Skip to content
    • About
    • Contact
    • Legal stuff (Terms & Conditions)

Alistair Sloan, Advocate

  • Councillors, Erroneous Benefit Claims, FOI and DPA

    January 5th, 2015

    The relationship between FOI and Data Protection is one that causes frequent tension.  Obtaining personal data on third parties held by public authorities under FOI is, rightly, a difficult task.  On Sunday it was reported that Cornwall Council refused to release, in response to a Freedom of Information request, the name of a Councillor who had been advised by the Council that they had “erroneously claimed entitlement to Housing Benefit and Council Tax Benefit / Support” while they were a member of the Council, and that the amount involved was less than £5,000.  The Council refused to disclose the name of the Councillor on the basis that it was exempt under section 40(2) of the Freedom of Information Act (which exempts the release of personal data where its release would be in contravention of the Data Protection Act (DPA)).  This resulted in an interesting discussion between a few individuals on twitter relative to whether the Council was correct to withhold the Councillor’s name.

    Lynn Wyeth concluded that it came down to the standard Data Protection Officer’s answer of “it depends” – and it really does; there is a whole heap of information missing which would be relevant to whether releasing the Councillor’s name would breach the DPA.

    The starting point in respect of this one is establishing whether it is personal data, clearly it is; not only is it personal data, but it falls within the definition of sensitive personal data in section 2 of the DPA.  The information concerned here is personal data concerning the alleged commission of an offence by an individual (claiming benefits to which you’re not entitled being a criminal act).  This is an important point because the restrictions placed upon the processing of sensitive personal data are a lot more stringent than personal data which is not considered sensitive under the DPA.

    The first Data Protection Principal is clear, that personal data must be processed fairly and lawfully.  It goes on to provide that personal data should not be processed unless at least one of the conditions in Schedule 2 is applicable; in the case of sensitive personal data it is also necessary to ensure that one of the conditions in Schedule 3 applies as well.

    When it comes to releasing personal data under FOI, the condition in schedule 2 that is most often (if not always) applicable is Condition 6(1).  This condition provides:

    The processing is necessary for the purposes of legitimate interests pursued by the data controller or by the third party or parties to whom the data are disclosed, except where the processing is unwarranted in any particular case by reason of prejudice to the rights and freedoms or legitimate interests of the data subject.

    In other words, a person seeking the release of personal data about a  third party under FOI must be able to show that he has a legitimate interest and that it is necessary for the personal data to be disclosed in pursuance of that legitimate interest.  I would say that it would generally be the case that uncovering wrong-doing by an elected official while holding public office is a legitimate interest.  Unless the matter was reported in the newspapers or in other media at the time the accusation was being pursued by the body concerned, it would be necessary for the data controller to release the personal data in order to enable the third party to pursue their legitimate aim (uncovering misconduct by a public official and holding them to account).

    However, this is personal data that falls within the scope of sensitive personal data and as such the very fact that condition 6(1) of Schedule 2 to the DPA is likely to be satisfied it is not the case that releasing the personal data would be fair and lawful.  There needs to be a condition in schedule 3 that is applicable as well.

    In the normal course of things there wouldn’t, in my view, be a condition in schedule 3 which would apply – unless the data subject consented to the disclosure.  However, in certain circumstances it may be possible to use the paragraph 3(b) of Schedule 3 which applies where the processing is necessary:

    in order to protect the vital interests of another person, in a case where consent by or on behalf of the data subject has been unreasonably withheld.

    There are a number of key words here.  The first is “necessary”; if there was another way in which the vital interests of another person could be met without the data controller releasing the information then it wouldn’t apply (for example, if there had been a news report revealing the name – but then the FOI request wouldn’t have been necessary in the first place).  The next is “vital”; there is not, to my knowledge, any case law on what exactly “vital” means in the DPA – it appears in a number of places within Schedule 3.   It could reasonably be argued that uncovering the misappropriation of public funds by an individual elected to public office and holding that individual to account is a “vital” interest of a person other than the data controller (essentially everyone who the data subject is elected to represent).  Finally, the data subject’s consent must be unreasonably withheld.

    This is where this case becomes particularly complicated.  It would seem that no criminal proceedings were ever brought against the councillor in question, and certainly it appears that there has been no conviction.  There is a presumption at the very heart of the criminal justice system in each of the legal jurisdictions in the UK: innocent until guilt is established.  As there would appear to be no criminal conviction in this case, the Councillor is an innocent member of the public holding elected public office.  The fact that there is no conviction, in my view, makes it harder to argue that there are vital interests to be protected.

    This isn’t that straightforward though; some weight needs to be given to the fact that this individual was accused of making erroneous claims for benefits while an elected official.  Furthermore, it is necessary to give some weight to the fact that some form of procedure was carried out to reclaim overpayments made to the councillor.  However, that alone might not be enough to make release of their name under FOI fair and lawful.  There are other factors to be considered.  For example, if there was a settlement agreement in place which proceeded upon the basis of no admission of liability then that, I suggest, would tend to count against disclosure; especially if this was exactly how an individual who didn’t happen to be an elected member of the council would be dealt with.  That leads onto the next issue; was there any preferential treatment given to the Councillor? It would appear not, the Council has said that it was handled in accordance with the normal procedures.  Had it not been handled in accordance with normal procedures (e.g. he was given special treatment because he happened to be a councillor) then that might tip the balance in favour of disclosure because it would suggest some level of impropriety over and above the allegation that there was an ‘erroneous claim’.

    In essence, these decisions are finely balanced.  I’m not going to say whether the Council was right or not to refuse to disclose because I’m not in possession of all of the relevant facts.  I don’t know what has gone on behind the scenes here, I don’t know whether the consent of the data subject has been sought let alone withheld unreasonably.  The journalist who made the request can make use of their right to request an internal review of the handling of the request and then complain to the Information Commissioner.  What I would say though is that simply because an elected official has been accused of something which may or may not amount to a criminal offence is not, in of itself, necessarily a justifiable reason to process personal data by releasing it under the Freedom of Information Act.

  • FOI at 10

    January 1st, 2015

    On 1st January 2005 the Freedom of Information Act 2000, the Environmental Information Regulations 2004, the Freedom of Information (Scotland) Act 2002 and the Environmental Information (Scotland) Regulations 2004 all entered into force.  For the first time in the UK people had a right, backed by Statute, to ask for information held by public bodies and to be given that information unless it fell within the ambit of one of the exemptions in the Acts or Exceptions in the Regulations.  Those rights were backed-up by independent regulators who had the power to order public bodies to release information where it had been incorrectly withheld by public bodies.

