will be required to quote the password whenever they contact the university
about you. Enter one upper case character for the box, your password must be
at least five characters.”
I can set that aspect of the form aside. The claimant did not choose to add a password
enabling a third party to access data without giving his consent to a third party
accessing data in that way.
27.
The claimant argues that the evidence of DC Fell on documentation show that, contrary
to the policy which I have quoted from, the university released his data without a
written request from the police. Mr Masters on his behalf argues that the claimant is
entitled to relief against the university for breach of the Data Protection Act, for breach
of contract, for breach of trust and possibly for conspiracy.
28.
Mr Knight, who appeared before me for the university, began with an apology. Before
Master Yoxall the university had relied on a witness statement from Catherine Yule,
dated 18th October 2013. She said that the information disclosed to the police had
followed a written request from the police. Mr Knight accepts that that information
was incorrect. Ms Yule’s statement, he says, was made in good faith, but it was wrong
and Mr Knight apologised on the university’s behalf for providing that wrong
information to Master Yoxall.
29.
Mr Knight argues though, that this does not lead to the conclusion that the claimant
should now be granted the relief which he seeks. Firstly, he submits that the evidence
was not new. The security incident report, which I have quoted, was before Master
Yoxall and it was apparent from that report that the information had been provided in
advance of a written request. Secondly, he argues that in any event it makes no
difference if there had been no written request: there would nonetheless be no breach of
the Data Protection Act. Thirdly, he argues that there was no loss, because the
claimant was arrested at his home address and that home address in Loughborough was
provided to the police by the informant. Fourthly, he submits the university’s Data
Protection Policy is not a contractual document and there can be no claim for breach of
contract because it was not followed, if indeed that was the case. He argues as well
that the claim has no basis however it is phrased, even if it is labelled estoppel by
representation or breach of trust.
30.
In elaboration of his argument that even in the absence of a written request there would
be no breach of the Data Protection Act, Mr Knight draws attention to the first Data
Protection principle that data must be handled fairly and lawfully. While that is a
general principle, the Act itself provides an exemption to that principle, if the data is
being processed for the purposes of the prevention or detection of crime or the
apprehension or prosecution of offenders - see s.29 of the 1998 Act. Even then the data
controller must abide by the obligations in schedule 2. The university says the
disclosure in this case plainly conformed to condition 6.1 in schedule 2 since it was
necessary for the purposes of legitimate interest pursued by the police and the
disclosure was not unwarranted by reason of prejudice to the rights, freedoms or
legitimate interest of the data subject.
31.
He submits that the university’s policy is a document governing its intended processes.
It will ordinarily expect those procedures to be followed, but he adds two important