|
|
Preface |
|
vii | |
|
|
xvii | |
United Kingdom |
|
xvii | |
CJEU and ECtHR |
|
lxx | |
United States of America |
|
lxxx | |
Australia |
|
lxxxv | |
Canada |
|
xc | |
New Zealand |
|
xciii | |
Republic of Ireland |
|
xciii | |
|
|
xciii | |
Glossary |
|
cxxxv | |
|
|
|
|
|
1 Overview of information rights |
|
|
2 | (4) |
|
|
6 | (3) |
|
3 The rationale for official information access legislation |
|
|
9 | (8) |
|
Chapter 2 Westminster legislation |
|
|
|
1 Background to freedom of information legislation |
|
|
17 | (2) |
|
2 The open government code of practice |
|
|
19 | (4) |
|
3 Enactment of the Freedom of Information Act 2000 |
|
|
23 | (3) |
|
4 Developments since 1 January 2005 |
|
|
26 | (10) |
|
Chapter 3 Scottish legislation James Findlay QC |
|
|
|
Chapter 4 The influence of the European Convention on Human Rights etc |
|
|
|
|
1 The ECHR and information rights |
|
|
36 | (3) |
|
2 Article 8: Accessing information |
|
|
39 | (3) |
|
3 Article 8: Personal information |
|
|
42 | (3) |
|
4 Article 10: Accessing information |
|
|
45 | (7) |
|
|
52 | (2) |
|
6 International instruments |
|
|
54 | (2) |
|
|
56 | (5) |
|
Chapter 5 Exemptions: general principles |
|
|
|
|
|
|
61 | (3) |
|
2 The duty to confirm or deny |
|
|
64 | (3) |
|
3 The discretion to maintain an exemption |
|
|
67 | (4) |
|
4 Classification of exemptions |
|
|
71 | (8) |
|
5 Interpretation of exemptions and onus |
|
|
79 | (8) |
|
6 Conclusive certificates |
|
|
87 | (18) |
|
Chapter 6 Prejudice and the public interest |
|
|
|
|
|
105 | (6) |
|
2 Weighing the public interest: disclosure |
|
|
111 | (7) |
|
3 Weighing the public interest: confirmation and denial |
|
|
118 | (1) |
|
4 Ascertaining and weighing prejudice |
|
|
119 | (9) |
|
|
|
Chapter 7 Data protection: introduction |
|
|
|
|
1 Origins of data protection law |
|
|
128 | (6) |
|
2 Directive 95/46/EC & DPA 1998 regime |
|
|
134 | (10) |
|
3 GDPR, Directive 2016/680 & DPA 2018 regime |
|
|
144 | (3) |
|
4 Interpretational principles |
|
|
147 | (4) |
|
|
151 | (7) |
|
Chapter 8 GDPR and DPA 2018: introduction |
|
|
|
|
158 | (7) |
|
|
165 | (17) |
|
|
182 | (6) |
|
Chapter 9 General processing: continuing obligations |
|
|
|
|
188 | (5) |
|
2 Lawfully, fairly and transparently |
|
|
193 | (15) |
|
|
208 | (2) |
|
|
210 | (1) |
|
|
210 | (1) |
|
|
211 | (1) |
|
|
212 | (4) |
|
8 Sensitive personal data |
|
|
216 | (11) |
|
9 Organisational obligations |
|
|
227 | (8) |
|
10 International transfers |
|
|
235 | (5) |
|
Chapter 10 General processing: data subject rights |
|
|
|
|
240 | (6) |
|
|
246 | (2) |
|
|
248 | (2) |
|
|
250 | (4) |
|
5 Right to restrict processing |
|
|
254 | (4) |
|
6 Right to data portability |
|
|
258 | (2) |
|
|
260 | (2) |
|
8 Right against automated decisions |
|
|
262 | (2) |
|
9 Ancillary rights and obligations |
|
|
264 | (2) |
|
Chapter 11 General processing: exemptions etc |
|
|
|
|
266 | (6) |
|
2 Groups of disapplied provisions |
|
|
272 | (7) |
|
3 Purpose-based exemptions |
|
|
279 | (7) |
|
|
286 | (4) |
|
|
290 | (3) |
|
Chapter 12 Law enforcement processing: continuing obligations |