    Today, is of course, the 10th anniversary of the coming into force of those rights and it has become so ingrained into our lives that we probably don’t notice it.  Every year thousands of stories that we see on TV or in the newspapers or hear about on radio have been the result of information obtained under Freedom of Information; much of that information may well have remained hidden had it not been for the rights enshrined in law to obtain that information.

    Freedom of Information has been used to uncover scandals around Parliamentary expenses, both in Westminster and in Holyrood.  The late David McLetchie resigned as leader of the Scottish Conservative party following revelations that he had used taxpayers money to pay for taxis used in connection with party, rather than constituency, business.  That information was obtained under Freedom of Information.  At Westminster some politicians have served prison sentences as details of their expenses claims were revealed with help from FOI (and a leak to the Telegraph).

    Over the last 10 years, Freedom of Information has become a powerful tool for local and national campaign groups to obtain information from the State as to how and why decisions have been taken.  It has enabled public bodies to be held accountable much more easily and for the public to better understand decisions that have been taken by public bodies.

    Of course, FOI has not come without its problems and difficulties.  It does add an additional burden to public bodies – but the legislation does have limits to ensure that the burden doesn’t become too big or disproportionate.  There are individuals who abuse their rights under FOI.  There are a group of individuals who make use of FOI to try and keep open grievances that they have had with the public authority – some of which have been running for many years and been subjected to every form of scrutiny possible.  There are also those who make requests about plans for dealing with a Zombie Apocalypse or how many red pens had been bought.

    There have also been regular attempts to undermine Freedom of Information by representative bodies.  These attempts have often cited ‘bizarre’ FOI requests.  Many of these so called ‘bizarre’ requests have a perfectly legitimate basis as explored here by Jon Baines.  The Prime Minister, David Cameron, also has some pretty strange ideas as to what Freedom of Information is.

    FOI was a hard won right, with organisations such as the Campaign for Freedom of Information spending decades campaigning for access to information rights.  As a consequence we have some of the best access to information rights in the world.  Our rights are wide-ranging and simple to use whereas in other countries they are restrictive and contain a multitude of technical requirements making them difficult to use while others put the rights out of the reach of ordinary people by requiring fees to be paid in order to exercise those rights.  However, while it is probably true to say that our FOI laws are some of the best in the world it is also true to say that they are in need of serious protection.  As the way in which public services are delivered has changed, a lot of information has fallen out of the scope of FOI.  The regular attacks from bodies representing public authorities also threaten FOI.  These are important rights and it is right that on the 10th anniversary of FOI we remember their importance and how easy it would be for a Government to reduce, restrict or remove those rights.  As a rule, politicians don’t like FOI – it can be embarrassing for them and leads to a much more informed electorate.  A better informed electorate is a good thing, as is removing the Government’s total control  over the flow of information.

    The House of Commons Select Committee concluded that FOI ‘has been a significant enhancement to our democracy’ in a report following its post-legislative scrutiny of the Freedom of Information Act 2000.  FOI has changed our democracy for the better, the 10th anniversary is a good opportunity to remind ourselves of how significantly things have changed in the last 10 years as a result of FOI and how valuable it has become.

    The Campaign for Freedom of Information fought hard to get FOI onto the statute books and continues to work hard to promote it, campaign for its strengthening and protection; perhaps you would consider donating, even a small amount, to help them with this important work.

  • Beyond Reasonable Doubt: An unfair advantage to the accused?

    December 9th, 2014

    In the wake of the dismissal of the case against Shrien Dewani in South Africa, Dan Hodges has written a piece on the Telegraph website questioning the criminal standard of proof.  I will write this blog post from a Scottish perspective, but the general points will apply equally to most ‘western’ legal systems.

    There are two burdens of proof recognised before the courts: the criminal standard, which is “beyond reasonable doubt” and the civil standard, “on the balance of probabilities”.  What we are concerned here with is the criminal standard of proof, and particularly whether it weighs the system too heavily in favour of the accused.

    Before going further, it might be helpful to set out what beyond reasonable doubt means.  In his comment piece, Mr Hodges, asserts that in order for the prosecution to secure a conviction against an accused they “must prove beyond question the guilt of the accused.”  This is not the case, and overstates the standard of proof.  The criminal standard of proof does not require there to be no doubt at all, only that there is an absence of reasonable doubt.  What this means is that the accused is entitled to the benefit of any doubt which is based upon reason and commonsense following a careful and impartial consideration of the evidence (and the lack thereof) presented to the court.  The doubt, as Lord Justice-Clerk Cooper put it in Irving v Minister of Pensions, should be something more than “a strained or fanciful acceptance of remote possibilities”; Lord Justice-Clerk Thomson said in McKenzie v HM Advocate  that it is something “more than a merely speculative or academic doubt”.  The finder of fact (the jury or the sheriff/Justice of the Peace) doesn’t have to be convinced beyond doubt that the accused perpetrated the crime alleged, only to the point where he has no reasonable doubt.

    There are a variety of reasons as to why there is such a high standard of proof in criminal cases.  One of those reasons is the consequence of a guilty verdict in a criminal trial.  As Jones and Christie put it in Criminal Law (4th Edition), “conviction certainly entails more than a mere finding that, e.g. “A killed B”.  This in itself is a legally neutral statement…The Prime function of the criminal law is that of articulating the circumstances under which it is justifiable to hold a person punishable for his conduct.” (para 1-13).  In other words, with the criminal law we are going beyond a situation where we are simply ascribing liability to concluding that a person’s conduct renders them liable for punishment.  That punishment can be severe, it could result in a person being deprived of their liberty for a lengthy period of time.  A finding of liability in a civil case does not generally result in the liable party being punished; there may be a requirement to compensate the party that they have wronged to try and place them back into the position they were in before the wrong occurred (or to place them in the position they would have been in had the wrong not occurred), but that is manifestly different from punishment.  The stakes are much higher and as such it has been the position that the standard of proof must also be higher as a consequence.

    It seems unjust to punish someone, in the severe ways open to the criminal justice system, on the basis that it is merely more likely than not that they committed the crime alleged.  A system whereby an accused person could be convicted merely on the balance of probabilities would inevitably result in the entire criminal justice system being brought into serious disrepute as individuals would routinely be convicted where there are sensible and logical alternatives to their guilt based on the evidence which was heard in court.

