03/02/2020
Privacy International v Secretary of State for Foreign And Commonwealth Affairs & Ors (Rev 2) [2016] UKIPTrib 15_110-CH (17 October 2016)
s94 itself clearly extended to requiring [PSENs] to provide BCD in the
interests of national security; and
(b) although the use by the SIA of Bulk Personal Datasets had not been
avowed, the acquisition of personal data in bulk was foreseeable because (i)
the Respondents' powers to obtain information clearly extend to obtaining
personal data; (ii) the acquisition of large volumes of such personal
information was also foreseeable, albeit subject to statutory requirements of
necessity and proportionality; and (iii) the inclusion within such bulk
personal data of information relating to individuals who were unlikely to be
of intelligence interest (which would include, for instance, a telephone
directory or electoral roll) was also foreseeable, again subject to the
requirement that any acquisition of such data was necessary and
proportionate; and
(c) in both cases, the use of BCD/BPD was foreseeable "even if the precise
form of it and the existence of its use was not admitted."
70. The situation here in our judgment is however quite distinct. In that case there was a Property Code.
In this case there were, at the relevant times, no Codes of Practice relating to either BCD or BPD, or
anything approximating to them. Interception, even bulk interception, by warrant was sufficiently
known about, but this is a long way from BCD or BPD. At least in the case of BPD, concern was
expressed, emanating from the SIAs themselves, in the Respondents' own documents now disclosed
during the course of these proceedings, as to the absence of knowledge on the part of the public about
it:
(i) In a Review of Agency Handling of Bulk Personal Data dated February 2010 by a Mr
Hannigan, then of the Cabinet Office, he wrote
(a) at paragraph 6.2: "It is difficult to assess the extent to which the public is
aware of agencies' holding and exploiting in-house personal bulk datasets,
including data on individuals of no intelligence interest." and
(b) at paragraph 36: "Although existing legislation allows companies and UK
Government Departments to share personal data with the agencies if
necessary in the interests of national security, the extent to which this sharing
takes place may not be evident to the public."
(ii) In the (then unpublished, but now disclosed) MI5 Policy for Bulk Data Acquisition,
Sharing, Retention & Deletion issued on 19 October 2010 it was stated: "The fact that the
Service holds bulk financial, albeit anonymised, data is assessed to be a HIGH corporate
risk, since there is no public expectation that the Service will hold or have access to this
data in bulk. Were it to become widely known that the Service held this data, the media
response would most likely be unfavourable and probably inaccurate."
In any event it seems difficult to conclude that the use of BCD was foreseeable by the public, when it
was not explained to Parliament; and several opportunities arose when legislation or Codes of Practice
were being introduced or amended (and particularly in 2000 when s.80 of RIPA was passed), when the
government of the day did not avow the use of s.94.
71. The Respondents attached helpful Appendices to their Skeleton Argument, setting out, by reference to
the disclosed evidence (some of it redacted), the detailed rules and arrangements which related to BCD
(GCHQ and MI5) and BPD (all three SIAs) during the period since at least 2010. However, none of
those rules or arrangements were previously disclosed or signposted, prior to the publication of the
Handling Arrangements in November 2015.
Supervision/Oversight
www.bailii.org/cgi-bin/format.cgi?doc=/uk/cases/UKIPTrib/2016/15_110-CH.html&query=([2016])+AND+(UKIPTrib)+AND+(15_110-CH)
22/53