|
|
|
|
|
|
293 | (7) |
|
|
300 | (5) |
|
3 Specific, explicit & legitimate purpose |
|
|
305 | (1) |
|
4 Adequate, relevant and not excessive |
|
|
306 | (1) |
|
5 Accurate and up-to-date |
|
|
307 | (2) |
|
|
309 | (1) |
|
|
309 | (1) |
|
8 Organisational obligations |
|
|
310 | (10) |
|
9 International transfers |
|
|
320 | (6) |
|
10 Enforcement and remedies |
|
|
326 | (2) |
|
Chapter 13 Law enforcement processing: data subject rights |
|
|
|
|
|
|
328 | (8) |
|
|
336 | (2) |
|
|
338 | (3) |
|
|
341 | (1) |
|
5 Right to restrict processing |
|
|
342 | (2) |
|
6 Right against automated decisions |
|
|
344 | (2) |
|
7 Enforcement and remedies |
|
|
346 | (3) |
|
Chapter 14 Intelligence services processing |
|
|
|
|
|
|
349 | (3) |
|
2 The continuing obligations |
|
|
352 | (8) |
|
3 Data subject access right |
|
|
360 | (3) |
|
4 Other data subject rights |
|
|
363 | (3) |
|
|
366 | (7) |
|
Chapter 15 DPA 1998: concepts, rights and duties |
|
|
|
|
|
373 | (4) |
|
2 The regulated matter: personal data |
|
|
377 | (12) |
|
3 The regulated activity: processing |
|
|
389 | (1) |
|
4 The regulated person: the data controller |
|
|
390 | (2) |
|
5 The required standard: the data protection principles |
|
|
392 | (1) |
|
6 The automous duty: compliance with the principles |
|
|
392 | (14) |
|
7 The notice-based rights and resultant duties |
|
|
406 | (14) |
|
Chapter 16 DPA 1998: exemptions |
|
|
|
|
|
420 | (1) |
|
|
421 | (16) |
|
|
437 | (7) |
|
Part III Environmental information |
|
|
|
Chapter 17 Environmental information introduction |
|
|
|
|
|
|
444 | (7) |
|
2 Environmental information |
|
|
451 | (10) |
|
Chapter 18 Environmental information - rights & appeals |
|
|
|
|
|
1 The right to environmental information |
|
|
461 | (11) |
|
|
472 | (5) |
|
3 Commissioners, appeals, enforcement etc |
|
|
477 | (6) |
|
Chapter 19 Environmental information - exceptions |
|
|
|
|
|
|
483 | (6) |
|
|
489 | (19) |
|
Part IV Freedom of information |
|
|
|
Chapter 20 The right to information |
|
|
|
|
1 The nature of information |
|
|
508 | (7) |
|
2 The holding requirement |
|
|
515 | (5) |
|
|
520 | (2) |
|
4 Bodies subject to Freedom of Information Act |
|
|
522 | (10) |
|
5 Bodies subject to Freedom of Information (Scotland) Act |
|
|
532 | (3) |
|
6 Constraints on disclosure |
|
|
535 | (1) |
|
7 Discretionary disclosure of information |
|
|
536 | (4) |
|
Chapter 21 The duty to advise and assist, codes of practice and publication schemes |
|
|
|
|
1 The duty to advise and assist |
|
|
540 | (5) |
|
|
545 | (4) |
|
|
549 | (4) |
|
|
553 | (2) |
|
|
|
|
1 The request for information |
|
|
555 | (4) |
|
2 Particularising the request |
|
|
559 | (1) |
|
|
560 | (3) |
|
|
563 | (5) |
|
5 Transferring requests for information |
|
|
568 | (1) |
|
6 Failure to locate information |
|
|
569 | (1) |
|
7 Consultation with third parties |
|
|
570 | (6) |
|
Chapter 23 Disentitlement |
|
|
|
|
1 Excessive cost of compliance |
|
|
576 | (7) |
|
|
583 | (3) |
|
|
586 | (2) |
|
|
|
|
|
588 | (2) |
|
2 Non-substantive responses |
