03/02/2020 Privacy International v Secretary of State for Foreign And Commonwealth Affairs & Ors (Rev 2) [2016] UKIPTrib 15_110-CH (17 October 2016) s94 itself clearly extended to requiring  [PSENs] to provide BCD in the interests of national  security; and (b) although the use by the SIA of Bulk Personal  Datasets had not been avowed, the acquisition of  personal data in bulk was foreseeable because (i) the  Respondents' powers to obtain information clearly extend  to obtaining personal data; (ii) the acquisition of  large volumes of such personal information was also  foreseeable, albeit subject to statutory requirements of  necessity and proportionality; and (iii) the inclusion  within such bulk personal data of information relating  to individuals who were unlikely to be of intelligence  interest (which would include, for instance, a telephone  directory or electoral roll) was also foreseeable, again  subject to the requirement that any acquisition of such  data was necessary and proportionate; and (c) in both cases, the use of BCD/BPD was  foreseeable "even if the precise form of it and the  existence of its use was not admitted." 70. The situation here in our judgment is however quite distinct.  In that case there was a Property Code.  In this case there were, at the relevant times, no Codes of Practice relating to either BCD or BPD, or anything approximating to them.  Interception, even bulk interception, by warrant was sufficiently known about, but this is a long way from BCD or BPD.  At least in the case of BPD, concern was expressed, emanating from the SIAs themselves, in the Respondents' own documents now disclosed during the course of these proceedings, as to the absence of knowledge on the part of the public about it: (i) In a Review of Agency Handling of Bulk Personal Data dated February 2010 by a Mr Hannigan, then of the Cabinet Office, he wrote (a) at paragraph 6.2: "It is difficult to assess the  extent to which the public is aware of agencies' holding  and exploiting in-house personal bulk datasets,  including data on individuals of no intelligence  interest." and (b)  at paragraph 36: "Although existing legislation allows companies and UK Government Departments to share personal data with the agencies if necessary in the interests of national security, the extent to which this sharing takes place may not be evident to the public."  (ii) In the (then unpublished, but now disclosed) MI5 Policy for Bulk Data Acquisition, Sharing, Retention & Deletion issued on 19 October 2010 it was stated: "The fact that the Service holds bulk financial, albeit anonymised, data is assessed to be a HIGH corporate risk, since there is no public expectation that the Service will hold or have access to this data in bulk.  Were it to become widely known that the Service held this data, the media response would most likely be unfavourable and probably inaccurate." In any event it seems difficult to conclude that the use of BCD was foreseeable by the public, when it was not explained to Parliament; and several opportunities arose when legislation or Codes of Practice were being introduced or amended (and particularly in 2000 when s.80 of RIPA was passed), when the government of the day did not avow the use of s.94. 71. The Respondents attached helpful Appendices to their Skeleton Argument, setting  out, by reference to the disclosed evidence (some of it redacted), the detailed rules and arrangements which related to BCD (GCHQ  and MI5) and BPD (all three SIAs) during the period since at least 2010. However, none of those rules or arrangements were previously disclosed or signposted, prior to the publication of the Handling Arrangements in November 2015. Supervision/Oversight www.bailii.org/cgi-bin/format.cgi?doc=/uk/cases/UKIPTrib/2016/15_110-CH.html&query=([2016])+AND+(UKIPTrib)+AND+(15_110-CH) 22/53

اختر الفقرة المستهدفة3