Geoffrey Driver v Crown Prosecution Service

[2022] EWHC 2500 (KB)

Case details

Case citations
[2022] EWHC 2500 (KB)
Court
High Court (King's Bench Division)
Judgment date
10 October 2022
Judgment text

This feature is available to zoomLaw Pro members.

Subjects
Data protection Human rights Misuse of private information
Keywords
personal data indirect identification law-enforcement processing necessity and proportionality data-protection principles misuse of private information reasonable expectation of privacy criminal investigation damages for distress
Outcome
claim succeeded in part; damages of £250 and declaration granted
Judicial consideration

This feature is available to zoomLaw Pro members.

Summary

Processing personal data for law-enforcement purposes must be necessary and proportionate. The necessity test is strict and requires a pressing social need. A public authority cannot justify disclosing information about an ongoing criminal investigation to an individual member of the public merely by invoking public confidence.

Information may constitute personal data even where the individual is identified only indirectly, particularly where a small group is involved and the information is clearly focused on a significant event affecting that individual. However, a suspect’s reasonable expectation of privacy may be displaced where the investigation and the relevant charging process have already been widely publicised. Damages for a low-level breach may be modest.

Factual background

The claimant, a senior local politician, brought claims against the Crown Prosecution Service arising from an email sent by a CPS lawyer to a member of the public concerning Operation Sheridan, a long-running criminal investigation. The email stated that a charging file had been referred to the CPS for consideration.

The claimant alleged unlawful processing of personal data, misuse of private information and breach of the Human Rights Act 1998. The CPS sought to withdraw an earlier admission of a data-protection breach and argued that the email contained no personal data, that any processing was lawful, and that the information was already public. The issues included the applicable data-protection regime, whether the email contained personal data, necessity and proportionality, privacy, limitation and remedy.

Held

  1. Data-protection regime. The email, if it involved processing of personal data, was processed for law-enforcement purposes. The applicable regime was therefore Part 3 of the Data Protection Act 2018, rather than the GDPR.
  2. Personal data. The reference to Operation Sheridan indirectly identified the claimant as one of the small number of suspects connected with the charging file. Applying the approach in Durant, Ittihadieh and Aven, the information related to him because it was focused on a significant event affecting his privacy. The fact that his name was absent and that the underlying facts were public did not prevent the information from being personal data.
  3. Lawfulness and necessity. Under sections 35 and 36 of the Data Protection Act 2018, necessity is a strict test requiring proportionality to the gravity of the public-interest threat and, where applicable, a pressing social need. The CPS failed to show any pressing social need to update this particular member of the public, who had no legitimate interest in the investigation. The first and second data-protection principles were breached.
  4. Security. The CPS also failed to prove appropriate organisational measures protecting against unauthorised or unlawful processing. The sixth data-protection principle was therefore breached.
  5. Misuse of private information. The two-stage McKennitt and Bloomberg test applied. Although a suspect ordinarily has a reasonable expectation of privacy in a criminal investigation, the claimant’s expectation concerning the charging decision had been displaced by his public self-identification, extensive reporting, the Fitzgerald litigation and earlier reports that the file had been sent to the CPS for a charging decision. The claim therefore failed at the first stage.
  6. Human rights claim. The claim under the Human Rights Act 1998 was out of time. Since Article 8 was not engaged on the facts, extending time would serve no purpose and was refused.
  7. Remedy. The data-protection claim succeeded. The breach was at the lowest end of the spectrum and caused only modest distress. Damages of £250 were awarded, together with a declaration that the CPS had breached the claimant’s rights under Part 3 of the Data Protection Act 2018.

The court’s approach to earlier authorities

This feature is available to zoomLaw Pro members.

Key cases cited

This feature is available to zoomLaw Pro members.

Cases citing this case

This feature is available to zoomLaw Pro members.