|
|
590 | (2) |
|
|
592 | (5) |
|
4 Communication of information |
|
|
597 | (7) |
|
|
|
Chapter 25 Information otherwise accessible |
|
|
|
|
1 Information otherwise accessible |
|
|
604 | (4) |
|
2 Information intended for future publication |
|
|
608 | (3) |
|
3 Environmental information |
|
|
611 | (4) |
|
Chapter 26 Security bodies, national security and defence |
|
|
|
|
|
615 | (10) |
|
|
625 | (37) |
|
3 Information supplied by, or relating to, the security bodies |
|
|
662 | (5) |
|
4 Information whose exemption is required for national security purposes |
|
|
667 | (14) |
|
5 National security certificates and the operation of the related exemptions |
|
|
681 | (11) |
|
6 Information prejudicial to defence or the armed forces |
|
|
692 | (8) |
|
Chapter 27 International and internal relations |
|
|
|
|
1 International relations |
|
|
700 | (13) |
|
|
713 | (5) |
|
Chapter 28 Economic and financial interests Economic and financial interests |
|
|
718 | (7) |
|
Chapter 29 Investigation, audit, law enforcement and the courts |
|
|
|
|
|
725 | (2) |
|
2 Information held for purposes of criminal investigations or proceedings |
|
|
727 | (4) |
|
3 Information relating to the obtaining of information from confidential sources |
|
|
731 | (2) |
|
4 Information whose disclosure might prejudice the enforcement of criminal law |
|
|
733 | (3) |
|
|
736 | (2) |
|
6 Other investigatory and regulatory functions |
|
|
738 | (4) |
|
|
742 | (3) |
|
|
745 | (3) |
|
|
|
|
|
1 Parliamentary privilege |
|
|
748 | (9) |
|
2 Legal professional privilege |
|
|
757 | (13) |
|
Chapter 31 Policy formulation and public affairs |
|
|
|
|
|
770 | (6) |
|
2 Information relating to the formulation of government policy, etc |
|
|
776 | (18) |
|
3 Information the disclosure of which would be prejudicial to public affairs |
|
|
794 | (11) |
|
Chapter 32 Research, health and safety |
|
|
|
|
805 | (1) |
|
|
806 | (2) |
|
|
808 | (8) |
|
Chapter 33 Personal information |
|
|
|
|
|
816 | (5) |
|
2 Applicant is the data subject |
|
|
821 | (1) |
|
3 Applicant is not the data subject |
|
|
822 | (12) |
|
4 Pre-25 May 2018 approach |
|
|
834 | (4) |
|
Chapter 34 Commercial and other confidentiality |
|
|
|
|
1 Breach of confidence: introduction |
|
|
838 | (6) |
|
2 Conventional breach of confidence |
|
|
844 | (14) |
|
3 Privacy and breach of confidence |
|
|
858 | (16) |
|
|
874 | (5) |
|
5 Prejudice to commercial interests |
|
|
879 | (4) |
|
6 International confidences |
|
|
883 | (3) |
|
7 Environmental information and confidentiality |
|
|
886 | (4) |
|
Chapter 35 Miscellaneous exemptions |
|
|
|
|
|
|
1 Communications with Her Majesty, etc |
|
|
890 | (7) |
|
|
897 | (6) |
|
3 Prohibitions on disclosure |
|
|
903 | (2) |
|
4 Prohibitions by or under enactment |
|
|
905 | (6) |
|
5 Incompatibility with EU obligations |
|
|
911 | (1) |
|
|
912 | (6) |
|
Part VI Other rights to information |
|
|
|
Chapter 36 Historical records and public records |
|
|
|
|
918 | (5) |
|
2 FOIA and historical records: exemptions |
|
|
923 | (4) |
|
3 FOIA and historical records: decision-making |
