The 3Million & Anor, R (on the application of) v Secretary of State for the Home Department & Anor
[2023] EWCA Civ 1474
Article 23 UK GDPR permits restrictions on data protection rights if necessary and proportionate to safeguard public interest, but requires specific provisions (Article 23(2)).
UK GDPR, Article 23
Restrictions must be a 'legislative measure' containing specific provisions on purposes, categories of data, scope of restrictions, safeguards against abuse, controller specification, storage periods, risks to data subjects' rights, and the right to be informed.
UK GDPR, Article 23(2); CJEU case law (La Quadrature du Net, SS SIA, Bara, HK v Prokuratuur)
Derogations from fundamental rights must be clear, precise, legally binding, accessible, foreseeable, and provide substantive and procedural safeguards.
CJEU case law
Data protection rights are not 'second-order' rights; right of subject access is crucial.
CJEU case law (YS v Minister voor Immigratie, RW v Österreichische Post AG)
The Immigration Exemption is unlawful.
It fails to comply with Article 23(2) by outsourcing safeguards to a non-legislative policy document (IEPD). Specifically, it lacks sufficient detail regarding safeguards to prevent abuse, and doesn't adequately address risks to data subjects' rights.
[2023] EWCA Civ 1474
[2023] EWHC 1092 (KB)
[2023] UKFTT 819 (GRC)
[2024] EWHC 844 (KB)
[2023] EWHC 791 (Admin)