APPENDICES
¶4.103 The powers of the Information Commissioner include: i) a power requiring a public authority
to furnish the Commissioner with information he or she reasonably requires to determine whether a public authority has complied with its obligations under Part 1 and whether its practices comply with the Code of Practice, (ii) a power to issue an enforcement notice, if the Commissioner is satisfied that a public authority has failed to comply with Part 1, requiring the public authority to take the steps in the notice, (iii) certify that a public authority has failed to comply with a decision notice, information notice or enforcement notice, which allows the High Court to inquire into the matter and the deal with the public authority as if it had committed contempt of court, (iv) powers of entry and inspection pursuant to Schedule 33.431
¶4.104 Pursuant to s57 the public authority may appeal against a decision notice, information notice or enforcement notice to the Information Tribunal.
¶4.105 There are a number of general functions conferred on the Information Commissioner pursuant to s47 of the FOIA:
1925(a) The Commissioner has a duty to promote the following of good practice by public authorities and in particular to perform his or her function under the Act to promote the observance by public authorities of the requirements of the Act and the provisions of the codes of practice under ss45 and 46. The Act confers a number of powers on him or her to enable this, specifically in relation to the Code. (b) The Commissioner shall arrange for the dissemination of information as it may appear expedient to give to the public about the operation of the Act, about good practice and other matters within the scope of his or her functions under the Act. (c) The Commissioner may, with the consent of any public authority, assess whether that authority is following good practice. (d) If it appears to the Commissioner that the practice of a public authority in relation to the exercise of its functions under the Act does not conform with that proposed in this Code of Practice, a recommendation may be given to the authority under s48 specifying the steps which should, the Commissioner's opinion, be taken for promoting such conformity. (e) The Commissioner may also refer to non-compliance with the Code in decision notices issued as a result of a complaint under s50 of the Act and enforcement notices issued under s52 of the Act where, irrespective of any complaints that may have been received, the Commissioner considers that a public authority has failed to comply with any requirement of Part 1 of the Act. (f) If the Information Commissioner reasonably requires any information for the purpose of determining whether the practice of a public authority conforms to the Code, under s51 of the Act the Commissioner may serve an "information notice" on the authority, requiring it to provide specified information relating to its conformity with the Code. (g) The Commissioner shall from time to time as considered appropriate consult the Keeper of Public Records about the promotion by the Commissioner of the observance by public authorities of the provisions of the code of practice under s46 in relation to records which are public records for the purposes of the Public Records Act 1958.
¶Appendix 4 | Legal Materials
¶4.106 Section 49 provides that the Commissioner shall lay annually before each House of Parliament
a general report on the exercise of his or her functions under this Act and other such reports from time to time with respect these functions as thought fit.
¶Possible reform of the law in this area 4.107 In November 2010 the European Commission announced a review of the Data Protection
Directive.432 On 25 January 2012, the European Commission published a draft European Data Protection Regulation that will supersede the Data Protection Directive.433 The Commission has proposed a new regime comprising:
(a) a Regulation of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), and (b) a proposal for a Directive of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data by competent authorities for the purposes of prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and the free movement of such data.
¶4.108 The draft Regulation seeks to modernise the legal framework for data protection needs in
the EU in response to increasingly sophisticated information systems, global information networks, mass information sharing and the collection of personal data online.
¶4.109 A number of amendments to the current Directive are contemplated by the draft Regulation.
¶These include:
(a) strengthening provisions relating to consent to the processing of data, by requiring explicit rather than implied consent, (b) strengthening the right to object to processing of data, with no requirement to show that use of the data would cause substantial damage or distress, (c) placing important legal obligations directly on processors: introducing a compulsory data breach notification duty that applies across all sectors, a requirement to demonstrate compliance with the regulation through the adoption of policies and procedures, the requirement to undertake data protection impact assessments prior to processing that is likely to impact on the privacy of a data subject, and the power of supervisory authorities to impose sanctions on data controllers for administrative offences such as not complying with a data subject request, a failure to maintain the requisite records or a failure to comply with the right to be forgotten.
Article 80 is of particular relevance and concerns the processing of personal data and free- dom of expression. It provides as follows:
1926"Member States shall provide for exemptions or derogations from the provisions on the general principles in Chapter II, the rights of the data subject in Chapter III, on controller and processor in Chapter IV, on the transfer of personal data to third countries and international organisations in Chapter V, the independent supervisory