against misuse” and be “subject to rigorous oversight” is made clear (§2.6).
The BPD Handling Arrangements are intended to provide such safeguards
(§2.7) and must be complied with, along with the requirements of the
information gateway provisions:
“Staff must ensure that no bulk personal dataset is obtained, used, retained or
disclosed except in accordance with the information gateway provisions and
these Arrangements.”
36. The BPD Handling Arrangements apply to BPD “howsoever obtained”, that
is through whichever of the variety of statutory powers by which the
Intelligence Services are entitled to obtain it (§§2.8-2.9) without prejudice to
“additional applicable statutory requirements” which apply in the case of
some statutory powers (§2.9).
37. The BPD Handling Arrangements set out provisions in respect of each of the
stages of the lifecycle of a Bulk Personal Dataset.
Authorisation and Acquisition
38. The key requirements on staff of the Intelligence Services before obtaining
BPD are set out at §4.2:
“based on the information available to them at the time, staff should always:
be satisfied that the objective in question falls within the Service’s statutory
functions;
be satisfied that it is necessary to obtain and retain the information
concerned in order to achieve the objective;
be satisfied that obtaining and retaining the information in question is
proportionate to the objective;
be satisfied that only as much information will be obtained as is necessary
to achieve that objective.”
39. Clear guidance is provided to staff on the considerations of necessity and
proportionality:
“When will acquisition be “necessary”?
4.3 What is necessary in a particular case is ultimately a question of fact and
judgement, taking all the relevant circumstances into account. In order to meet
the ‘necessity’ requirement in relation to acquisition and retention, staff must
consider why obtaining the bulk personal dataset is ‘really needed’ for the
purpose of discharging a statutory function of the relevant Intelligence
Service. In practice this means identifying the intelligence aim which is likely
to be met and giving careful consideration as to how the data could be used to
support achievement of that aim.
The obtaining must also be “proportionate”
4.4 The obtaining and retention of the bulk personal dataset must also be
proportionate to the purpose in question. In order to meet the
63