Feeds

Does Gove’s webmail policy breach Data Protection Act too?

FOI-fudging foolery might've been the least of Mrs Blurt's boo-boos

Build a business case: developing custom apps

Does the use of Gmail or Hotmail by a Minister's Private Office (in order to evade Freedom of Information (FOI) obligations) also lead to breaches in the Data Protection Act? Well, I can see how this could be the case.

The press has raised this issue only in the context of FOI. Yesterday's Sunday Times, for example, noted that the allegations facing Michael Gove and his special adviser, Dominic Cummings, were that by using personal email accounts, they were assuming that any requested information could not be held by a public authority and therefore not subject to a FOI regime.

A spokesman for the Department for Education (DfE) has told the press that "The Cabinet Office is clear that private email accounts do not fall within the FOI Act and are not searchable by civil servants. Neither the Secretary of State nor special advisers have been asked to disclose emails sent from private accounts".

The DfE spokesman then added: "The Permanent Secretary is satisfied that ministers and special advisers act within the law." Despite this, the Information Commissioner has entered the fray and has said that private account emails discussing Government business could be subject to FOI requests.

Whether these emails are, or are not, subject to FOIA will no doubt be resolved in the near future. However, what I am certain about is that all these emails contain some personal data (even if the personal data is limited to email addresses) and these emails are regulated by the Data Protection Act.

Mr Gove, the Sunday Times reports, uses the username of “Mrs Blurt” in his emails. However, suppose the advisor (Dominic Cummings perhaps using the name of “Mr Blurt”) sends an email to “Mrs Blurt” or vice-versa. Now further suppose that email says the following: “Can we talk to the Whips to make sure that Joe Bloggs MP does not get on the Standing Committee that is scrutinising the Education Bill?”. (This kind of exclusion happens as MPs are usually selected for Committees by the Whips on the basis the less troublesome they are, the easier it is for Government business to get through).

Perhaps another email might go: “I have just had a meeting from Head Teacher X who publicly asked some very awkward questions about our education reforms. Just in case there are ‘future complications’ , I recommend that this head teacher’s school should not be in the first wave of schools that get compulsory Academy status?”.

Could these be the sort of emails that a special advisor could send to a Minister – especially if they think the FOI regime does not apply? Well I think this is distinctly possible.

First data protection question: are these emails personal data? I think we can say: “obviously yes”. There are four data subjects: Mr Gove, Dominic Cummings (i.e. “Mr and Mrs Blurt”) and the MP or Head Teacher X. Who is the data controller? Well if it is not the Department for Education (remember, the claim is that the emails are exempt from FOIA) then it has to be Mr Gove and possibly Mr Cummings as well.

Does the personal data fall into the domestic purpose exemption in Section 36 of the DPA? Well, if there are emails that have the content described above, I suggest that this exemption is inapplicable. Do the emails impact on the MP and Head Teacher mentioned in them, so much so that they should be informed about the processing purpose via the fair processing rules? Well, I can’t see an exemption from this obligation.

Michael Gove, as an MP, has a register entry that describes his constituency casework for the purpose of “the carrying out of casework on behalf of individual constituents”. Any “personal emails” about an MP or head teacher as postulated above have nothing to do with this purpose as the data subjects are not constituents. Dominic Cummings, as of today, is not registered at all.

So we have one, possibly two data controllers, likely to be processing personal data in breach of the data protection principles:- one for an unregistered purpose and the other just, plain simple unregistered. Not only could we have FOI evasion but we are also likely to have DP evasion in addition. This means that Mr Gove has gone one better than Tony Blair: Mr Blair only disapproves of FOI.

So if the Information Commissioner finds resistance to his FOI enforcement powers, perhaps he should put his data protection hat on. After all, I think the data protection arguments are sound and failure to comply with the Commissioner's data protection powers can be a criminal offence (unlike with FOIA).

This story originally appeared at HAWKTALK, the blog of Amberhawk Training Ltd.

Build a business case: developing custom apps

More from The Register

next story
Just TWO climate committee MPs contradict IPCC: The two with SCIENCE degrees
'Greenhouse effect is real, but as for the rest of it ...'
Adam Afriyie MP: Smart meters are NOT so smart
Mega-costly gas 'n' 'leccy totting-up tech not worth it - Tory MP
'Blow it up': Plods pop round for chat with Commonwealth Games tweeter
You'd better not be talking about the council's housing plans
Arrr: Freetard-bothering Digital Economy Act tied up, thrown in the hold
Ministry of Fun confirms: Yes, we're busy doing nothing
ONE EMAIL costs mining company $300 MEEELION
Environmental activist walks free after hoax sent share price over a cliff
Help yourself to anyone's photos FOR FREE, suggests UK.gov
Copyright law reforms will keep m'learned friends busy
Apple smacked with privacy sueball over Location Services
Class action launched on behalf of 100 million iPhone owners
UK government officially adopts Open Document Format
Microsoft insurgency fails, earns snarky remark from UK digital services head
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
The Essential Guide to IT Transformation
ServiceNow discusses three IT transformations that can help CIO's automate IT services to transform IT and the enterprise.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.