PART 8SInformation

Sensitive informationS

39.—(1) In these Regulations, “sensitive information” means information which is not reasonably accessible to the public and which is–

(a)information the disclosure of which to the public would, or would be likely to, adversely affect national security;

(b)information the disclosure of which to the public would, or would be likely to, adversely affect public safety;

(c)information, disclosure of which to the public would or would be likely to prejudice the commercial interests of the person to whom that information relates; or

(d)information which is personal dataF1... if the condition in paragraph [F2(1A), (1B) or (1C)] is satisfied.

[F3(1A) The condition in this paragraph is that the disclosure of the information to a member of the public—

(a)would contravene any of the data protection principles, or

(b)would do so if the exemptions in section 24(1) of the Data Protection Act 2018 (manual unstructured data held by public authorities) were disregarded.

(1B) The condition in this paragraph is that the disclosure of the information to a member of the public would contravene—

(a)Article 21 of the [F4UK GDPR] (general processing: right to object to processing), or

(b)section 99 of the Data Protection Act 2018 (intelligence services processing: right to object to processing).

(1C) The condition in this paragraph is that—

(a)on a request under Article 15(1) of the [F5UK GDPR] (general processing: right of access by the data subject) for access to personal data, the information would be withheld in reliance on provision made by or under section 15, 16 or 26 of, or Schedule 2, 3 or 4 to, the Data Protection Act 2018,

(b)on a request under section 45(1)(b) of that Act (law enforcement processing: right of access by the data subject), the information would be withheld in reliance on subsection (4) of that section, or

(c)on a request under section 94(1)(b) of that Act (intelligence services processing: rights of access by the data subject), the information would be withheld in reliance on a provision of Chapter 6 of Part 4 of that Act.

(1D) In this regulation—

the data protection principles” means the principles set out in—

(a)

Article 5(1) of the [F6UK GDPR],

(b)

section 34(1) of the Data Protection Act 2018, and

(c)

section 85(1) of that Act;

data subject” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);

F7...

personal data” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(2) and (14) of that Act).

[F8the UK GDPR” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(10) and (14) of that Act);]

(1E) In determining for the purposes of this regulation whether the lawfulness principle in Article 5(1)(a) of the [F9UK GDPR] would be contravened by the disclosure of information, Article 6(1) of the [F9UK GDPR] (lawfulness) is to be read as if the second sub-paragraph (disapplying the legitimate interests gateway in relation to public authorities) were omitted.]

F10(2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

F10(3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

F10(4) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Textual Amendments

Commencement Information

I1Reg. 39 in force at 14.11.2005, see reg. 1