M, R (on the application of) v The Chief Constable of Sussex Police & Anor

[2019] EWHC 975 (Admin)

Case details

Case citations
[2019] EWHC 975 (Admin)
Court
High Court (Administrative Court)
Judgment date
15 April 2019
Judgment text

This feature is available to zoomLaw Pro members.

Subjects
Administrative law Data protection Human rights
Keywords
Data Protection Act 2018 data sharing sensitive personal data children and young persons child sexual exploitation appropriate safeguards duty of candour bail conditions judicial review
Outcome
claim dismissed in part; claimant succeeded on one part of issue two
Judicial consideration

This feature is available to zoomLaw Pro members.

Summary

A data controller must demonstrate that its arrangements comply with the Data Protection Act 2018 and must implement appropriate technical and organisational safeguards. The statutory requirement concerns the system of safeguards, not merely whether there is a serious risk of an individual breach. Proportionality is relevant when assessing whether safeguards are sufficient. The assessment should consider the nature of the data, who may receive it, onward disclosure, training and vetting, the interests of children, and the public protection purpose. A child’s interests require particular weight, but the Act does not require separately listed safeguards for children. Information about a child’s vulnerability to sexual exploitation requires specific and careful assessment before disclosure.

Factual background

The claimant, a vulnerable 16-year-old, challenged Sussex Police’s arrangements for sharing personal data with a Business Crime Reduction Partnership and several past disclosures. The first issue concerned the December 2018 Information Sharing Agreement under the Data Protection Act 2018. The second concerned disclosures made principally under the 2017 agreement and the Data Protection Act 1998, including information about alleged offending, a photograph, bail conditions, and vulnerability to child sexual exploitation.

The court also considered whether disclosure of bail conditions breached statutory restrictions on identifying children involved in criminal proceedings, and whether the defendant had complied with its duty of candour.

Held

  1. Issue One dismissed. The defendant had to demonstrate compliance with the data protection principles and maintain appropriate safeguards. The court rejected the submission that the agreement would be unlawful only if it created a serious risk of an individual breach. The statutory scheme required a compliant system, while allowing proportionality in assessing whether safeguards were sufficient.
  2. The relevant assessment was holistic. It included:
    • the nature of the data shared;
    • the persons who could access it and controls on onward disclosure;
    • training, vetting and licensing of recipients; and
    • the specific interests of children and young people.
    The public protection and crime-prevention purpose was also relevant.
  3. The 2018 agreement and its appendices were legally capable of being read together. Safeguards contained in incorporated documents had to be clearly identified and accessible. The agreement was poorly drafted, particularly concerning the exclusion of bail conditions and the legitimate-interest assessment, but the safeguards, taken together, were sufficient. The secure intranet, access controls, data-integrity obligations, vetting and licensing requirements provided proportionate safeguards.
  4. Children’s interests had particular weight in the Article 8 balance, and data sharing could itself increase risks to a vulnerable child. The Law Enforcement Directive recital concerning vulnerable persons assisted interpretation but did not create an independent requirement for separately listed child-specific safeguards.
  5. The 2017 agreement did not breach the Data Protection Act 1998 or 2018. Its safeguards were less clearly expressed, and the treatment of bail conditions was troubling, but the principal controls over the data shared and onward transmission were present.
  6. Disclosure of information about incidents and of the claimant’s photograph and other personal information was lawful. Disclosure of information revealing vulnerability to sexual exploitation was unlawful under the 1998 Act because the defendant had not shown that it had properly assessed the risks, benefits or onward-disclosure safeguards.
  7. Disclosure of bail conditions to BCRP members and their employees was not disclosure to members of the public for the purposes of the Children and Young Persons Act 1933 or the Youth Justice and Criminal Evidence Act 1999. The recipients obtained the information in an employment or contractual capacity and were subject to restrictions on its use.

The court’s approach to earlier authorities

This feature is available to zoomLaw Pro members.

Appellate history

This was a first-instance judicial review in the Administrative Court. No earlier decision in the same proceedings is stated.

Appeal to higher court

Outcome of appeal
appeal dismissed; cross-appeal allowed

Key cases cited

This feature is available to zoomLaw Pro members.

Cases citing this case

This feature is available to zoomLaw Pro members.