    It has long been the case that the justice system has preferred to see guilty men walk free than an innocent man be unjustly punished.  This is not some ‘liberal, leftard, hand-wringly nonsense’; it is a centuries old principle and can be found in times where liberal principles were about as far away from the justice system as was possible.  We’re going back to the times of gruesome public executions for the most minor of crimes, to where transportation was still a sanction open to judges and to where prison conditions were probably more horrible than even the most right-wing member of society would care to suggest today.  Moreover, is it’s a principal which is a recognised international standard and features in what most people would consider to be “decent” legal systems.  This principle is another reason for the high standard of proof in criminal trials and is linked closely to the idea that a finding of guilt in a criminal trial opens up legitimate punishment upon the offender.

    We’re probably all familiar with the concept of an accused person being innocent until proved otherwise (even if, as a society, we don’t always hold to that with our quick condemnations upon those suspected or accused of crimes).  The burden is placed squarely upon the State for a number of reasons, not least an equality issue.  The State is vastly better resourced than an individual and it can call upon those resources when trying to prove that someone “did it”.  The State has professional investigators in the form of the police, and teams of specialist lawyers to prosecute the case in court in the form of the public prosecution service.  While those services, in the UK at least, are suffering from a considerable cut to their funding, those resources continue to vastly outstrip the resources of the accused who has only his (small) defence team to counter the might of the State.  Lowering the Standard of proof would inevitably lead to the accused having to prove things that he does not currently have to prove.  Of course, it is presently the case that an innocent accused facing an overwhelming case against them would be sensible to offer evidence as to why the State is wrong; however, in a system where the standard of proof was merely whether it was more likely than not that the accused had committed the crime it would almost always be the case that the accused would have to be disproving the States case (or, to put it another way, prove his own innocence).  It would eat away at the presumption of innocence and would result in a great inequality between the State and the accused.

    Does the criminal standard of proof weight the system in favour of the accused?  I suggest no.  What it does, I suggest, is merely rebalance a system that without it would unfairly favour the State with its huge and specialist resources over the extremely limited resources of the accused.

  • Devolving Data Protection

    November 13th, 2014

    The Data Protection Act 1998 (DPA) applies across the whole of the United Kingdom and is enforced centrally by the Information Commissioner’s Office in Wilmslow (which also has offices in Belfast, Cardiff and  Edinburgh).  Anyone who has been following Scottish politics recently will be aware that a Commission has been established to make proposals on further devolution to Scotland following the Scottish Independence Referendum in September.  It has been suggested by the Law Society of Scotland in their written evidence [pdf] to the Smith Commission that consideration should be given to devolving data protection to Scotland.

    This was a proposal that caught my eye when I read the Law Society of Scotland’s evidence, and it is an interesting one. Is there any real reason as to why Data Protection ought not to be devolved?

    The Law Society of Scotland narrate within their evidence the confusion that can arise with the Scottish Information Commissioner being approached in respect of enforcement action relating to Data Protection, a function that she does not presently undertake.  The Scottish Information Commissioner enforces the Freedom of Information (Scotland) Act 2002, the Environmental Information (Scotland) Regulations 2004 and the INSPIRE (Scotland) Regulations 2009.  In their evidence, the Society makes reference to the way in which Freedom of Information (Scotland) Act 2002 and the DPA interact.  They rightly point out that the Scottish Information Commissioner is required to make decisions in respect of whether it would breach the DPA to release personal data in response to a FOI request.

    The interaction between DPA and FOI is a well known difficulty and there has been litigation surrounding it, such as in South Lanarkshire Council v the Scottish Information Commissioner (on which I have previously written here and here).  Understandably it must be difficult for the Scottish Information Commissioner to take decisions on disclosure in respect of personal data when her office is not also responsible for enforcing the DPA – it risks her taking a decision with which the Information Commissioner in Wilmslow might well disagree with (and consequently result in a Scottish public Authority breaching its obligations under the DPA).

    The law relating to Data Protection comes from the EU, but that on its own would not prohibit its devolution. The INSPIRE (Scotland) Regulations 2009 and the Environmental Information (Scotland) Regulations 2004 both give effect to EU Directives in Scotland.  Ultimately, it is the UK Government that is accountable to the EU for the implementation of EU law within the United Kingdom.  That fact though doesn’t appear to have stopped the UK Government from devolving to Scotland the power to implement EU law into Scots law in some areas already.

    There is a difference between the DPA and the legislation that the Scottish Information Commissioner currently enforces. The DPA applies to the private sector to the same extent as the public sector.  The legislation currently enforced by the Scottish Information Commissioner applies to public sector and bodies falling within certain definitions that provide functions of a public nature only.  There is a degree of difference between them; for example, the bodies caught by the Environmental Information (Scotland) Regulations is wider than the bodies caught by the Freedom of Information (Scotland) Act 2002.  What has this got to do with devolving Data Protection?  It might not be of an immediately obvious nature; however, the bodies covered by the Freedom of Information (Scotland) Act 2002, the Environmental Information (Scotland) Regulations 2004 and the INSPIRE (Scotland) Regulations 2009 are all largely based entirely within Scotland; there are almost no examples of where the Scottish law here applies to bodies carrying out functions elsewhere in the UK.  Is this difference (i.e. the cross jurisdictional aspect of Data Protection) a sufficient reason not to devolve Data Protection to Scotland?

    In terms of FOI, public bodies which have functions across the whole of the UK, or are part of the UK Central Government, are covered by the UK equivalent and not the Scottish law. Some examples include: the BBC, the British Transport Police, the Scotland Office, the Office of the Advocate General for Scotland, the Home Office, the Department for Work and Pensions and HMRC.  In these cases the Freedom of Information Act 2000, the Environmental Information Regulations 2004 and the INSPIRE Regulations 2009 apply and it is the UK Information Commissioner in Wilmslow who enforces their compliance.

    In terms of devolution, it is logical why the Freedom of Information Act 2000, the Environmental Information Regulations 2004 and the INSPIRE Regulations 2009 apply to UK wide bodies. It would undoubtedly present difficulties for those organisations if they had to comply with different requirements in different parts of the UK.  However, in terms of FOI, some bodies already have that difficulty.

