Global Freedom of Expression

Department of Health v. Information Commissioner and Rt Hon John Healey MP and Nicholas Cecil

The U.K. First-Tier Tribunal of the General Regulatory Chamber for Information Rights held that a Transitional Risk Register (“TRR”), relating to sweeping changes to the country’s National Health System (“NHS”), should be disclosed under The Freedom of Information Act (“FOIA”) but that a Strategic Risk Register, relating to the changes, was exempt from disclosure. The court found that a public authority must release risk registers evaluating health policy if the request is made when policy consultation and formulation has been largely completed, but not during a period of consultation and when the register includes more sensitive policy information. In the present case, the Court ruled in favor of the public interest in transparency because at the time of the TRR request, the Report largely covered operational and implementation risks being faced by the Department of Health (“DOH”), rather than direct policy considerations. On the other hand, the Court found that the public interest in the Government having safe space to formulate policy took precedence at the time of the SRR request because the request was made at a time when the government was engaged in ongoing policy deliberations.

Schrems v. Data Protection Commissioner

“On those grounds, the Court (Grand Chamber) hereby rules:

1. Article 25(6) of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data as amended by Regulation (EC) No 1882/2003 of the European Parliament and of the Council of 29 September 2003, read in the light of Articles 7, 8 and 47 of the Charter of Fundamental Rights of the European Union, must be interpreted as meaning that a decision adopted pursuant to that provision, such as Commission Decision 2000/520/EC of 26 July 2000 pursuant to Directive 95/46 on the adequacy of the protection provided by the safe harbour privacy principles and related frequently asked questions issued by the US Department of Commerce, by which the European Commission finds that a third country ensures an adequate level of protection, does not prevent a supervisory authority of a Member State, within the meaning of Article 28 of that directive as amended, from examining the claim of a person concerning the protection of his rights and freedoms in regard to the processing of personal data relating to him which has been transferred from a Member State to that third country when that person contends that the law and practices in force in the third country do not ensure an adequate level of protection.

2. Decision 2000/520 is invalid.”