First-tier Tribunal
(General Regulatory Chamber)
Information Rights
Appeal Reference: EA/2019/0407
Decided without a hearing on:
13 October 2020
Before
JUDGE SOPHIE BUCKLEY
JEAN NELSON
MICHAEL JONES
Between
NHS BUSINESS SERVICES AUTHORITY
Appellant
and
THE INFORMATION COMMISSIONER
First Respondent
and
DAVID SPIVACK
Second Respondent
DECISION
1. For the reasons set out below the appeal is dismissed.
MODE OF HEARING
1
1. The parties and the Tribunal agreed that this matter was suitable for
determination on the papers in accordance with rule 32 Chamber’s Procedure
Rules.
REASONS
Introduction
1. This is an appeal against the Commissioner’s decision notice FS50832217 of 7
October 2019 which held that the NHS Business Services Authority (the
NHSBSA) was not entitled to rely on s 40(2) and s 41(1) of the Freedom of
Information Act (FOIA) to withhold the information.
2. The Commissioner required the NHSBSA to disclose the withheld information.
Factual background to the appeal
3. The NHSBSA provides support services to the NHS in England and Wales. Its
functions include the administration of prescription services. The request
relates to the prescription of Diacomit, a medication used to treat epilepsy, in
particular severe myoclonic epilepsy in infancy (Dravet syndrome). The active
ingredient is Stiripentol. The request was made by Mr. Spivack on behalf of his
pharmaceutical company.
4. The withheld information is the dispenser name (the name of the business that
fulfilled the prescription) and the dispenser code (a code allocated to an
individual dispenser) where the total number of items dispensed was below 5.
5. NHS data linking the dispenser code with the name and address of the
dispenser is publicly available.
Request and Decision Notice
The Request
6. Mr Spivack made the request which is the subject of this appeal on 16 January
2019:
Please can we have a re-run of request number 7568 (relating to the dispensing of
Stiripentol (Diacomit) for the period February 2018 to the latest available.
7. Request number 7568 refers back to a previous request, which itself refers back
to a previous request and so on. The substantive request is found in request
number 4629 which asked for the following information
2
A list of dispensaries (by dispensary code only) which have dispensed the following products ,
along with prescription items, cost and quantity for each dispenser by individual month from
May 2013 to the latest available month: Diacomit (Stiripentol) coded as 0408010AGAAAAAA
0408010AGAAABAB 0408010AGAAACAC 0408010AGAAADAD 0408010AGBBAAAA
0408010AGBBABAB 0408010AGBBACAC 0408010AGBBADAD.
The Response
8. NHSBSA replied to the request on 13 February 2019, confirming that it held
information within the scope of the request. It refused to supply data for
February 2018 under s 14(2) (repeat requests). In relation to the data for March
2018 to November 2018 the NHSBSA supplied the requested information
where the total number of items was five or over but refused to provide the
dispenser code and the dispenser name where the total number fell below five
relying on s 40(2) of the FOIA (personal information).
9. The NHSBSA carried out an internal review and upheld the original decision
on 12 March 2019, relying in addition on s 41(1) FOIA (information provided
in confidence).
10. Mr Spivack complained to the Commissioner on 18 March 2019.
The Decision Notice
11. In a decision notice dated 7 October 209 the Commissioner concluded that the
information did not fall within the definition of ‘personal data’ in s 3(2) of the
Data Protection Act (DPA), because she was not convinced that the combined
addresses of the prescriber and dispenser of epileptic medicine would lead to
the identification of the patient collecting the prescription, and therefore
NHSBSA could not rely on s 40.
12. In relation to s 41 the Commissioner was not satisfied that the withheld
information has the necessary quality of confidence, nor that it was imparted
in circumstances importing the obligation of confidence. The reason for this
conclusion was the information identifies the dispenser and not the patient.
The Commissioner held that it was ‘difficult to see’ how a motivated intruder
would locate the patient and provide detrimental impact in the way the
NHSBSA suggests. Therefore s 41 was not engaged.
Grounds of Appeal
13. The Grounds of Appeal in summary are:
Ground 1 – personal data
3
14. The withheld information related to a person who was identifiable in the
requisite sense.