    It does not appear to be widely known, but some of the UKs biggest businesses are covered by FOI law to a very limited extent. The likes of Tesco, Sainsbury’s, Asda and Boots are all subject to FOI law in respect of their NHS Pharmaceutical and Optometry services.  These are the bodies that have the difficulty of complying with two separate FOI regimes.  In respect of their services contracted by the NHS in Scotland it is the Freedom of Information (Scotland) Act 2002 and the Environmental Information (Scotland) Regulations 2004 that apply (and the Scottish Information Commissioner is responsible for enforcement) while in respect of their services contracted by the NHS in England it is the Freedom of Information Act 2000 and the Environmental Information Regulations 2004 that apply (and the UK Information Commissioner is responsible for enforcement).  A request to one of those bodies for information on a UK wide scale would require them to deal with the request under two separate access to information schemes (potentially four if the information was environmental in nature).  Outside of the world of access to information legislation there is a great deal of differences between the legal frameworks in which UK wide businesses operate across the UK.  A contemporary example might be statutory charges for carrier bags.  Wales, Northern Ireland and Scotland all have them while England does not.  As a consequence businesses operating across the UK have to adopt difference practices on carrier bags to ensure legal compliance in those parts of the UK that do require charges to be made for carrier bags.  This is a fairly minor example, but there are some which are much more substantial in nature.

    In terms of devolving data protection to Scotland, if it were to be devolved at all, there are two options. The first would be to devolve it only in respect of data controllers domiciled in Scotland.  This would mean Scottish domiciled data controllers would have to comply with a Scottish Data Protection Act while data controllers domiciled elsewhere in the UK would have to comply with a UK Data Protection Act.  This is probably not a good option from the point of view of Data Subjects; some UK wide companies would be domiciled in Scotland and some would be domiciled elsewhere in the UK.  This could cause confusion as to which Information Commissioner they ought to be dealing with in relation to a data protection concern.  For example, in that situation customers of RBS might find themselves dealing with the Scottish Commissioner as RBS is a company registered in Scotland.  This is the sort of confusion that the Law Society of Scotland mentioned within their response as to why consideration ought to be given to devolving data protection to Scotland.  The other option is to simply devolve Data Protection and that would mean any UK-wide organisation operating in Scotland would have to comply with both the UK and the Scottish Data Protection Acts – it would be no different to multi-nationals who have to comply with the different Data Protection regimes across the world or the multitude of other areas where UK-wide businesses already have to comply with different laws north and south of the border.

    Devolving Data Protection to Scotland wouldn’t end the UK Information Commissioner’s responsibilities in Scotland. He would still be responsible for dealing with Freedom of Information in respect of the many bodies covered by the Freedom of Information Act 2000 and the Environmental Information Regulations 2004 which operate in Scotland.  His office would also still be responsible for enforcing the Privacy and Electronic Communications (EC Directive) Regulations 2003 (which overlap considerably with data protection) unless responsibility for implementing the E-Privacy Directive upon which they are based was similarly devolved to Scotland.

    So, should Data Protection be devolved? Well, there is no good reason against it that I can see.  There would be a good opportunity for devolution in the form of the Data Protection Regulation currently working its way through the EU legislative process.  At that stage Data Protection law in the UK will have to change and if this were to be an area for devolution to Scotland that would seem like a sensible time to do it.  However, given the nature of EU Regulations as opposed to EU Directives, the practical effect of devolving Data Protection to the Scottish Parliament would be limited.  The question would become “what is the point?”.  The arguments in favour of further devolution to Scotland centre around the Scottish Parliament taking decisions on matters for Scotland which do not need to be reserved; however, the practical effect of the new Data Protection Regulation would be that there would be almost no scope for the Scottish Parliament to take decisions on data protection; there would be an EU Regulation which has direct effect in all EU member states, without the need to pass domestic legislation.  Any legislation, UK or Scottish, would simply be regurgitating the Regulation alongside some minor consequential and transitional matters.

    The Law Society of Scotland argues that the new regulation means that there is less of a need for data protection to be a reserved matter; that would be true because from an EU compliance point of view there would be no risk to the UK Government. They also seem to place a lot of weight on the issue of confusion between the responsibilities of the two information commissioners; however, I’m not sure that would be resolved by devolving data protection – in fact there is real potential for it to be compounded rather than resolved.  The only real argument is the one concerning FOI decisions involving third party personal data, but so far that doesn’t appear to have been an issue.  Indeed, in the South Lanarkshire Council case mentioned above, the Supreme Court agreed with the approach of the Scottish Information Commissioner; although there is always scope for the Scottish Information Commissioner to get things wrong.  That said, the UK Information Commissioner could equally get things wrong and wrongly order the disclosure of personal data under FOI.

    Should data protection be devolved?  There doesn’t seem to be strong case one way or the other.  In the grand scheme of things there are far more important issues in the devolution debate than whether the Scottish Parliament should get power devolved over an issue that won’t actually amount to much power at all.

  • Consultation on PECR Monetary Penalty Notice Threshold: Initial Thought

    October 26th, 2014

    Section 55A of the Data Protection Act 1998 (DPA) confers upon the Information Commissioner the power to issue a Monetary Penalty Notice (MPN) to Data Controllers for serious contraventions of the DPA.  This power is extended to cover contraventions of the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECRs) by virtue of an amendment made to Regulation 31 of the PECRs.

    The test for issuing a MPN for contraventions of either the DPA or the PECRs is as set out in Section 55A of the DPA and it requires a number of boxes to be ticked before the Commissioner can issue one:

    • That the commissioner is satisfied that there has been a serious contravention of section 4(4) of the DPA (or a serious contravention of the PECRs)
    • The contravention was of a kind likely to cause substantial damage or substantial distress
    • and either the contravention was deliberate but failed to take reasonable steps to prevent it; or that the data controller knew (or ought to have known) that there was a risk that the contravention would occur and that such a contravention was of a kind likely to cause substantial damage or substantial distress but failed to take reasonable steps to prevent it

    It looks complicated, and to an extent it is.  However, what is clear from the way in which the statutory provisions have been drafted and from the binding interpretation given to them by the Upper Tribunal in The Information Commissioner v Niebel [pdf] is that the test is an almost impossibly high one to meet.

    The Department of Culture Media and Sport (DCMS) has issued a consultation document seeking the views of those interested as to whether the threshold should be lowered (and to what) for the Commissioner to be able to issue a MPN in respect of breaches of the PECRs (the proposal would see the test remain as is in respect of contraventions of the DPA).

