will be required to quote the password whenever they contact the university about you. Enter one upper case character for the box, your password must be at least five characters.” I can set that aspect of the form aside. The claimant did not choose to add a password enabling a third party to access data without giving his consent to a third party accessing data in that way. 27. The claimant argues that the evidence of DC Fell on documentation show that, contrary to the policy which I have quoted from, the university released his data without a written request from the police. Mr Masters on his behalf argues that the claimant is entitled to relief against the university for breach of the Data Protection Act, for breach of contract, for breach of trust and possibly for conspiracy. 28. Mr Knight, who appeared before me for the university, began with an apology. Before Master Yoxall the university had relied on a witness statement from Catherine Yule, dated 18th October 2013. She said that the information disclosed to the police had followed a written request from the police. Mr Knight accepts that that information was incorrect. Ms Yule’s statement, he says, was made in good faith, but it was wrong and Mr Knight apologised on the university’s behalf for providing that wrong information to Master Yoxall. 29. Mr Knight argues though, that this does not lead to the conclusion that the claimant should now be granted the relief which he seeks. Firstly, he submits that the evidence was not new. The security incident report, which I have quoted, was before Master Yoxall and it was apparent from that report that the information had been provided in advance of a written request. Secondly, he argues that in any event it makes no difference if there had been no written request: there would nonetheless be no breach of the Data Protection Act. Thirdly, he argues that there was no loss, because the claimant was arrested at his home address and that home address in Loughborough was provided to the police by the informant. Fourthly, he submits the university’s Data Protection Policy is not a contractual document and there can be no claim for breach of contract because it was not followed, if indeed that was the case. He argues as well that the claim has no basis however it is phrased, even if it is labelled estoppel by representation or breach of trust. 30. In elaboration of his argument that even in the absence of a written request there would be no breach of the Data Protection Act, Mr Knight draws attention to the first Data Protection principle that data must be handled fairly and lawfully. While that is a general principle, the Act itself provides an exemption to that principle, if the data is being processed for the purposes of the prevention or detection of crime or the apprehension or prosecution of offenders - see s.29 of the 1998 Act. Even then the data controller must abide by the obligations in schedule 2. The university says the disclosure in this case plainly conformed to condition 6.1 in schedule 2 since it was necessary for the purposes of legitimate interest pursued by the police and the disclosure was not unwarranted by reason of prejudice to the rights, freedoms or legitimate interest of the data subject. 31. He submits that the university’s policy is a document governing its intended processes. It will ordinarily expect those procedures to be followed, but he adds two important

Select target paragraph3