Indirect identification
15. Identification could realistically be achieved by combining the withheld
information with other publicly available information, including in particular:
a) NHS data identifying what medicines were prescribed by each NHS
practice (organised by code) and how many times they were prescribed;
and
b) NHS data linking NHS practice codes with the names and addresses of
that practice.
16. There is a reasonable likelihood that the information could be linked with
media reports or social media postings as well as other persons’ knowledge of
the underlying data subjects in what could be pinpointed as a relatively small
geographical area. A motivated intruder would have at least two geographic
reference points with which to attempt identification which establishes a
reasonable likelihood of them ascertaining an individual’s identity. There is
currently considerable motivation to identify epilepsy patients because of
interest in new cannabis-based medicine for epilepsy. There is a substantial
prospect, which is more than an insignificant risk, of a motivated intruder
attempting and succeeding in identification.
Individuation
17. Stiripentol was dispensed just 1,884 times by up to 1,779 different dispenses
across England between March and November 2018. There is accordingly a
very real prospect that individuals taking Stiripentol could be singled out from
this data.
18. Individuals are identifiable either on the basis that they could be indirectly
identified from public data sources, or alternatively that the numbers of
persons taking Stiripentol are so small that the information falling within the
request would facilitate the singling out of the relevant individuals.
Breach of data protection principles
19. Disclosure of the withheld information would have breached the data
protection principles. There is no relevant legitimate interest strong enough to
outweigh the interests/fundamental rights of the data subjects. In any event
disclosure would have involved the processing of special category data; would
have been unlawful because it contravened the duty of confidence and would
be unfair.
Ground 2 – the confidential information exemption applies
4
20. The information had the necessary quality of confidence. The Commissioner
erred in concluding that the withheld information could not be linked to any
identifiable individuals. Further, the Commissioner should have had regard to
the information falling within the request as a whole when considering
whether the withheld information had the necessary quality of confidence,
rather than considering the withheld information in isolation.
21. The information was imparted in circumstances importing an obligation of
confidence. The Commissioner failed correctly to assess the risk of
identification and focussed on the withheld information in isolation from the
rest of the information disclosed. The Commissioner failed to ask whether the
withheld information, viewed together with the disclosed information, was
imparted in circumstances importing an obligation of confidence. Paragraph
42 shows that she would have concluded that it was.
22. If the patients were identifiable, disclosure would be of detriment to the
patients.
The Commissioner’s response
23. The NHSBA has not established the likelihood that specific patients would be
identifiable from the disclosure of the location of dispensers of Stiripentol in
cases where fewer than 5 items of this drug have been dispensed in a month.
The NHSBA does not explain how a motivated intruder would be able to
ascertain that a particular patient had been prescribed Stiripentol from a
particular dispensary by combining:
a) the information that the items were dispensed in a relatively small
geographic area with
b) the identification, from social media, of patients in that area who suffer
from epilepsy and may therefore be prescribed Stiripentol.
24. The nature of the withheld information, whether considered in isolation or
with the other requested information is not confidential in nature. The only
basis on which it may be said to have a quality of confidence is if it is combined
with information which enables identification of individuals.
Mr Spivack’s response
25. Mr. Spivack supported the Commissioner’s response. In addition he makes the
following points.
26. The request was made on behalf of Mr. Spivack’s pharmaceutical company. It
has no wish to obtain information which might constitute patient details.
Prescription medicines cannot be promoted to the public.
5
27. The withheld information has been consistently provided to Mr. Spivack since
March 2016. Responses to the earlier requests remain available online.
28. On 28 January 2018 NHSBSA published 5 years’ worth of prescription data by
prescription code, giving dispenser details for all prescribed drugs including
data where fewer than 5 items were dispensed on a monthly basis.
29. The NHSBSA has since late 2018 adopted an apparent policy of refusing
dispensing data where fewer than five (or sometimes ten) items were
dispensed on a monthly basis whether or not there is heightened media interest.