    The consultation document makes three proposals:

    1. do nothing
    2. replace the requirement for the contravention to be of a kind likely to cause substantial damage or substantial distress with a requirement that the contravention is of a kind likely to cause annoyance, inconvenience or anxiety
    3. remove the requirement for the contravention to be of a kind likely to cause substantial damage or substantial distress altogether and replace it with nothing

    The Commissioner favours the third option and the DCMS state in the consultation document that their provisional view is that the third option is their preference too.

    I’ve given the consultation some consideration since its publication on Saturday and begun to formulate my response (it’s nor a particularly lengthy consultation document and does present three clear and simple options).  What has struck me though is what is missing from option three.  The current test and the second option within the consultation document both include situations where the Data Controller ought to have known that there was a risk that the contravention would occur and that such a contravention was of a kind likely to cause substantial damage or substantial distress but failed to take reasonable steps to prevent it.  However, this appears to be missing from the third option as expressed within the consultation document.

    This apparent omission concerns me.  It creates a defence where someone can demonstrate that they didn’t know that there was a risk the contravention would occur even when it is apparent to all and sundry that they really should have known there was a risk.  It basically excuses negligence.  It allows a completely unreasonable situation to avoid the regulatory sanction of a MPN.

    This seems like a glaring omission to me and it’s something I’ll certainly be thinking about the possible ramifications of in more detail before submitting a response to the DCMS.  I thought it was an interesting point that was worth raising in a blog.

    The DCMS consultation can be found here [pdf] and the deadline for responses to be received by the DCMS is 7 December 2014.

  • Direct Marketing by E-mail and Text: the need for consent

    October 17th, 2014

    The Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECRs) are probably not the most widely known piece of legislation, but they are important when it comes to marketing – and everyone who hates spam text messages, telephone calls and E-mails would probably benefit from knowing about them!  The Regulations implement a piece of EU law into domestic law (for those that are interested the relevant EU law is Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications)) and are concerned with when and how organisations and individuals (which for ease of reference will simply be referred to as ‘organisations’ throughout) can market directly to individuals via electronic means.  Direct marketing means any form of advertising or marketing which is targeted at a specific individual.

    The rules are really very simple, but are regularly not complied with by companies large and small.  The general rule is that unless you have the consent of the individual (and that consent should be freely given and informed) then you cannot market directly to individuals via E-mail, text message, telephone call or any other electronic means.  This post will focus on electronic mail only (such as text messages and E-mail).

    What does not qualify as consent for the purposes of the PECRs?  Consent isn’t specifically defined within the PECRs; however, the Regulations provide that where a term is not defined within either the PECRs or the Data Protection Act 1998 (DPA) the terms should be given the definition ascribed to it in the Directive.  The Directive, in turn, directs us to another EU Directive (95/46/EC – the Directive upon which the DPA is based) where the definition is given as:

    any freely given specific and informed indication of his wishes by which the data subject signifies his agreement to personal data relating to him being processed.

    It is very clear.  Consent must be:

    • Freely given
    • Specific
    • informed

    When it comes to gaining consent different companies do it in different ways, most of which do not in any way come close to satisfying those three basic requirements.  One way, which I have encountered recently, is to simply build it into their Privacy Policy and/or Terms and Conditions that you consent.  That’s probably the most blatant and flagrant way of breaching the PECRs you can get.  The consent is neither freely given nor informed.  While such organisations might give an option to opt-out at a later date that is insufficient to comply with the Regulations.  Consent isn’t consent unless there is an option not to consent.  Refusing should also be free (except for the cost of transmitting the refusal).  In other words, an individual cannot be charged a fee for refusing (or withdrawing) consent to direct marketing by electronic mail, but if there is a cost to transmitting it (e.g. the cost of a text message or a stamp) then that cost is legitimate.

    Another common occurrence is for organisations to have an ‘opt-out’ box requiring the individual to tick in order to say that they don’t consent.  This is nothing more than another form of presumed consent, which clearly doesn’t comply with the requirements of the PECRs.  So far as electronic mail is concerned, the only option is a clear decision to opt-in.

    Some organisations will have the opt-in box and will have helpfully already ticked it, meaning that individuals need to un-tick it to withhold their consent to direct marketing by electronic mail.  Again, this is not compliant with the Regulations.  Giving consent is a positive action, if the registration, order form, enquiry form, questionnaire etc. goes away with a pre-ticked marketing box still ticked then it is unclear whether the individual has given their consent to the direct marketing or whether they simply  haven’t (for whatever reason) un-ticked the box.

    All is not lost though if details have been obtained by stealth.  There ought to be a way of withdrawing consent contained in every text message or E-mail that is received (a requirement of the PECRs).  However, there is another useful right open to individuals.  That right is contained in section 11(1) of the DPA which states:

    An individual is entitled at any time by notice in writing to a data controller to require the data controller at the end of such period as is reasonable in the circumstances to cease, or not to begin, processing for the purposes of direct marketing personal data in respect of which he is the data subject.

    Simply put, individuals can send a letter or an E-mail or some other form of written notice to the organisation in question requiring them to stop sending direct marketing.  This covers all forms of direct marketing and would include text messages, E-mails, letters, phone calls and such like.  The organisation then has to stop direct marketing within “a reasonable time” – the Information Commissioner gives guidance which states that for direct marketing by electronic means organisations should comply within 28 days, and for postal marketing the guidance is 6 weeks.  These notices are legally enforceable and it is possible to go to Court if an organisation doesn’t comply – alternatively the Information Commisisoner can become involved as there will be breaches of the Data Protection Principles if such a notice is not complied with.

    This is just a very basic overview of the requirements of the PECRs, the Information Commissioner has produced a more in-depth guide  to Direct Marketing [pdf] which covers everything in more detail.  I was prompted to write this blog post based on the sheer number of flagrant breaches of the PECRs that there are.  These breaches are by big names.  Major political parties, FTSE 100 companies and major household brands are failing to act in accordance with a basic requirement: that before they can bombard individuals with direct marketing they have to obtain the freely given and informed consent of the individual.

  • The death of the death penalty in the UK: 50 years on

    August 13th, 2014

    At 8am on 13 August 1964 at Strangeways Prison in Manchester Gwynne Owen Evans was hanged by executioner Harry Allen for the murder of John Allan West. At the same time 30 miles away in Walton Prison, Liverpool Peter Anthony Allen was hanged by Robert Leslie Stewart, also for the murder of John Allan West. Evans and Allen were to be the last two men executed by the State in the United Kingdom. The Death Penalty was effectively abolished in 1965; however, remained an option until 1998 in cases of Treason and Piracy with violence.

