Case details
Summary
Retained EU law required prior independent authorisation before security and intelligence agencies accessed communications data for ordinary criminal purposes. Internal authorisation within the same organisation was insufficient.
Other challenges to the Investigatory Powers Act 2016 failed. The statutory safeguards meant that its communications-data and bulk-power regimes were not “general and indiscriminate” in the relevant EU-law sense. EU law did not impose a freestanding duty to notify every person whose data had been accessed, or require accessed data to remain within the EU or UK, provided applicable data-transfer safeguards were maintained.
The court declined to apply the later Big Brother Watch judgment indirectly through the EU Charter.
Factual background
The claim was the third stage of a judicial review challenge to Parts 3, 4, 5, 6 and 7 of the Investigatory Powers Act 2016. Earlier stages had produced a declaration that Part 4 was incompatible with EU law in relation to access to retained data for criminal-justice purposes.
The remaining issues followed the CJEU judgments in Privacy International and La Quadrature du Net. They concerned communications-data retention and access, automated processing, notification, overseas data transfers, prior independent authorisation, bulk powers and the effect of Big Brother Watch.
Held
- Part 3 access for ordinary criminal purposes. The requirement in Watson CJEU for prior review by a court or independent administrative body applied to access to retained communications data for the applicable crime purpose. An “independent administrative body” had to be independent of the body applying for authorisation. Internal authorisation by a senior officer within a security or intelligence service therefore did not satisfy the requirement. The distinction between the police and those services was unjustified when the function being performed was ordinary crime prevention or detection. The ability to rely on section 61 rather than section 60A was incompatible with retained EU law.
- Other Parts 3 and 4 issues. The safeguards in the Act meant that the regimes were not general and indiscriminate. The [2021] 1 WLR 4457 requirements concerning automated analysis did not require identical wording in domestic legislation and were adequately addressed by the necessity, proportionality and other safeguards in the Act. EU law did not require additional notification of persons affected by access. The IPT, section 231 and the Code of Practice supplied an effective remedy without universal notification. The data-transfer rules did not breach EU law because they provided safeguards equivalent to those required for transfers outside the EU.
- Bulk powers. Part 7 was outside the scope of the e-Privacy Directive because it regulated the handling of datasets already obtained by state authorities and did not require communications providers to supply them. The bulk powers were not general and indiscriminate. Approval by a Judicial Commissioner, together with the statutory safeguards, was sufficient; separate independent authorisation was not required each time data was selected or accessed.
- Big Brother Watch. The later ECtHR judgment was not binding in these proceedings and could not indirectly impose requirements which later CJEU decisions did not establish. The claim therefore succeeded only in relation to the Part 3 and Part 4 prior-authorisation issue and was otherwise dismissed. The decision hearing on remedies was adjourned.
The court’s approach to earlier authorities
This feature is available to zoomLaw Pro members.
Appellate history
This was the third stage of the judicial review. The court had previously given judgments at [2018] EWHC 975 (Admin) and [2019] EWHC 2057 (Admin). An appeal concerning the Convention issues was pending before the Court of Appeal, but the present judgment determined the remaining EU-law issues.
Key cases cited
This feature is available to zoomLaw Pro members.
Cases citing this case
This feature is available to zoomLaw Pro members.