30. The NHSBSA does not apply the same approach to prescribing data (the
equivalent data for the organisation where it was prescribed, e.g. the GP
practice, rather than where it was dispensed. In the FAQs accompanying such
data online, it is stated that “You can't...[i]dentify individual patients, even
those receiving medication for rare conditions, because no patient data is
contained in the data”
31. The HNSBSA has not provided evidence to support its assertion that patients
are identifiable. It is practically impossible using the publicly available data to
associate the location of the prescribing organisation for any individual
prescription with the location of the dispensing organisation. Even if both the
dispensing and prescribing location could be linked with respect to a particular
prescription, it would still not be possible to identify an individual from it. The
accuracy and timeliness of the data set further reduces the likelihood of any
patients and their current location being identified.
32. NHSBSA’s concern about increased media interest in epileptic patients due to
the availability of alternative cannabis based treatments is irrelevant to
whether the data is disclosive of patient identities.
33. In summary, the risk of identification is insignificant in reality, as is the
possibility of individuating an individual from the withheld information.
NHSBSA’s reply
Personal data
34. It is not disputed that if the withheld data is personal data, then it is exempt
from disclosure under s 40(2) FOIA. The pivotal issue is whether an individual
patient or patients would be identifiable from the withheld information, taken
together with any other information that could reasonably be utilised by
someone seeking to identify the patient. The applicable test is a reasonable
likelihood of identification rather than a certainty of identification.
6
35. NHSBSA maintains that a motivated intruder would be reasonably likely to
succeed in identifying the relevant patient(s), given that:
a) There may be highly motivated intruders seeking to ascertain the identity
of patients given the considerable levels of interest in the use of
medications that treat epilepsy.
b) An individual is likely to collect prescribed medication from a pharmacy
near to their home, school, work or some other location with which those
known to them would associate them.
c) There are likely to be circumstances in which a number of others are aware,
for good reason, about an individual’s medical condition.
d) A motivated intruder would be reasonably likely to combine it with what
they already know in order to gain knowledge of or draw reliable
inferences about the medication an individual is taking for their condition.
This is all the more so given that a proportion of the withheld information
concerns a single instance of Stiripentol being dispensed within a given
month, so that there is a 1:1 correspondence between the item and an
individual patient.
e) The Commissioner erred in applying an impermissibly high threshold
(‘would’ identify rather than a reasonable likelihood) and/or in focussing
on how a member of the public who knows nothing about an individual
patient could utilise the withheld information. Account should be taken of
what the withheld information would be likely to reveal to those who start
of with some knowledge of the data subject.
36. NHSBSA has changed its approach in the light of input from statisticians about
the risk of identification.
37. The practice of releasing data in relation to prescribing medication is under
review because of the risk of identification. Further there is greater public
interest in transparency about prescriptions. In any event, the disclosure of one
dataset that entails an identification risk does not justify the disclosure of
another.
38. Disclosure is to the public at large, not just to Mr. Spivack and its company.
The public at large includes persons motivated to identify patients and who
are reasonably likely to succeed in doing so, in particular if they start off with
some knowledge about the patient’s condition.
S 41
7
39. The Commissioner’s argument that no duty of confidence attaches to a
dispenser’s name and code alone is wrong (in that it ignores the need to assess
that information in its context), but is also beside the point. If NHSBSA were to
make publicly available information that risked identifying the patients to
whom it relates, that would constitute an actionable breach of confidence.
NHSBSA’s final closed submissions
40. There is ample information online about those experiencing Dravet’s
syndrome and who are therefore potential users of Stiripentol or a cannabis-
based alternative can be found. This includes peoples’ names, the treatments
they receive and the geographical areas in where they live. A substantial body
of publicly available information exists concerning the postcode district of a
person and the postcode of a dispenser and their specific location. Accessing
this information is simple and free.
41. Where the information reveals that a named individual with Dravet’s
syndrome lives in a particular postcode district, that person is likely to be the
patient (or the parent of the patient with the same surname) who received the
medicine that was prescribed and/or dispensed in that same postcode district.
42. The closed submissions give specific examples of this.
43. It cannot be said that the prospects of identities of Stiripentol users being
ascertained by means reasonably likely to be used by a motivated intruder
could appear “in reality to be insignificant”.
44. The NHSBSA submits that it has demonstrated that a considerable body of
accessible information exists in the public domain which, if utilised by a
motivated intruder in conjunction with the withheld information gives rise to
the reasonable likelihood of identification of one or more patients.