    Fifty years on there comes with each high profile murder, and indeed other cases which prove the public’s revulsion, calls to re-instate the death penalty in the UK. Only 50 years ago crowds were taking to the streets in protest at the death penalty. The death of the death penalty in the UK came about from a number of shocking miscarriages of justice in which innocent people were wrongly convicted and executed by the State.

    One of those cases was that of Timothy Evans who was executed on 9 March 1950 for the murder of his wife and daughter. His neighbour, John Christie, was later executed for the murder of Evans’ daughter as well as the murder of a number of others, including Christie’s own wife. John Christie had been a witness at Evans trial for the prosecution, and almost certainly saw Evans be sent to the Gallows. On 19 November 2004 the Court of Appeal accepted the Evans did not murder either his wife or his child, but refused to quash his conviction on the basis that the cost and resources of quashing them could not be justified. The case caused public outrage and was one of a number of cases which saw Capital Punishment being confined to history in the UK.
    There were other cases that saw the end of the death penalty in the UK, but the Evans case highlights perfectly the very real dangers of Capital Punishment. It is a non-reversible form of punishment; no quashing of the conviction and no financial compensation from the Government can ever rectify an execution. If an innocent man is executed; he is dead and remains dead even after the mistake is discovered. While imprisoning an innocent person can have some devastating effects on that individual, th every fact that they continue to breathe means that they can, when mistakes are uncovered, be released.

    There have, of course, been some exceptionally high profile miscarriages of justice over the years. Hugh Callaghan, Patrick Joseph Hill, Gerard Hunter, Richard McIlkenny, William Power, John Walker, Paul Michael Hill, Gerard Conlan, Patrick Armstrong, Carole Richardson and Sam Hallam are all individuals who have been convicted of Murder, and whose convictions were overturned long after they would have been executed had Capital Punishment remained in the UK.

    Of course, investigative techniques have moved along and advances in science have drastically changed the way in which the police investigate crimes. We have also moved on from the days where murder trials are over in a matter of a few short days, with these trials often lasting considerably longer than a week – sometimes even running into months. However, to argue that forensic science, such as DNA, helps prove who is guilty and who is not of murder in a lot of cases is to overstate the value of DNA evidence. DNA evidence is not, as some may thing, the golden bullet in a criminal trial. It cannot, and is unlikely to ever, prove conclusively that the accused is guilty of the crime libled. It helps to build the picture and along with other circumstantial evidence might be able to convince a jury to beyond reasonable doubt; however, as with all systems that involve humans there is room for error. When the end result is going to be the State depriving an individual of their life, there can be no room for error.

    The case of Shirley McKie highlights the errors that can be made in examining forensic evidence. Shirley McKie, a form er Detective Constable, was accused of perjury after testifying at the Murder Trial of David Asbury for the murder of Marion Ross that she had not been in the house of Marion Ross, where she had been killed. A scandal erupted following the case and it resulted in changes being made to the comparison and verification of fingerprints in Scotland.

    Regardless of whether you take the view that morally someone who takes the life of another should lose their own life or not, or whether you believe executing people is a deterrent to others; the very fact that there is a risk of the State executing an innocent person should be reason enough not to return to the days of capital punishment. Executing an innocent person deters no-body, it’s not justice and should never be considered an acceptable price to pay for executing people who really are guilty.

  • Valid FOI requests via Twitter?

    July 7th, 2014

    The Information Commissioner’s Office (ICO) has issued a Decision Notice that the Metropolitan Police failed to comply with section 10 of the Freedom of Information Act 2000 (FOIA) which was made to it through Twitter.  In November 2012 the ICO issued a one page document setting out its view on whether a valid request can be made via Twitter.  In that document the ICO acknowledged that Twitter was not the most effective way to submit a FOI request; however, it went on to say that requests made via Twitter are not necessarily invalid.

    The test for whether a request is a valid one or not is to be found in section 8 of the FOIA; it sets out the requirements as to what constitutes a valid request.  The Act provides:

    (1) In this Act any reference to a “request for information” is a reference to such a request which—

    (a) is in writing,

    (b) states the name of the applicant and an address for correspondence, and

    (c) describes the information requested.

    (2) For the purposes of subsection (1)(a), a request is to be treated as made in writing where the text of the request—

    (a) is transmitted by electronic means,

    (b) is received in legible form, and

    (c) is capable of being used for subsequent reference.

     Let us look at each requirement in turn:

    The request is in writing

    The starting point with statutory interpretation would normally be what is the literal meaning of the word?  Here Parliament has given us some assistance in interpreting what is considered to be in writing.  This does appear to be one of those ‘for the avoidance of doubt’ provisions and was most probably inserted to take account of E-mail.  There is little doubt that when passing the Act Parliament did not think about Facebook or Twitter, indeed when the Act was passed Facebook was barely a thing and Twitter hadn’t been invented.  However, as technology changes it is necessary for the law to move with it – whether it is capable of doing so without amendment by Parliament is a different matter!

    Is a tweet transmitted by electronic means?

    It is certainly sent and received by electronic means, but what does ‘transmitted’ mean?  According to the literal rule of statutory interpretation we must look at the ordinary meaning of the word transmitted.  Let’s turn to the online Oxford English dictionary and its entry for transmit.  Only the first two definitions are relevant here.  To transmit something is to “cause (something) to pass on from one person or place to another” or “broadcast or send out (an electrical signal or a radio or television programme).”  So, is a tweet transmitted by electronic means?  Sending a tweet is certainly causing something (the content of the tweet) to pass from one person (the sender) to the other (the recipient).  It might also be said that it is being sent from one place (the sender’s computer) to another (the recipient’s computer).  It could be said that sending a tweet is not too dissimilar to sending an E-mail.  Is it by electronic means?  I think that it is clear that it is, for obvious reasons such as without electronics there wouldn’t be the hardware to enable a tweet to be sent.  Is a tweet being broadcast or sent out?  The dictionary gives an example of an electronic signal or a radio/television programme.  What is a tweet?  It is essentially a series of digits which put together displays on the screen as an image – it might be said to be similar to a TV programme.  Whether it meets the second definition or not, I do think that it is safe to say it meets the first.

    Is it received in a legible form? 

    Well it’s certainly not going to be illegible because it is typeface rather than handwritten.  One might be of the view that this was perhaps to cover a handwritten note sent by fax and so probably isn’t relevant here – I think we can tick this box as well.

