Information Law & Governance 11 November 2014 Key contacts: Simon Charlton / Associate 0121 200 8118

Slides:



Advertisements
Similar presentations
Lifecycle of a Freedom of Information (FOI) request – corporate or business information.
Advertisements

The Legislative Position in Scotland Environmental Information (Scotland) Regulations 2004 SSI 2004 No.520 Professor Colin Reid, School of Law, University.
IMPS Information Management and Policy Services Information Services Directorate A briefing for all University staff November 2004 New Information Legislation.
In confidence Chair: Storm Westmaas Principal Legal Adviser, the Standards Board for England Speakers: Bernadette Livesey Chief Law and Administration.
Freedom of Information Act 2000 and the PCT Audit Procedure Background: The Act was passed in November The Act will be fully in force by January.
The Data Protection Act - an absolute right to ask but a qualified right to receive Maureen H Falconer Senior Policy Officer, ICO CELCIS, Scottish University.
INTRODUCTION TO PUBLIC DISCLOSURE RESPONSE Paula Adams, King County Public Disclosure Officer.
Overview of FOI legislation FOI and HE researchers Margaret Keyse Head of Enforcement.
“It’s public knowledge” Freedom of information law in Scotland Presentation to the Scottish Civil Justice Council Susan Gray 10 June 2013.
Freedom of Information What does it mean for us? Introductory Training Session.
1 NSW Work Health & Safety Act Session 3 WHS Act.
Freedom of Information 1 Freedom of Information - overview FOI Unit (December 2011)
Role of the Information Commissioner’s Office 'Promoting public access to official information and protecting your personal information' Christine Johnson.
The UK Freedom of Information Act – A Practical Guide for Academic Researchers Cambridge Wednesday, 16 February 2011.
Transparency in Public Administration – FOI and EIR
Information Governance in Commissioning Mental Health Commissioners Collaborative.
Towards a Freedom of Information Law in Qatar Fahad bin Mohammed Al Attiya Executive Chairman, Qatar National Food Security Programme.
Freedom of Information – a brief guide David Evans.
Information Commissioner’s Office: data protection Judith Jones Senior Policy Officer Strategic Liaison – public security 16 November 2011.
1 WHY IS WHISTLEBLOWING IMPORTANT AND ON WHAT PRINCIPLES SHOULD PROTECTIVE LEGISLATION BE BASED? David Lewis, Professor of Employment Law, MiddlesexUniversity,
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
An overview of the Data Protection Act Legal framework The Data Protection Act 1998 came into force in March 2001, replacing the Data Protection.
The ICO and the DPA Ken Macdonald Assistant Commissioner Information Commissioner’s Office ScotStat Public Sector Analysts Network 30 th September 2010.
How the Information Commissioner’s office operates as a regulator David Smith Deputy Information Commissioner.
1 OVERVIEW PRESENTATION FREEDOM OF INFORMATION (SCOTLAND) ACT 2002.
Exemptions and the Public Interest Test Louise Townsend - Masons.
Freedom of Information Act Update 15 th November 2006 Damien Welfare, 2-3 GIS.
The Information Commissioner’s Office David Evans.
Freedom of Information KILO Induction Day. By the end of the day, you should know… What is the Freedom Of Information Act and how it should be used. Our.
Regulation of Personal Information Daniel Pettitt, Leon Sewell and Matthew Pallot.
ICO: Alternative Access Regimes– Overview of FOIA/DPA/EIRs Catherine Vint ICO NI.
SROC Conference Data Sharing – The New Culture? Elaine Fletcher, Senior Associate, Eversheds LLP April 2008.
Training for Grantham Institute staff 29 th November 2013.
1 Freedom of Information (Scotland) Act 2002 A strategic view.
Managing complex and challenging requests Margaret Keyse Paul Mutch 21 May 2014.
Public rights of access to information Grisilda Ponniah, Corporate Information Governance Manager Mary Elliott, FOI Officer Legal & Democratic Services.
HAIAF FOI – To what extent does it apply to RSLs? Thursday 1 July.
The FPP Test What you (or your students) need to know Flight Training Division Presentation AIA Aviation Week Conference July 2011.
Data Protection Act & Freedom of Information Simon Mansell Corporate Governance and Information Team.
DIRECT WORKS FORUM 10 June 2008 Andy Ballard. COMMON LAW MANSLAUGHTER Effectively – Death by gross negligence Test – (a) was a (common law) duty of care.
OPEN UP! Introduction to handling Freedom of Information requests.
Local Government Reform and Compliance with the DPA Ken Macdonald Assistant Commissioner (Scotland & Northern Ireland) Information Commissioner’s Office.
Overview of FOI in HM Treasury Technical aspects of the FOI Act Tips and best practice 2.
OPEN GOVERNMENT: IMPLICATIONS FOR INVESTIGATORS Elizabeth Tydd Information and Privacy Commission CEO NSW Information Commissioner November 2014.
Internal Review under the Freedom of Information Law 2007 Carole Excell, FOI Coordinator.
IM NETWORK MEETING 20 TH JULY, 2010 CONSULTATION WITH 3 RD PARTIES.
Session 7 Compliance failure policy. 1 Contents Part 1: COLP and COFA duties Part 2: What do we have to comply with and why does it matter? Part 3: Compliance.
Introduction to the Cayman Islands FOI Bill 2007 Carole Excell FOI Coordinator.
Data protection and compliance in context 19 November 2007 Stewart Room Partner.
July 051 LIABILITY ISSUES FOR COAL MINE SURVEYORS Australian Institute of Mine Surveyors Seminar Catherine Bolger Association of Professional Engineers,
An Introduction to the Privacy Act Privacy Act 1993 Promotes and protects individual privacy Is concerned with the privacy of information about people.
The Law Society and You. The Role of the L.S.U.C. Regulates, governs and licenses Ontario’s lawyers and licensed paralegals pursuant to the Law Society.
FREEDOM OF INFORMATION Getting to grips with the Act.
© University of Reading Lee Shailer 06 June 2016 Data Protection the basics.
Workshop Understanding your responsibilities under the Data Protection Act 1998 and the Freedom of Information Act 2000 Adele Rhodes Girling.
Sharing Personal Data ‘What you need to know’ Corporate Information Governance Team Strategic Intelligence.
“The right to know” Scottish Borders Council 27 March 2013 Rosemary Agnew Scottish Information Commissioner And Sarah Hutchison Head of Policy and Information.
Taking Regulatory Action: The Logic Behind our Decisions Maureen H Falconer Senior Policy Officer Scottish Local Authority Computer Audit Group November.
Freedom of Information Act ‘What you need to know’ Corporate Information Governance Team Strategic Intelligence.
Freedom of Information Requests. Information Management Framework Access to Information Access to Information Environmental Information Regulations 2004.
Data Protection and Freedom of Information. Objectives Describe the main points of the Data Protection Act 1998 and Freedom of Information Act 2000 Illustrate.
1 Office of the Information Commissioner of Canada September 28, 2010 Balancing Openness and the Public Interest In Protecting Information Vanessa R. Brinkmann.
The FPP Test What you need to know Commercial Transport/Tourist Flight Operators Presentation AIA Aviation Week Conference July 2011.
Records management for the public sector 8 September 2016 Judith Jones - Group Manager Sue Markey - Senior Policy Officer Government and Society.
Data protection issues in regulatory investigations
Data Protection principles
The ICO: New Powers and Penalties
The Freedom of Information and Data Protection Legislation An Overview
DATA PROTECTION: LEGAL CONSEQUENCES OF A FAILURE TO COMPLY
Data protection & FOIA considerations
Presentation transcript:

Information Law & Governance 11 November 2014 Key contacts: Simon Charlton / Associate Emma Emery/Partner

Contents Decision Notices and Case Law update FOIA/DPA update Enforcement Actions by the ICO including a case study on Niebel v Information Commissioner Overview of the Information Rights Tribunal procedure

Human Rights Act 1998 Direct Result: Data Protection Act 1998 – governs the storage of and the access by individuals to personal information about themselves held by any body (private or public). Protects personal data. Freedom Information Act 2000 – allows individuals access to information held by Public Authorities of “recorded” non personal information. NB: Access is to information, not necessarily to documents.

Freedom of Information Act – Public Authorities’ Obligations Adopt and maintain a “publication scheme”. Respond to requests for information under the Freedom Information Act Obligation to respond within 20 working days. Presumption is for disclosure – cultural change.

Data Protection Act 1998 An individual is a data subject. Records relating to LIVING PERSONS. Came into force – 1 March Disclose within 40 calendar days. Strengthens and extends data protection regime created by Data Protection Act 1984.

Freedom of Information Act 2000 Requests for Information Can be made by:- Any person – corporate or unincorporated body. Could be foreign applications via UK agents. For data held by or on behalf of the Public Authority. Request must be in writing (no statutory application form). Must provide name and address of correspondent ? ( ?).

Requests for Information Must describe information required. Must pay a fee. Respondent Authority duty bound to provide reasonable advice and assistance. Authorities ( subject to exceptions) have to: (i)State whether they hold such information. (ii)Communicate actual information.

Requests for Information Satisfy request within 20 working days once fee is paid unless there is a need to consider public interest. If so estimate of time for disclosure should be given to applicant. Hence need for early decision making. Breach of 20 working days common ground for criticism and sanctions from ICO. Need process to deal with complicated requests. Staff equipped to recognise exemptions. Staff equipped to consider public interest test.

FOIA Exemptions Absolute – do not require the test of prejudice or the balance of public interest to be in the favour of non disclosure. Section 36 – Prejudice to effective conduct of public affairs (relating to information held by Parliament). Section 40 – Personal Information (disclosure may contravene DPA 1998). Section 41 – Information provided in confidence. Section 44 – Prohibitions on disclosure.

FOIA Exemptions Qualified – public interest test to be applied to decide whether exemption should be applied or not. Section 36 – Prejudice to effective conduct of public affairs (excepting Parliament). Section 37 – Communications with Her Majesty etc., and Honours. Section 38 – Health and Safety. Section 39 – Environmental Information. Section 42 – Legal Professional privilege. Section 43 – Commercial interests.