Evidence
45. We have read an open and a closed bundle of documents, which we have taken
account of where relevant.
46. We read a statement on behalf of NHSBSA from Joseph Hamed, a statistician
employed in the NHSBSA. Part of his witness statement is closed.
47. His evidence was that cells with an item count of one (and, with less certainty,
other low numbers) relate to a single person. If this information could be
combined with other information then the identity of the person who received
the item can be revealed.
48. He sets out publicly available information which shows that it is possible to
identify that a named individual has Dravet syndrome and lives in a particular
8
geographical area. It is also possible to identify the address of the Dispenser.
On this basis it is possible to identify a ‘likely match’.
49. The match is only likely because:
a) another patient could potentially receive medication from this dispenser,
b) the ‘likely match’ could potentially receive medication from other
neighbouring dispensers,
c) the likely match may receive a different treatment or receive treatment
dispensed from, for example, a hospital
d) the likely match may not have received NHS treatment – they may have
been treated privately.
50. The ‘likely match’ made by Mr. Hamed, was confirmed as correct by using
personal identifiable information held by NHSBSA.
51. It is possible that other corroborating information is publicly available, for
example the information could be combined with publicly available practice
level prescribing information to obtain a different shortlist, which when
matched could potentially achieve a greater degree of certainty.
52. Mr. Hamed gave evidence about the likelihood of Stiripentol being prescribed
and dispensed in the same geographical area. Broadly this showed that 64% of
Stiripentol prescription items were dispensed from within the same postcode
district.
53. Other sources might be available to family members, acquaintances, colleagues,
or customers who overhear or read information not intended for them, for
example, people might be present in the clinic when Stiripentol was prescribed,
or in the dispenser when it was dispensed, or might overhear a conversation
to this effect.
54. Mr. Hamed sets out a number of hypothetical motivations for intruders to seek
to identify patients.
55. Mr. Hamed states that the risk of identification that includes single instances
of activities or items that relate to one person is generally considered to be large
and it is common to redact or round small numbers to reduce this risk.
56. The NHSBSA prescriptions data is a near ‘population level’ dataset, including
records relating to around 40 million people in a typical year. It is more than
likely that one or other of the data subjects will have some information or
circumstances that could reveal their personal information in ways that they
might not expect. The best practical way to derive as much value from data as
possible and offer as much to the public as possible is to use small data
suppression and other forms of statistical disclosure control.
9
57. Mr Hamed accepts that the level of detail requested in this case is no more
detailed than that included in other datasets already published. The release of
those datasets involves the parties knowingly taking on a risk of re-
identification. The NHSBSA is not in a position to make such a judgment as
part of responding to each FOIA request.
58. Mr. Hamed considered the risk of the releasing the entire dataset in relation to
dispensing information in the level of detail requested taken together with the
prescription information dataset which is already in the public domain. The
detailed prescribing information that is released shows that 2,611 items were
only prescribed once in England in a month. This means that the dataset
effectively reveals information about the prescribing organisation for the
patients who received those items to anyone who knows the product they were
prescribed. If dispenser information were released at the same level of detail,
a link could be made to establish the dispenser used by those people.
Approximate links could also be made if they made assumptions about the
proximity of prescribing and dispensing organisations.
Legal framework
S 40 – personal Information
59. The relevant parts of s 40 of FOIA provide:
(1) Any information to which a request for information relates is exempt
information if it constitutes personal data of which the applicant is the data
subject.
(2) Any information to which a request for information relates is also exempt
information if –
(a) It constitutes personal data which does not fall within subsection (1), and
(b) either the first, second or the third condition below is satisfied.
(3A) The first condition is that the disclosure of the information to a member of the
public otherwise than under this Act -
(a) would contravene any of the data protection principles, or..,
60. Personal data is defined in s 3(2) of the Data Protection Act 2018 (DPA) as:
Any information relating to an identified or identifiable living individual
a) Under article 4(1) GDPR an ‘identifiable’ person is defined as:
one who can be identified, directly or indirectly…
61. The use of the word ‘indirectly’ means that it is not necessary that the
information alone allows the data subject to be identified. (Breyer v Federal
Republic of Germany (Case C-582/14) [2017] 1 WLR 1569. Account should be
10
taken of all the means reasonably likely to be used to identify the data subject .