    Is it capable of being used for subsequent reference?

    This is where things get slightly more difficult! The Act doesn’t say who has to be capable of referencing it subsequently.  Obviously, the Public Authority will have to be able to reference it subsequently in order to check that it is complying with the request made.  Furthermore, the requester has to be able to subsequently reference it should they need to make a complaint to the ICO – the ICO will usually want to see the request and where possible evidence of the request having been sent.  However it does not seem to be as straight forward as that.

    If I tweet a public authority’s official account, my tweets are not protected and I don’t do anything else then it is possible for both the public authority and I to subsequently reference the tweet.  On the face of it, this would clearly meet the requirement.  Whether or not they know it is there is probably an irrelevant question in the same way someone missing a request in their E-mail inbox doesn’t matter.

    The issue becomes slightly more complicated if I protect my tweets later and the public authority is not following me – then only I can subsequently reference the tweet – or if I delete my tweet altogether.  In the first of these two situations (protecting my tweets where the authority is not following me) the tweet is clearly capable of being referenced subsequently, but only by me.   Does this meet the requirements of the Act?  Well I would suggest that in order to establish that we need to understand why Parliament included it.  What situations were Parliament envisaging when they enacted this part of the Act?  The explanatory notes do not provide any illumination on that question.  I don’t have time to, at this stage, wade through the many lines of debate in Handsard on the Bill in the hope that there is an explanation here.  I can’t immediately think of a situation which Parliament would have had in its mind when enacting this section.  On that basis I don’t think that really takes us any further forward.

    The question that immediately springs to mind is for how long does the request have to be capable of being subsequently referenced by the authority?  If I protect my tweets on the 20th working day following sending the request is that different to if I protect them immediately following the sending of the request?  After all, by the 20th working day the authority should be in a position to respond, or at least have gathered all of the information in scope and simply be conducting the public interest balancing exercise.  I’d suggest there is a difference.  Quite where the ‘cut off is’ would most probably be a question of looking at the circumstances in each individual case – not an ideal situation though.

    What about if I delete the tweet?  That might cause problems when making an application to the Commissioner – although taking a screenshot of the tweet prior to deleting it might cure that.  Again is it dependent upon when I delete the tweet – e.g. on the 20th working day or immediately after it was sent?

    These are difficult questions and ones that don’t have clear answers.  However, in at least one case (the first – where the tweet was and remains public after it is sent and is not at any stage deleted or becomes inaccessible to the public authority by way of an individual’s tweets become protected) a tweet appears to meet all of the requirements set out in section 8(2) of the Act.

    However, as mentioned earlier section 8(2) does seem to be more of a ‘for the avoidance of doubt’ subsection – a request can be in writing in other ways and it would appear that this has most probably been included so as to ensure that public authority’s treat requests received by E-mail as being valid requests – it would not appear to be the ‘be all and end all’ of the matter.

    At the end of the day, what does ‘in writing’ mean? I don’t think we could realistically argue that a tweet is not ‘in writing’ even if it does not meet all of those tests – after all, a letter sent by mail doesn’t meet the requirements of section 8(2) and nobody would sensibly argue or find that such a request is not ‘in writing’ and so section 8(2) is clearly not the complete definition of what is meant by ‘in writing’ within section 8(1).

    The request states the name of the applicant and an address for correspondence

    Assuming that we have a request made via twitter that meets the definition of being ‘in writing’ the next requirement is that the request must state the name of the applicant and an address for correspondence.  If we accept that a public authority’s twitter accounts is an address capable of having correspondence (not necessarily just a FOI request, but any type of correspondence) sent to it, then equally an individual’s twitter account must also be an address for correspondence.  If an individual does not need to, for example, include within the body of their E-mail their E-mail address (i.e. it appearing in the ‘From’ field is sufficient) then I don’t see why someone would have to include their own twitter handle in their request – it is there for the authority to see in its mentions.

    However, the name issue is more problematic.  It is the view of the Commissioner (and I believe that it is the correct one) that the name of the applicant must be their real name – lots of people don’t use their real name (or indeed any of the acceptable forms thereof for the purposes of FOI) in their twitter profile; so there we could have a problem.  If it’s not on their profile, then it’s not a valid request – even if we’ve managed to overcome the ‘in writing’ issue.

    Describes the information requested

    The final requirement is that the request describes the information requested.  That has to be in enough detail to enable the authority to identify what is sought.  That could be difficult in 140 characters.  However with services such as twitlonger it can be done.  It could also be possible to send the request over a number of tweets (as was done in the Metropolitan Police case linked to at the outset of this blog post).  I don’t see that as being any different to sending it in a number of letters or in a number of separate E-mails.  Indeed, when an authority seeks clarification because it is unable to identify what information is being requested it is looking at a request over at least two pieces of separate correspondence, if not more, to create a valid request.

    Conclusion

    The ICO does not say in its guidance that all requests made via twitter will be valid, only that a request made via Twitter may not necessarily be invalid.  I would certainly have to agree: it is possible to make a valid request by twitter.  Is it a good idea?  I would say that it’s not, and that it is probably best to stick to more conventional methods such as letter or E-mail.

  • The law and historic cases: sensible or bizarre?

    July 5th, 2014

    It has been reported by the BBC today that president of the ‘Association of Child Abuse Lawyers’ has said the way in which Rolf Harris was sentenced was ‘bizarre’. He is referring to the fact that in historic cases the judge passing sentence is limited to the maximum sentence that was available at the time of the offence. In the Harris case this was 2 years (or 5 years in the cases where the victim was under the age of 13).

    There are a lot of historic sexual assault and abuse cases trundling their way through the justice system. It is right that, no matter how many years later, the perpetrators of these crimes face justice. However, there is a significant issue in such cases; whether it is a sexual offence or not. As time progresses and as Government’s change, the law too goes through change. If you’re prosecuting an individual 20 or 30 years after the offence was committed it is highly likely that the law has undergone several significant changes: that is true with the law surrounding sexual offences. In all cases historic offences will be prosecuted according to the law at the time the offence was committed. The other alternative is to prosecute them under the law at the time they are prosecuted.

