Header graphic for print
HL Chronicle of Data Protection Privacy & Information Security News & Trends

Tag Archives: Data Protection Act 1998

Posted in Consumer Privacy

What Will be the Impact of the New EU Data Protection Regulation on the UK’s Freedom of Information Act?

Undoubtedly one of the more mind-bending exemptions to apply under the Freedom of Information Act 2000 (FOIA) is the exemption for personal information (s.40) (although sections 30 and 36 are also up there!). This is partly due to s. 40’s close link with the Data Protection Act 1998 (DPA). Not one to hog the limelight, the DPA has typically been cited in past litigation as a secondary or even tertiary issue to the main action when there is a claim for breach of confidence or breach of privacy. This led to a scarcity of judicial rulings on the DPA prior to the FOIA. However, in the Tribunal and higher court decisions flowing from the FOIA, certain aspects of the DPA have frequently been examined when public authorities seek to rely on the s. 40 exemption. Consequently there have been a number of rulings on the scope of personal data and on the ‘legitimate interests’ ground as a legal basis for disclosing such information. These rulings have been based on the DPA which itself implements the EU Data Protection Directive 95/46/EC. But the Directive is due to be replaced by an EU Regulation in the next few years. What will this mean for how the s. 40 exemption under FOIA is interpreted?

Posted in Cybersecurity & Data Breaches, Employment Privacy, International/EU Privacy

UK Council Successfully Appeals ICO Fine Arising from Processor Breach

The UK First Tier Tribunal issued a decision on August 21 finding that the Information Commissioner’s Office (ICO) was wrong to impose a £250,000 fine on Scottish Borders Council in relation to an incident where pension records of former Council employees were discovered overflowing from recycling bins outside a local supermarket. The Tribunal held that the contravention, while serious, was not of a kind likely to cause substantial damage or substantial distress, which is a requirement for imposing such a penalty. The decision may have implications for the ICO’s approach to imposing monetary penalties in the future.

Posted in Employment Privacy, International/EU Privacy

Disclosure of Employment Equality Data “Necessary” Under UK Data Protection Act

A Scottish council has been required to provide data indicating whether it pays traditionally “male” jobs more than traditionally “female” roles, after the Supreme Court rejected its argument that Data Protection legislation prevented disclosure. The case provides clarification on what is meant by the requirement that disclosure, and other forms of data processing, be “necessary” for the purposes of a legitimate interest.