several past disclosures. The first issue concerned the December 2018 Information Sharing Agreement under the Data Protection Act 2018. The second concerned disclosures made principally under the 2017 agreement and the Data Protection Act 1998, including information about alleged offending, a photograph, bail conditions, and vulnerability to child sexual exploitation.
The court also considered whether disclosure of bail conditions breached statutory restrictions on identifying children involved in criminal proceedings, and whether the defendant had complied with its duty of candour.
Held
- Issue One dismissed. The defendant had to demonstrate compliance with the data protection principles and maintain appropriate safeguards. The court rejected the submission that the agreement would be unlawful only if it created a serious risk of an individual breach. The statutory scheme required a compliant system, while allowing proportionality in assessing whether safeguards were sufficient.
- The relevant assessment was holistic. It included:
- the nature of the data shared;
- the persons who could access it and controls on onward disclosure;
- training, vetting and licensing of recipients; and
- the specific interests of children and young people.
- The 2018 agreement and its appendices were legally capable of being read together. Safeguards contained in incorporated documents had to be clearly identified and accessible. The agreement was poorly drafted, particularly concerning the exclusion of bail conditions and the legitimate-interest assessment, but the safeguards, taken together, were sufficient. The secure intranet, access controls, data-integrity obligations, vetting and licensing requirements provided proportionate safeguards.
- Children’s interests had particular weight in the Article 8 balance, and data sharing could itself increase risks to a vulnerable child. The Law Enforcement Directive recital concerning vulnerable persons assisted interpretation but did not create an independent requirement for separately listed child-specific safeguards.
- The 2017 agreement did not breach the Data Protection Act 1998 or 2018. Its safeguards were less clearly expressed, and the treatment of bail conditions was troubling, but the principal controls over the data shared and onward transmission were present.
- Disclosure of information about incidents and of the claimant’s photograph and other personal information was lawful. Disclosure of information revealing vulnerability to sexual exploitation was unlawful under the 1998 Act because the defendant had not shown that it had properly assessed the risks, benefits or onward-disclosure safeguards.
- Disclosure of bail conditions to BCRP members and their employees was not disclosure to members of the public for the purposes of the Children and Young Persons Act 1933 or the Youth Justice and Criminal Evidence Act 1999. The recipients obtained the information in an employment or contractual capacity and were subject to restrictions on its use.
The court’s approach to earlier authorities
Available to signed-in members.
Appellate history
This was a first-instance judicial review in the Administrative Court. No earlier decision in the same proceedings is stated.
Appeal route
- This judgment [2019] EWHC 975 (Admin) High Court (Administrative Court)
- Appealed to[2021] EWCA Civ 42Outcomeappeal dismissed; cross-appeal allowed
Key cases cited
10 authorities cited.
- R (on the application of Bancoult (No 2)) v Secretary of State for Foreign and Commonwealth Affairs [2016] UKSC 35
- Dennis Graham v Police Service Commission and the Attorney General of Trinidad & Tobago (Trinidad and Tobago) [2011] UKPC 46
- ZH (Tanzania) (FC) v Secretary of State for the Home Department [2011] UKSC 4
- Regina v. Ashworth Hospital Authority (now Mersey Care National Health Service Trust) (Appellants) ex parte Munjaz (FC) (Respondent) [2005] UKHL 58
- CLG & Ors v Chief Constable of Merseyside Police [2015] EWCA Civ 836
- Secretary of State for Foreign and Commonwealth Affairs v Quark Fishing Ltd. [2002] EWCA Civ 1409
- McKerry v Teesdale & Wear Valley Justices [2000] EWCA Crim 3553
- El Gizouli, R (On the Application Of) v The Secretary of State for the Home Department [2019] EWHC 60 (Admin)
- Various Claimants v WM Morrisons Supermarket Plc (Rev 1) [2017] EWHC 3113 (QB)
- Race Relations Board v Dockers’ Labour Club and Institute Ltd (Dockers’ Labour Club and Institute Ltd v Race Relations Board) [1976] AC 285
Sign in to see how the court treated each authority. A free account is enough.
Cases citing this case
Available to signed-in members.