|
|
927 | (6) |
|
|
933 | (4) |
|
5 The preservation of public records |
|
|
937 | (10) |
|
Chapter 37 Local government documents |
|
|
|
1 Local government information |
|
|
947 | (3) |
|
2 Common law rights of elected representatives |
|
|
950 | (5) |
|
3 Rights under Part Va of the Local Government Act 1972 |
|
|
955 | (13) |
|
4 Rights in relation to executive decisions |
|
|
968 | (6) |
|
5 Other rights to non-register information |
|
|
974 | (7) |
|
6 Register information: non-personal matters |
|
|
981 | (7) |
|
7 Register information: personal information |
|
|
988 | (4) |
|
Chapter 38 Medical records |
|
|
|
1 Health, medical and care records |
|
|
992 | (4) |
|
Chapter 39 Business and financial information |
|
|
|
1 Economic and business information |
|
|
996 | (5) |
|
Chapter 40 Educational information |
|
|
|
1 Educational information |
|
|
1001 | (7) |
|
Chapter 41 Common law rights and controls |
|
|
|
|
|
1008 | (9) |
|
|
1017 | (7) |
|
Chapter 42 Court-held documents |
|
|
|
|
|
1024 | (6) |
|
|
1030 | (4) |
|
3 Courts subject to the CPR |
|
|
1034 | (7) |
|
|
1041 | (2) |
|
|
1043 | (3) |
|
|
1046 | (2) |
|
7 Tribunals, inquiries etc |
|
|
1048 | (6) |
|
Chapter 43 Information held by EU bodies |
|
|
|
|
|
1054 | (6) |
|
2 The code of practice and Decisions 93/731 and 94/90 |
|
|
1060 | (3) |
|
|
1063 | (23) |
|
Part VII Appeals, remedies and enforcement |
|
|
|
Chapter 44 The Information Commissioner and the tribunals |
|
|
|
|
1 The functions of the Information Commissioner |
|
|
1086 | (5) |
|
2 The FTT and the Upper Tribunal |
|
|
1091 | (11) |
|
Chapter 45 FOIA and EIR appeals |
|
|
|
|
1 First stage: internal review |
|
|
1102 | (2) |
|
2 Second stage: application to the Information Commissioner |
|
|
1104 | (5) |
|
3 Third stage: appeals and the First-Tier Tribunal |
|
|
1109 | (6) |
|
4 Fourth stage: appeals to the Upper Tribunal |
|
|
1115 | (7) |
|
5 Fifth stage: appeal from Upper Tribunal to Court of Appeal |
|
|
1122 | (1) |
|
|
1123 | (2) |
|
7 Third parties: institution of appeals and participation in appeals |
|
|
1125 | (2) |
|
Chapter 46 The Scottish Information Commission and FOI(S)A etc appeals |
|
|
|
|
1 The Scottish Information Commissioner |
|
|
1127 | (3) |
|
|
1130 | (8) |
|
Chapter 47 Freedom of information: regulatory enforcement |
|
|
|
|
|
|
1138 | (4) |
|
|
1142 | (4) |
|
Chapter 48 GDPR and DPA 2018: private remedies and regulatory enforcement |
|
|
|
|
1146 | (3) |
|
|
1149 | (6) |
|
|
1155 | (28) |
|
4 Special purposes processing |
|
|
1183 | (3) |
|
5 National security certificate appeals |
|
|
1186 | (3) |
|
|
1189 | (1) |
|
|
1190 | (2) |
|
Chapter 49 DPA 1998: private remedies and regulatory enforcement |
|
|
|
|
|
1192 | (1) |
|
2 Private remedies: subject access requests |
|
|
1193 | (2) |
|
3 Private remedies: breach of the continuing duty |
|
|
1195 | (1) |
|
|
1196 | (4) |
|
5 National security certificate appeals |
|
|
1200 | (2) |
|
|
1202 | (1) |
|
7 Third parties and appeals |
|
|
1202 | (2) |
|
Chapter 50 Warrants, offences and immunities |
|
|
|
|
|