This is set out in recital 26 of the General Data Protection Regulation (‘GDPR’)
which provides:
The principles of data protection should apply to any information concerning an
identified or identifiable natural person. Personal data which have undergone
pseudonymisation, which could be attributed to a natural person by the use of
additional information should be considered to be information on an identifiable
natural person. To determine whether a natural person is identifiable, account
should be taken of all the means reasonably likely to be used, such as singling out,
either by the controller or by another person to identify the natural person directly
or indirectly. To ascertain whether means are reasonably likely to be used to
identify the natural person, account should be taken of all objective factors, such as
the costs of and the amount of time required for identification, taking into
consideration the available technology at the time of the processing and
technological developments. The principles of data protection should therefore not
apply to anonymous information, namely information which does not relate to an
identified or identifiable natural person or to personal data rendered anonymous
in such a manner that the data subject is not or no longer identifiable. This
Regulation does not therefore concern the processing of such anonymous
information, including for statistical or research purposes.
62. When assessing whether a particular means was reasonably likely to be used,
the court in Breyer said that it would not be the case if the identification of the
data subject was, for example, prohibited by law or practically impossible on
account of the fact that it required a disproportionate amount of time, cost and
man-power so that the risk of identification appears in reality to be
insignificant.
63. We adopt and apply the following summary of the law by Upper Tribunal
Judge K Markus QC in The Information Commissioner v Miller [2018] UKUT
229 (AAC) at paragraphs 10-16. Although it relates to the pre-GDPR position
our view is that it applies equally under the new law:
1. The correct approach to the application of section 1(1)(b) to disclosure of
anonymised data was addressed by the House of Lords in Common
Services Agency v Scottish Information Commissioner [2008] 1 WLR 1550.
That decision was discussed by the Administrative Court in R (Department
of Health) v Information Commissioner [2011] EWHC1430 (Admin).
Cranston J explained that the House of Lords had decided that, even though
the data controller holds the key to identification of individuals to which the
data relates, whether it is personal information when disclosed depends on
“whether any living individuals can be identified by the public following
disclosure of the information” (paragraph 52). In Information
Commissioner v Magherafelt District Council [2013] AACR 14 the Upper
Tribunal said that the decision in Department of Health meant that the
proper approach to whether anonymised information is personal data
within section 1(1)(b), for the purposes of a disclosure request, is to consider
whether an individual or individuals could be identified from it and other
11
information which is in the possession of, or likely to come into the
possession of a person other than the data controller after disclosure.
2. In the Department of Health case Cranston J said at paragraph 66 that the
assessment of the likelihood of identification included
“assessing a range of every day factors, such as the likelihood that particular
groups, such as campaigners, and the press, will seek out information of
identity and the types of other information, already in the public domain,
which could inform the search.”
3. As for the likelihood of identification, Recital 26 of the preamble to the
Directive provides that “account should be taken of all the means likely
reasonably to be used”. In Magherafelt the Upper Tribunal acknowledged
the “motivated intruder” test advanced by the Information Commissioner:
“37 ...A ‘motivated intruder’ was ‘...a person who starts without any prior
knowledge but who wishes to identify the individual or individuals
referred to in the purportedly anonymised information and will take all
reasonable steps to do so.’. The question was then one of assessment by a
public authority as to ‘... whether, taking account of the nature of the
information, there would be likely to be a motivated intruder within the
public at large who would be able to identify the individuals to whom the
disclosed information relates.’
4. While not expressly adopting that test, the approach of the Upper Tribunal
in that case was consistent with it. A similar approach was taken by the
Court of Session (Inner House) in Craigdale Housing Association v The
Scottish Information Commissioner [2010] CSIH 43 at paragraph 24:
“...it is not just the means reasonably likely to be used by the ordinary man
on the street to identify a person, but also the means which are likely to be
used by a determined person with a particular reason to want to identify
the individual...using the touchstone of, say, an investigative journalist...”