FOIA-Public Interest Test Does the public interest in withholding information outweigh the public interest in releasing it? If information is exempt this does not mean the whole document will be withheld.

Section 40(2) Personal Data Halton Borough Council, ICO Decision Notice ref FS April 2014 Governing Body of Reading School v (1) Information Commissioner (2) James Coombs EA/2013/0227, 15 April 2014 Jonathan Corke v Information Commissioner EA/2014/ June 2014

Recent Cases Edem v Information Commissioner – Court of Appeal [2014] EWCA Civ 92. Surrey Heath Borough Council v (1)Information Commissioner (2) Morley [2014] UKUT 0339 (AAC) Farrand v (1)Information Commissioner (2) London Fire & Emergency Planning Authority [2014] UKUT 0310 (AAC)

FOI/EIR and Vexatious Requests Section 14 of the Freedom of Information Act 2000 –Section 1(1) does not oblige a public authority to comply with a request for information if the request is vexatious Regulation 12 (4) (b) of the Environmental Information Regulations 2004 –…a public authority may refuse to disclose information … to the extent that the request for the information is manifestly unreasonable.”

Case Law Upper Tribunal considered what constitutes a vexatious request in Information Commissioner v Devon CC and Dransfield [2012] UKUT 440 (AAC) Judge Nicholas Wikeley described section 14 as a “get out of jail free card” for public authorities Key factors –the burden (on the public authority and its staff) –the motive (of the requester) –the value or serious purpose (of the request); and –any harassment or distress (of and to staff).

ICO Guidance Revised guidance issued in May 2013 Authorities should address the four themes. “Significant burden” becomes one factor rather than a first test. Well reasoned evidence is needed. Authorities should engage with applicants to help them understand why they consider a request to be vexatious.

EIR ICO Guidance on dealing with “manifestly unreasonable requests” issued in March 2013 may relate to the request being vexatious or the cost of compliance being too great “there is no material difference between a request that us vexatious under section 14(1) of FOIA and a request that is manifestly unreasonable on vexatious grounds under the EIR” “the exception is subject to the public interest test. In practice however, many of the issues relevant to the public interest test will already have been considered when deciding if the exception is engaged.

Cases since Dransfield Cain v Information Commissioner (EA/2012/0226) Sivier v Information Commissioner (EA/2013/0277) Department of Education v (1) ICO (2) L.McInerney (EA/2013/0270) NS Chadha v IC EA/2013/260

Section 3 (2) Information held by public authority Hackett v (1) IC (2) United Learning Trust EA/2012/265 Sandwell MBC FS Innes v (1) IC (2) Buckinghamshire County Council 2014 EWCA Civ 1086

Section 43 Prejudice to Commercial Interests Hugh Mills v IC EA/2013/ May 2014

Publications/Guidance Local Government Transparency Code ICO Audit of 16 Local Authorities ICO Publication : Definition Documents & Templates Guides for Model Publication Schemes ICO Publication: CCTV Code of Practice

News Privacy by Design Beacon Technology

Information Law and Governance Enforcement action by the ICO

Enforcement action by the ICO Information Notice (section 43 DPA) –Grounds –Content –Failure to comply –Defence –Privilege and self incrimination

Enforcement action by the ICO Enforcement Notice (section 40 DPA) –Grounds –Content –Failure to comply, defence –Recent cases: Wolverhampton City Council 15 May 2014 Glasgow City Council 4 June 2013

Enforcement action by the ICO Assessment Notice (sections 41A – C DPA) –Audit –Grounds –Content –Code of Practice –Failure to comply – Schedule 9 –Undertakings

Enforcement action by the ICO Monetary Penalty Notice (section 55 DPA) –Very high threshold Deliberate Knew or ought to have known Significant damage or distress –Maximum penalty £500,000 –Notice of intent and representations

Enforcement action by the ICO Monetary Penalty Notice (section 55 DPA) –Aggravating and mitigating circumstances Effect of contravention Behavioural issues Impact on Data Controller –Right of Appeal –Enforcement –Guidance

Enforcement action by the ICO Monetary Penalty Notice (section 55 DPA) –Recent cases Ministry of Justice August £100,000 Department of Justice Northern Ireland Jan £185,000

Enforcement action by the ICO Criminal Prosecution –Failure to notify (ss 17(1), 21(1)) –Failure to notify of changes (ss 20(1), 21(2) and (3) Jayesh Shah –Unlawful obtaining of personal data (s55) Dalvinder Singh –Penalties

Case Study: Niebel v Information Commissioner Appeal against MPN Breach of PECR but appeal against section 55A not PECR breach Central London Community Healthcare NHS Trust –Failed to properly exercise discretion –Self reported so barred –Unlawful not to extend discount period –Amount unsustainably high

Case Study: Niebel v Information Commissioner Notice and representations Grounds for challenge –Serious contravention –of a kind likely to cause significant damage and significant distress –Deliberate –Knew or ought to have known Serious contravention would occur Likely to cause significant damage or distress

Case Study: Niebel v Information Commissioner Request for particulars/statement of the contravention Evidence Tactics

Information Tribunal Procedure