1204 | (5) |
|
2 FOI(S)A 2002 and EI(S)R 2004 |
|
|
1209 | (1) |
|
|
1210 | (2) |
|
|
1212 | (4) |
|
|
1216 | (4) |
|
Part VIII Comparative law |
|
|
|
Chapter 51 The Comparative Jurisdictions |
|
|
|
1 Information Rights Legislation Elsewhere |
|
|
1220 | (1) |
|
2 United States of America |
|
|
1221 | (11) |
|
3 Commonwealth of Australia |
|
|
1232 | (8) |
|
|
1240 | (6) |
|
|
1246 | (7) |
|
|
1253 | (7) |
Index |
|
Index |
|
1260 | |
|
|
|
|
|
|
|
|
3 | (253) |
|
General Data Protection Regulation |
|
|
256 | (118) |
|
|
|
Law Enforcement Directive |
|
|
374 | (53) |
|
International Conventions etc |
|
|
|
Convention for the Protection oflndividuals with regard to the Automatic Processing of Personal Data (1981) |
|
|
427 | (8) |
|
Modernised Convention for the Protection oflndividuals with regard to the Automatic Processing of Personal Data (2018) |
|
|
435 | (13) |
|
OECD Revised Guidelines Governing the Protection of Privacy and Transborder Flows of Personal Data (2013) |
|
|
448 | (4) |
|
|
|
Data Protection (Charges and Information) Regulations 2018 |
|
|
452 | (7) |
|
Statutory codes of practice, etc |
|
|
|
Table of statutory codes and statutory guidance required to be produced by the Information Commissioner under DPA 2018 |
|
|
459 | (1) |
|
Information Commissioner: Regulatory Action Policy (November 2018), pursuant to DPA 2018 ss 133 158 & 150 |
|
|
460 | (31) |
|
Part II Freedom of Information |
|
|
|
|
|
Freedom of Information Act 2000 |
|
|
491 | (85) |
|
Freedom of Information (Scotland) Act 2002 |
|
|
576 | (58) |
|
|
|
Freedom of Information and Data Protection (Appropriate Limit and Fees) Regulations 2004 |
|
|
634 | (3) |
|
Freedom of Information (Definition of Historical Records) (Transitional & Saving Provisions) Order 2012 |
|
|
637 | (2) |
|
Freedom of Information (Designation as Public Authorities) Order 2011 |
|
|
639 | (1) |
|
Freedom of Information (Designation as Public Authorities) Order 2015 |
|
|
640 | (2) |
|
Freedom of Information (Designation as Public Authority and Amendment) Order 2018 |
|
|
642 | (1) |
|
Freedom of Information (Excluded Welsh Authorities) Order 2002 |
|
|
643 | (2) |
|
Freedom of Information (Release of Datasets for Re-Use) (Fees) Regulations 2013 |
|
|
645 | (1) |
|
Freedom of Information (Time for Compliance with Request) Regulations 2004 |
|
|
646 | (3) |
|
Freedom of Information (Time for Compliance with Request) Regulations 2009 |
|
|
649 | (1) |
|
Freedom of Information (Time for Compliance with Request) Regulations 2010 |
|
|
650 | (1) |
|
|
|
Section 45 Code of Practice (4 July 2018) |
|
|
651 | (23) |
|
Section 46 Code of Practice (16 July 2009) |
|
|
674 | (25) |
|
Part III Environmental Information |
|
|
|
|
|
Environmental Information Regulations 2004 |
|
|
699 | (17) |
|
Environmental Information (Scotland) Regulations 2004 |
|
|
716 | (12) |
|
|
|
|
728 | (21) |
|
|
749 | (10) |
|
|
|
Code of Practice (16 February 2005) |
|
|
759 | (18) |
|
Part IV Other Rights to Information Primary legislation |
|
|
|
|
777 | (35) |
|
Local Government Act 1972, Part VA |
|
|
789 | (17) |