5. The Information Commissioner’s Code of Practice on “Anonymisation:
managing data protection risk” provides guidance at page 22/23 on the
application of the “motivated intruder” test:
“The approach assumes that the ‘motivated intruder’ is reasonably
competent, has access to resources such as the internet, libraries, and all
public documents, and would employ investigative techniques such as
making enquiries of people who may have additional knowledge of the
identity of the data subject or advertising for anyone with information to
come forward. The ‘motivated intruder’ is not assumed to have any
specialist knowledge such as computer hacking skills, or to have access to
specialist equipment or to resort to criminality such as burglary, to gain
access to data that is kept securely.”
6. The guidance also addresses the risk of re-identification where one
individual or group of individuals already knows a great deal about another
12
individual, such as a family member, colleague or doctor, and says at page
26:
“The starting point for assessing re-identification risk should be recorded
information and established fact. It is easier to establish that particular
recorded information is available, than to establish that an individual – or
group of individuals - has the knowledge necessary to allow re-
identification. However, there is no doubt that non-recorded personal
knowledge, in combination with anonymised data, can lead to
identification. It can be harder though to substantiate or argue convincingly.
There must be a plausible and reasonable basis for non- recorded
personal knowledge to be considered to present a significant re-
identification risk.” (my emphasis)
7. The guidance also distinguishes between identification and an educated
guess:
“[Identification] implies a degree of certainty that information is about one
person and not another. Identification involves more than making an
educated guess that information is about someone; the guess could be
wrong. The possibility of making an educated guess about an individual’s
identity may present a privacy risk but not a data protection one because
no personal data has been disclosed to the guesser. Even where a guess
based on anonymised data turns out to be correct, this does not mean that
a disclosure of personal data has taken place.”
64. Personal data must be processed ‘lawfully and fairly’ and one of the lawful
bases of processing in article 6(1) must apply. The only potentially relevant
basis here is article 6(1)(f):
Processing is necessary for the purposes of the legitimate interests pursued by the
controller or by a third party, except where such interests are overridden by the
interests or fundamental rights and freedoms of the data subject which requires
protection of personal data, in particular where the data subject is a child.
65. The case law on article 6(1))(f)’s predecessor established that it required three
questions to be answered, which we consider are still appropriate if reworded
as follows:
1. Is the data controller or a third party pursuing a legitimate interest or
interests?
2. Is the processing involved necessary for the purposes of those interests?
3. Are the above interests overridden by the interests or fundamental rights
and freedoms of the data subject?
S 41 – information provided in confidence
66. S 41 provides, so far as relevant:
13
S 41 – Information provided in confidence
(1) Information is exempt information if –
(a) it was obtained by the public authority from any other person (including
another public authority), and
(b) the disclosure of the information to the public (otherwise than under this Act)
by the public authority holding it would constitute a breach of confidence
actionable by that or any other person.
67. The starting point for assessing whether there is an actionable breach of
confidence is the three-fold test in Coco v AN Clark (Engineers) Ltd [1969]
RPC 41, read in the light of the developing case law on privacy:
a) Does the information have the necessary quality of confidence?
b) Was it imparted in circumstances importing an obligation of confidence?
c) Is there an unauthorised use to the detriment of the party communicating
it?
68. The common law of confidence has developed in the light of Articles 8 and 10
of the European Convention on Human Rights to provide, in effect, that the
misuse of ‘private’ information can also give rise to an actionable breach of
confidence. If an individual objectively has a reasonable expectation of privacy
in relation to the information, it may amount to an actionable breach of
confidence if the balancing exercise between article 8 and article 10 rights
comes down in favour of article 8.
69. S 41 is an absolute exemption, but a public interest defence is available to a
breach of confidence claim. Accordingly there is an inbuilt balancing of the
public interest in determining whether or not there is an actionable breach of
confidence.
The Task of the Tribunal
70. The tribunal’s remit is governed by s.58 FOIA. This requires the tribunal to
consider whether the decision made by the Commissioner is in accordance
with the law or, where the Commissioner’s decision involved exercising
discretion, whether she should have exercised it differently. The tribunal may
receive evidence that was not before the Commissioner and may make
different findings of fact from the Commissioner.
Issues
71. The issues we have to determine are as follows:
Personal Data
1. Is the disputed information personal data?
2. Would the release of that information be lawful and fair?
14
Section 41
3. Would disclosure have amounted to an actionable breach of confidence?
Discussion and conclusions
Is the disputed information personal data?
