The Data Protection Act

Provisions which may remove data-protection obstacles that might otherwise inhibit processing/disclosure – occasionally referred to as the ‘enabling sections’* of the Act. Current official language sometimes describes this part of the legislation as creating a “permissive gateway” for information sharing:


Data Protection Act 2018 – The Supply of information – ‘enabling’ sections

SCHEDULE 2
Exemptions etc from the GDPR
PART 1
Adaptations and restrictions based on Articles 6(3) and 23(1)

Crime:

2(1) The listed GDPR provisions and Article 34(1) and (4) of the GDPR (communication of personal data breach to the data subject) do not apply to personal data processed for any of the following purposes

  1. the prevention or detection of crime,

(b) the apprehension or prosecution of offenders

Legislation link.


Information required to be disclosed by law etc or in connection with legal proceedings

5

  1. The listed GDPR provisions do not apply to personal data consisting of information that the controller is obliged by an enactment to make available to the public, to the extent that the application of those provisions would prevent the controller from complying with that obligation.
  1. The listed GDPR provisions do not apply to personal data where disclosure of the data is required by an enactment, a rule of law or an order of a court or tribunal, to the extent that the application of those provisions would prevent the controller from making the disclosure.
  1. The listed GDPR provisions do not apply to personal data where disclosure of the data

(a)is necessary for the purpose of, or in connection with, legal proceedings (including prospective legal proceedings),
(b)is necessary for the purpose of obtaining legal advice, or
(c)is otherwise necessary for the purposes of establishing, exercising or defending legal rights, to the extent that the application of those provisions would prevent the controller from making the disclosure.


ICO Guidance regarding enabling sections – ‘exemptions’

For organisations / Guide to Data Protection / Guide to the General Data Protection Regulation (GDPR)/ Exemptions

*’Enabling provisions’ is a perfectly understandable practical description, but under the present legislation a more appropriate description would be “the applicable data-protection exemptions and lawful disclosure provisions”. The DPA:

  • does not compel disclosure, but
  • DPA/GDPR is not an automatic reason to refuse it.

Data protection legislation does not constitute an absolute bar to proportionate disclosure for these purposes.

The ICO expressly says an exemption does not remove the requirement for a lawful basis for processing. There are perfectly respectable routes for proportionate disclosure connected with legal rights and fraud prevention.


DPA historical references:

Under the even earlier 1984 Act, prevention/detection of crime was section 28.

In the Data Protection Act 1998, the crime provision was actually section 29 – “Crime and taxation”. Section 35 covered disclosures required by law or necessary for legal proceedings, prospective proceedings, legal advice, or establishing/exercising/defending legal rights. Section 34 concerned information required by legislation to be publicly available.

The modern equivalents are dispersed rather than contained in one neat section. In particular, Schedule 2 paragraph 2 DPA 2018 contains the crime-and-taxation exemption and expressly carries forward the old section 29 regime.

If what is being processed amounts to information concerning an alleged criminal offence, Schedule 1 paragraph 10 also contains a condition relating to preventing or detecting unlawful act

Schedule 2 paragraph 5 deals with disclosure connected with legal proceedings, including prospective proceedings, and establishing, exercising or defending legal rights.