|
Access to Health Records Act 1990 |
|
|
806 | (6) |
|
|
|
Regulation (EC) No 1049/2001 |
|
|
812 | (11) |
|
Part V Data Protection (post-EU Exit Day) |
|
|
|
|
|
Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019/419 |
|
|
823 | (56) |
|
Part VI Data Protection (pre-25 May 2018) |
|
|
|
|
|
|
879 | (89) |
|
|
|
|
968 | (25) |
|
|
|
Data Protection (Conditions under Paragraph 3 of Part II of Schedule 1) Order 2000 |
|
|
993 | (2) |
|
Data Protection (Crown Appointments) Order 2000 |
|
|
995 | (1) |
|
Data Protection (Fees under section 19(7)) Regulations 2000 |
|
|
996 | (1) |
|
Data Protection (Functions of Designated Authority) Order 2000 |
|
|
997 | (2) |
|
Data Protection (Miscellaneous Subject Access Exemptions) Order 2000 |
|
|
999 | (2) |
|
Data Protection (Monetary Penalties) Order 2010 |
|
|
1001 | (2) |
|
Data Protection (Monetary Penalties) (Maximum Penalty and Notices) Order 2010 |
|
|
1003 | (2) |
|
Data Protection (Processing of Sensitive Personal Data) Order 2000 |
|
|
1005 | (4) |
|
Data Protection (Processing of Sensitive Personal Data) Order 2006 |
|
|
1009 | (1) |
|
Data Protection (Processing of Sensitive Personal Data) Order 2009 |
|
|
1010 | (1) |
|
Data Protection (Processing of Sensitive Personal Data) (Elected Representatives) Order 2002 |
|
|
1011 | (3) |
|
Data Protection (Subject Access) (Fees and Miscellaneous Provisions) Regulations 2000 |
|
|
1014 | (3) |
|
Data Protection (Subject Access Modification) (Education) Order 2000 |
|
|
1017 | (3) |
|
Data Protection (Subject Access Modification) (Health) Order 2000 |
|
|
1020 | (3) |
|
Data Protection (Subject Access Modification) (Social Work) Order 2000 |
|
|
1023 | (8) |
|
Part VII Procedural Material |
|
|
|
|
|
Tribunals, Courts and Enforcement Act 2007 |
|
|
1031 | (66) |
|
|
|
Tribunal Procedure (First-tier Tribunal) (General Regulatory Chamber) Rules 2009 |
|
|
1097 | (25) |
|
Tribunal Procedure (Upper Tribunal) Rules 2008 |
|
|
1122 | (41) |
|
First-tier Tribunal and Upper Tribunal (Composition of Tribunal) Order 2008 |
|
|
1163 | (2) |
|
First-tier Tribunal and Upper Tribunal (Chambers) Order 2010 |
|
|
1165 | (7) |
|
Qualifications for Appointment of Members to the First-tier Tribunal and Upper Tribunal Order 2008 |
|
|
1172 | (2) |
|
Transfer of Tribunal Functions Order 2010 |
|
|
1174 | (4) |
|
Appeals from the Upper Tribunal to the Court of Appeal Order 2008 |
|
|
1178 | (1) |
|
Court proceedings: Practice rules & directions |
|
|
|
Civil Procedure Rules 1998: rule 53 |
|
|
1179 | (1) |
|
Practice Direction 53 A: Transferring proceedings to and from the media & communications list |
|
|
1180 | (1) |
|
Practice Direction 53B: Media & communication claims |
|
|
1181 | (6) |
|
Tribunal proceedings: Practice notes, Directions etc |
|
|
|
Practice Note: Confidential Information in the First-tier Tribunal |
|
|
1187 | (7) |
|
Practice Note: Closed Material in Information Rights Cases |
|
|
1194 | (2) |
|
Guidance Note: Permission to Appeal from FTT to UT |
|
|
1196 | (1) |
|
Guidance Note: Discretionary Transfers from FTT to UT |
|
|
1197 | |