What is the appropriate threshold test for indirect identification?
72. It is submitted on behalf of NHSBSA that the correct threshold is whether an
individual is reasonably likely to be identified having regard to the means of
identification reasonably likely to be used. Where such means exist, and
identification is a possibility, then the data is personal data.
73. In our view it is important to be precise when considering to what the phrase
‘reasonably likely’ applies. The question is whether a person can be identified
having regard to the means of identification reasonably likely to be used. As the
Upper Tribunal observes in Miller at para 28 this is not necessarily the same in all
cases as asking whether there is a “reasonable likelihood” of identification.
74. Further, even if the question can appropriately be framed as ‘whether an individual
is reasonably likely to be identified’ care must be taken to ensure that ‘identified’ is
given the appropriate meaning. The question for the tribunal is not whether a
person is reasonably likely to correctly guess the individual referred to in the data.
It must ask whether a person is reasonably likely to be able to identify the individual.
75. Looking at the test as set out in recital 26, we must determine if the individual can
be identified, i.e. we must ask if is possible to distinguish a specific individual from
others, taking account of all the means reasonably likely to be used by any person
to identify the natural person.
76. If, by ‘identification is a possibility’ NHSBSA means that it is possible, on the basis
of the available data, to distinguish a specific individual from others then that is, in
the tribunal’s view, a correct statement of the law. If NHSBSA mean that the
threshold is passed if it is possible that somebody may correctly guess the
individual concerned, then we disagree.
77. It is when considering if it is possible to distinguish a specific individual from others
that a degree of certainty as to the particular individual is required. The available
information must allow one individual to be distinguished from others, otherwise
they cannot be identified.
15
78. NHSBSA also submit that the threshold is passed unless it can be said that the
prospect of the identities of Stiripentol users being ascertained by means reasonably
likely to be used by a motivated intruder could not appear “in reality to be
insignificant”, relying on R (Bridges v Chief Constable of South Wales Police
[2020] 1 WLR citing Breyer.
79. We note that it was in the context of identifying the means ‘reasonably likely to be
used’ that the CJEU in Breyer said, at paras 45 and 46:
…it must be determined whether the possibility to combine a dynamic IP address with
the additional data held by the internet service provider constitutes a means likely
reasonably to be used to identify the data subject.
46. Thus ... that would not be the case if the identification of the data subject was
prohibited by law or practically impossible on account of the fact that it requires a
disproportionate effort in terms of time, cost and man-power, so that the risk of
identification appears in reality to be insignificant.
80. The divisional court in Bridges observes, obiter, at para 118 that in Breyer ‘the only
incidents excluded were where the risk of identification “appears in reality to be
insignificant”’. 1
81. It does not necessarily follow from the finding in Breyer (that an insignificant risk
in reality of identification would not suffice) that anything more than an
insignificant risk in reality of identification would suffice. The word ‘only’ appears
in Bridges not in Breyer.
82. In any event, it is important to remember that this phrase was used in the context
of determining whether a means was reasonably likely to be used. This is the
statutory wording and the wording that we must apply.
83. Further, for the reasons set out above, Bridges and Breyer are not authority for the
proposition that the tribunal should ask, taking account of all the means reasonably
likely to be used, whether there is, in reality, more than an insignificant risk of a
motivated intruder correctly guessing the name of the individual whose data is in
the withheld information. The question in Breyer was whether there was more than
an insignificant risk of getting to the point at which one individual had access to all
the relevant data. There was no question that the individual would be identifiable,
in the sense that it would be possible to distinguish a specific individual, once that
point was reached (see para 37).
Application of the law to the facts
1 The observation in Bridges was obiter because the Divisional Court reached the decision on the basis of individuation not indirect
identification.
16
84. Based on the legal principles set out above, we must consider if it is possible to
distinguish a specific individual from others, taking account of all the means
reasonably likely to be used by any person to identify that natural person.
85. We accept that is it appropriate to consider what means a ‘motivated intruder’
would be reasonably likely to use in these circumstances. We accept that, for
example, an individual who wanted to market alternative cannabis-based
treatments for epilepsy would be prepared to undertake the steps below.
