*/
In the second part of his feature on information security, Graham Cunningham looks at the guidelines regarding physical material.
Last month, I wrote about your responsibilities under the Data Protection Act 1998 (DPA 1998), concerning electronic processing of personal information. It was designed for your protection and, most especially to avoid you having to give undertakings to the Information Commissioner or pay fines. This month, I want to concentrate on physical material; ie, the paper in the lever arch files that makes up the average brief. Generally speaking, the sort of physical material you get in the average brief does not come within DPA 1998.
The Act, however, does cover manual files where these have been structured in such a way that personal information in them can readily be found without searching. It is then your obligation to treat this information as if it was held in electronic format. If you (or your clerks) do receive briefs in electronic format or you decide to scan physical material and manipulate it, then technically you are processing data and fall within DPA 1998.
That said, you are not absolved from all responsibilities. This is your client’s confidential information and has to be treated as such. Physical confidential information is much wider than the ambit of DPA 1998. The Act is essentially concerned with protecting the privacy of living individuals; confidential information covers everything from written information about individuals to inventions to marketing information and so on.
What to do with confidential information
Your IT Panel would like to restate formally what to do with confidential information:
If you do government or government agency work, you need to comply with the Attorney General’s guidelines on information security to be found at: www.tsol.gov.uk/PanelCounsel/security.htm.
Secure disposal
It is a requirement of DPA 1998 that personal data should not be retained for longer than is required. However, this may be seven years or longer for case files. Accordingly, the retention of personal data should be reviewed regularly. The retention of precedents, pleadings, advices and documents that have been used in open court, from which personal data have been removed by anonymising, is not a breach of DPA 1998.
Chambers should have procedures in place for the secure disposal of confidential material and electronic media (eg, the cross-cut shredding of papers and CD-ROMs) and hard drives.
Barristers who wish to dispose of any computer or electronic media upon which confidential material has been stored must ensure the material is effectively destroyed or wiped using a recognised method to put the data beyond recovery. Merely deleting the files, single-pass overwriting, or reformatting the disk is insufficient. Physical destruction or the use of specialist deletion and overwriting software is necessary.
Further information
This completes the IT Panel’s summary on how to treat both electronically processed and written information. It would be happy to answer queries from barristers.
Please contact Alexandra McHenry (AMcHenry@BarCouncil.org.uk).
Rule 702 of the Code of Conduct states:
“Whether or not the relation of counsel and client continues a barrister must preserve the confidentiality of the lay client’s affairs and must not without the prior consent of the lay client or as permitted by law lend or reveal the contents of the papers in any instructions to or communicate to any third person (other than another barrister, a pupil, in the case of a Registered European Lawyer, the person with whom he is acting in conjunction for the purposes of paragraph 5(3) of the Registered European Lawyers Rules or any other person who needs to know it for the performance of their duties) information which has been entrusted to him in confidence or use such information to the lay client’s detriment or to his own or another client’s advantage.”
Graham Cunningham, with contributions from Iain Mitchell QC, Clive Freedman and Jacqueline Reid of the Bar Council IT Panel
The Act, however, does cover manual files where these have been structured in such a way that personal information in them can readily be found without searching. It is then your obligation to treat this information as if it was held in electronic format. If you (or your clerks) do receive briefs in electronic format or you decide to scan physical material and manipulate it, then technically you are processing data and fall within DPA 1998.
That said, you are not absolved from all responsibilities. This is your client’s confidential information and has to be treated as such. Physical confidential information is much wider than the ambit of DPA 1998. The Act is essentially concerned with protecting the privacy of living individuals; confidential information covers everything from written information about individuals to inventions to marketing information and so on.
What to do with confidential information
Your IT Panel would like to restate formally what to do with confidential information:
If you do government or government agency work, you need to comply with the Attorney General’s guidelines on information security to be found at: www.tsol.gov.uk/PanelCounsel/security.htm.
Secure disposal
It is a requirement of DPA 1998 that personal data should not be retained for longer than is required. However, this may be seven years or longer for case files. Accordingly, the retention of personal data should be reviewed regularly. The retention of precedents, pleadings, advices and documents that have been used in open court, from which personal data have been removed by anonymising, is not a breach of DPA 1998.
Chambers should have procedures in place for the secure disposal of confidential material and electronic media (eg, the cross-cut shredding of papers and CD-ROMs) and hard drives.
Barristers who wish to dispose of any computer or electronic media upon which confidential material has been stored must ensure the material is effectively destroyed or wiped using a recognised method to put the data beyond recovery. Merely deleting the files, single-pass overwriting, or reformatting the disk is insufficient. Physical destruction or the use of specialist deletion and overwriting software is necessary.
Further information
This completes the IT Panel’s summary on how to treat both electronically processed and written information. It would be happy to answer queries from barristers.
Please contact Alexandra McHenry (AMcHenry@BarCouncil.org.uk).
Rule 702 of the Code of Conduct states:
“Whether or not the relation of counsel and client continues a barrister must preserve the confidentiality of the lay client’s affairs and must not without the prior consent of the lay client or as permitted by law lend or reveal the contents of the papers in any instructions to or communicate to any third person (other than another barrister, a pupil, in the case of a Registered European Lawyer, the person with whom he is acting in conjunction for the purposes of paragraph 5(3) of the Registered European Lawyers Rules or any other person who needs to know it for the performance of their duties) information which has been entrusted to him in confidence or use such information to the lay client’s detriment or to his own or another client’s advantage.”
Graham Cunningham, with contributions from Iain Mitchell QC, Clive Freedman and Jacqueline Reid of the Bar Council IT Panel
In the second part of his feature on information security, Graham Cunningham looks at the guidelines regarding physical material.
Last month, I wrote about your responsibilities under the Data Protection Act 1998 (DPA 1998), concerning electronic processing of personal information. It was designed for your protection and, most especially to avoid you having to give undertakings to the Information Commissioner or pay fines. This month, I want to concentrate on physical material; ie, the paper in the lever arch files that makes up the average brief. Generally speaking, the sort of physical material you get in the average brief does not come within DPA 1998.
Kirsty Brimelow KC, Chair of the Bar, sets our course for 2026
What meaningful steps can you take in 2026 to advance your legal career? asks Thomas Cowan of St Pauls Chambers
Marie Law, Director of Toxicology at AlphaBiolabs, explains why drugs may appear in test results, despite the donor denying use of them
Asks Louise Crush of Westgate Wealth Management
AlphaBiolabs has donated £500 to The Christie Charity through its Giving Back initiative, helping to support cancer care, treatment and research across Greater Manchester, Cheshire and further afield
Q&A with criminal barrister Nick Murphy, who moved to New Park Court Chambers on the North Eastern Circuit in search of a better work-life balance
With pupillage application season under way, Laura Wright reflects on her route to ‘tech barrister’ and offers advice for those aiming at a career at the Bar
Jury-less trial proposals threaten fairness, legitimacy and democracy without ending the backlog, writes Professor Cheryl Thomas KC (Hon), the UK’s leading expert on juries, judges and courts
Human rights cases don’t come bigger than this. Tim Otty KC, lead counsel for the Government of Ukraine in its case before the European Court against Russia, talks about the significance of this landmark ruling and other pro bono highlights from his career at the Bar. Interview by Anthony Inglese CB
Are you ready for the new way to do tax returns? David Southern KC explains the biggest change since HMRC launched self-assessment more than 30 years ago... and its impact on the Bar
Marking one year since a Bar disciplinary tribunal dismissed all charges against her, Dr Charlotte Proudman discusses the experience, her formative years and next steps. Interview by Anthony Inglese CB