    Why do we prosecute historic cases at the time they were committed? Well, it’s about what is fair and just. Justice is not just about the victim, but it must equally be about the offender. It would be oppressive if the law were to treat offences committed decades ago as if they were committed today. It is a general principle of law in democratic countries around the world, especially in the realm of criminal law, that the law is not retrospective. That means that current changes in the law should not affect future consequences of past conduct. In other words, if you did something that was a particular criminal offence which attracted a particular maximum penalty, but by the time you are prosecuted the law has changed, you should be treated (as far as is reasonably practicable) as you would have been when you committed the crime. The same would be true if you committed a crime today, but the law changed substantially tomorrow: you would be dealt with as the law was today and not as the law changed tomorrow – even if there was no substantial delay in arresting, charging and prosecuting you.

    In the Rolf Harris case he was prosecuted for the offences that he committed at the time. As such, the maximum penalty that was available to the court was that which would have been available at the time the offence was committed (2 years, or 5 in the case of offences relating to children under the age of 13). Specifically, in the case of Rolf Harris his sentence of 5 years and 9 months was made up of a mixture of concurrent and consecutive sentences for the various charges that he was convicted of. The sentencing remarks of Mr Justice Sweeny are available online and detail what the charges were and what the sentence was for each charge (and whether it was to be served concurrently or consecutively). You can read the sentencing remarks here.

    When it comes to sentencing cases like this one where there has been such a delay in bringing the offender to justice, it is not the job of the court to try and fix the sentence that would have been given at the time. The judge must have regard to the sentencing guidelines that are currently in place; however, they cannot pass a sentence which would exceed the maximum available at the time the offence was committed. I blogged in this issue last year looking specifically at the law of England and Wales, you can read that blog here.

    Sentencing is always a complex matter, but it is even more complex in these cases. While there will, quite understandably, be no sympathy for people like Rolf Harris; the law must be fair and it must be just. That applies to victim and offender and so the law must not be oppressive by prosecuting people for more serious offences than what they committed (while under the current law they may well have committed the more serious offence, they did not actually commit that offence because they offended at a time when the law was quite different) or by giving them a sentence that is in excess of the maximum that was available at the time they committed the offence.

    I won’t make any comment on whether I think the sentence Rolf Harris received was too harsh, too lenient or about right. I understand that the sentence has been referred by someone to the Attorney General and it is now for him to decide whether he thinks that it is unduly lenient and whether it ought to be referred to the Court of Appeal. When he is doing so he will have regard to the sentences passed, the law as it was at the time the offences were committed the present sentencing guidelines and no doubt the totality of the sentence passed. My understanding of the law is that the Attorney General has 28 days to decide whether he is going to refer it to the Court of Appeal. Even if the Attorney General decides to refer it to the Court of Appeal they may refuse to hear the case or decide that the sentence should remain the same: a referral does not mean that the sentence will increase or that it was unduly lenient.

  • Costs in the FTT: Snee v Information Commissioner & Leeds City Council

    May 28th, 2014

    Under the Freedom of Information Act 2000 a decision by the Information Commissioner is capable of being appealed to the First Tier Tribunal (Information Rights) by either the public authority involved or the Complainant.  There is no cost in brining an appeal and parties are generally responsible for paying any legal costs that they incur (public authorities will often be represented as will the Commissioner; sometimes by Counsel).  Under The Tribunal Procedure (First-tier Tribunal) (General Regulatory Chamber) Rules 2009 the Tribunal has, on the application of a party, the power to award costs.  It can do so where the appellant has acted unreasonably in brining or pursuing the appeal.

    Earlier this month the First Tier Tribunal issued a decision, Mark Snee v the Information Commissioner and Leeds City Council, in respect of an application for costs against an Appellant by Leeds City Council.  The Council were seeking their £20,000 costs in full, having  applied to be joined to the appeal and having been represented by Queens Counsel.  The Appellant in the case, Mr Snee, was represented by Counsel.  The Tribunal’s decision contains some useful information with regards to heir approach to such applications.

    Mr Snee’s requests had been refused by the Council on the grounds that they were vexatious (section 14(1) of the Freedom of Information Act 2000).  The Commissioner and the Tribunal agreed that they were vexatious, and it was at that stage the City Council applied under Rule 10(1)(b) of the Tribunal Rules for costs.

    One of the Council’s arguments, which was not accepted by the Tribunal, would have had a fundamental effect upon an individual’s right to appeal to the Tribunal.  It was argued that, because Mr Snee’s requests were vexatious he had acted unreasonably in bringing the case to the Tribunal.  The Tribunal did not agree.  It pointed out that the Commissioner had the opportunity to refuse to issue a decision notice where he found the complaint to be frivolous or vexatious, and the Tribunal had the power to Strike out an appeal upon the application of a party where it has no hope of succeeding.  The Tribunal stated that it was right to remember these protections against vexatious or hopeless appeals.  Automatically making appeals against a decision that requests are vexatious subject to the costs provisions where the appeal fails would have a significant impact upon the appeal rights of an individual.  The Tribunal considered that “it must be possible, depending on the circumstances, for the maker of a request regarded by everyone else as vexatious, to defend his or her position on that point without automatically being treated under the costs Rules as behaving unreasonably.”  In other words, it must be possible for an individual who makes a request which is considered to be vexatious to defend their position in the Tribunal.

    In the Tribunal individuals who are appealing against the Commissioner’s decision in respect of their FOI request will often not have the benefit of legal advice.  Thus, what might appear to a fully trained lawyer to be “futile or wrongheaded”, the Tribunal considered that “it would be wrong to assume that the challenge is inevitably an unreasonable one for the citizen to bring.”  The comments had a much more general application than that and equally well apply to a range of other Tribunals within the First Tier Tribunal structure where Legal Aid is not available, or is available only in very limited circumstances.

    It seems, from this decision, that the chances of an appellant facing a costs order for an Appeal against a decision of the Information Commissioner are unlikely; although it remains a possibility that costs will be awarded in exceptional circumstances; quite what those circumstances will be remains to be seen.  It seems more likely that an unreasonable appeal will be struck out during the early case management stages than for it to progress to a full hearing, thus preventing the generation of significant costs for all involved.

←Previous Page
1 … 6 7 8 9 10 … 16
Next Page→

Blog at WordPress.com.

  • Subscribe Subscribed
    • Alistair Sloan, Advocate
    • Join 62 other subscribers
    • Already have a WordPress.com account? Log in now.
    • Alistair Sloan, Advocate
    • Subscribe Subscribed
    • Sign up
    • Log in
    • Report this content
    • View site in Reader
    • Manage subscriptions
    • Collapse this bar