86. We find that it is reasonably likely that a motivated intruder would use the
information available on the internet to find out the names of individuals with
Dravet syndrome. We find that it is reasonably likely that a motivated intruder
would use the information available on the internet to find out the geographical
area in which those individuals’ live. Further a motivated intruder is reasonably
likely to use the information published about dispensers to identify the address of
the dispenser of Stiripentol. Further we accept that, for a number of legitimate
reasons, the fact that a particular individual used Stiripentol might be personally
known to a motivated intruder.
87. We do not accept that we are entitled to take account of the knowledge of an
individual who might have overheard someone being prescribed Stiripentol in a
doctor’s surgery or in a hospital. We do not accept that we are entitled to take
account of the knowledge of an individual who might have been present in a
pharmacy and witnessed someone picking up a prescription of Stiripentol. We
think that the risk of this person also being a motivated intruder with access to the
above information, or of this information being obtained from them by a motivated
intruder, is in reality, insignificant. We do not accept that there is a plausible and
reasonable basis for the non-recorded personal knowledge of these individuals
being used to identify individuals in the withheld data.
88. Taking all this information together with the withheld information, we do not
accept that it is possible to identify an individual, in the sense of distinguishing a
specific individual from others. The evidence of Mr Hamed was that a ‘likely match’
could be achieved. It was only a ‘likely match’ for a number of reasons identified
by Mr Hamed, including the fact that another patient could potentially receive
medication from this dispenser.
89. We accept that it is not necessary to have absolute certainty for an individual to be
identifiable: for example, on p 13 of the Article 29 Data Protection Working Party’s
Opinion 4/2007 on the concept of personal data (01248/07/EN), the Working Party
acknowledge that a combination of details on a categorical level may also be ‘pretty
conclusive’. Here, though there is a missing piece of the jigsaw which would enable
the data to be linked to the individual with any degree of certainty.
90. We are not considering the release of data that shows that Stiripentol had been
prescribed or dispensed to one individual who lived in a particular postcode area.
17
This could be combined with knowledge that a particular individual with epilepsy
lived in that area to enable a specific individual to be distinguished from others.
Alternatively, if a dataset was publicly available which identified the postcode
areas in which named individuals obtained their prescriptions or collected the
dispensed medicine, this could be combined with the withheld information to
enable a specific individual to be distinguished from others.
91. The information, taken together with any other publicly available information, does
not make it possible to distinguish a specific individual from others, and therefore
no specific individual is identifiable. The data cannot be linked to the individual
with any degree of certainty, because of the reasons set out by Mr Hamed and
summarised in paragraph 49 above. To use the terminology from p21 of the pre-
GDPR ICO Code of Practice on Anonymisation: managing data protection risk
(issued pre-GDPR) we do not accept, even taking account of all the means
reasonably likely to be used, that NHSBS have shown that there would be a ‘reliable
connection’ between the individual and the data, for the reasons set out by Mr
Hamed and summarised in paragraph 49 above.
92. In the absence of this reliable connection we are not satisfied that there is any degree
of certainty that the information is about one individual rather than another. A
person in possession of the withheld data and all the information available by
means reasonably likely to be used could not know that this was the individual to
which the withheld data referred. In effect, this a case where the correct name of the
individual can be reached only through an educated guess. We reach the same
conclusion for the same reasons in relation to individuation – it is not possible to
‘single out’ an individual.
93. Mr Hamed goes on to state that it is possible that publicly available practice level
prescribing information could be used to obtain a different shortlist, which when
matched could potentially achieve a greater degree of certainty. We do not think
that evidence that it is possible that someone could potentially achieve a greater
degree of certainty is sufficient to alter our conclusion set out above.
94. For those reasons we find that the information was not personal data and therefore
the NHSBSA was not entitled to rely on s 40(2).
S 41
95. In our view, if no individual is identifiable from the data, even taken together with
other information in the public domain which is reasonably likely to be used by a
motivated intruder, there can be no actionable breach of confidence. Accordingly
we conclude that NHSBSA was not entitled to rely on s 41.
Conclusion
96. For the reasons set out above the appeal is dismissed. Our decision is unanimous.
18
Signed Sophie Buckley
Judge of the First-tier Tribunal
Date: 9 November 2020
Date issued: 9 November 2020
19