These questions come from conversations with DPOs and in-house counsel over the past year. The UK Supreme Court's decision in ZXC v Bloomberg changed how we think about privacy during criminal investigations, and the effects are still impacting compliance teams. Here's what people are asking.
Do individuals under investigation have privacy rights before charges are filed?
Yes, and the UK Supreme Court made this clear in ZXC v Bloomberg. The court established that individuals have a reasonable expectation of privacy regarding the fact and details of a criminal investigation at the pre-charge stage.
This affects your operations in two ways. First, if you're handling information about ongoing investigations, you can't assume it's public just because law enforcement is involved. The ZXC case involved a regional CEO whose company was under investigation. Bloomberg published details from a letter between law enforcement agencies. The court found that the investigation details, allegations, and evidence were private information.
Second, this creates a framework for assessing privacy expectations that doesn't depend on whether charges have been filed. You need to evaluate the nature of the information and the context of the investigation.
What if investigation details came from a leaked official document?
The source of the information doesn't automatically override privacy rights. In ZXC v Bloomberg, the information came from a confidential law enforcement letter. Bloomberg argued that because the information originated from an official document and concerned potential criminal conduct, it should be publishable. The Court of Appeal and Supreme Court rejected this argument.
For your team, this means you can't rely on "it's already out there" or "it came from an official source" as a defense. If you're processing information about investigations, even if it reached you through a leak or official channel, you still need to assess whether the individual has a reasonable expectation of privacy in that specific information.
The Article 8/10 balancing exercise (privacy rights versus freedom of expression) still applies, but the starting assumption favors privacy at the pre-charge stage.
How should we handle DSARs related to investigation files?
This is where Driver v CPS becomes instructive. The case involved disclosure of a file to a third party, and the court found that personal data can relate to more than one person and doesn't have to relate exclusively to one data subject, particularly when the group is small. In that case, Operation Sheridan involved only eight suspects.
When someone challenges the accuracy of investigation records, you need to understand what "accuracy" means in this context. The AB v Chief Constable of British Transport Police case clarifies this. AB claimed that police records inaccurately stated he'd touched women inappropriately. The initial judge agreed and awarded £36,000 in damages.
On appeal, the court drew a critical distinction: police records are intended to reflect the information provided to police, not necessarily the underlying facts of what happened. The appeal court found the records were accurate as records of what was reported, even if the underlying allegations were disputed.
For your DSAR responses, document clearly whether you're recording what was reported versus what you've verified. If someone challenges accuracy, you're not required to adjudicate the truth of the underlying allegation, but you do need to accurately record the nature of the information you hold.
Can we keep investigation records indefinitely?
No. AB v Chief Constable also addressed retention. Even though the court found the records were accurate, it upheld the finding that retention was a disproportionate interference with AB's Article 8 rights. The individual had autism spectrum disorder and the incidents dated to 2011 and 2014, with no prosecution in either case.
Your retention schedules need to account for the nature of the allegations, the outcome (or lack thereof), and the ongoing impact on the individual. The court awarded £15,000 for distress and £15,000 for loss of earnings, demonstrating that unlawful retention has real consequences.
Build review points into your retention policies. Consider a team that retains investigation files for "as long as operationally useful." That's not a lawful basis for retention under Article 5(1)(e). You need defined periods tied to legitimate purposes, with regular reviews for proportionality.
How should we handle erasure requests based on inaccuracy?
The CJEU's decision in TU and RE v Google LLC sets out your obligations clearly. Where someone submits relevant and sufficient evidence establishing manifest inaccuracy of information, or at least a non-minor part of it, you must grant the erasure request. The same applies if they provide a judicial decision finding the information is, at least prima facie, inaccurate.
But here's the practical threshold: if the inaccuracy isn't obvious from the evidence provided, and there's no judicial decision, you're not required to grant the request. This is particularly true where the information contributes to a debate of public interest. In those cases, freedom of expression carries particular weight.
For your erasure assessment process, document what evidence you received, whether it establishes manifest inaccuracy, and whether the information contributes to public debate. Don't rely on "it might be wrong" as grounds to refuse. Assess the evidence actually provided.
How do we balance privacy rights with legitimate business interests?
Recognize that "we need it for the investigation" isn't the end of the analysis. In Brake v Guy, claimants argued they had privacy expectations in a business enquiries email account containing 3,149 emails. They produced only two emails for the judge to review.
The court found this wasn't sufficient to establish a reasonable expectation of privacy across the entire account. The burden of proof was described as "a very substantial hurdle" which the claimants "fell well short of surmounting."
If you're defending your processing against a privacy claim, the volume and nature of the information matters. But you need to actually assess it. The Brake court wasn't saying business email can never be private; it was saying you can't establish privacy expectations by showing two emails out of thousands and asking the court to assume the rest are similar.
Where should we go for more guidance?
Review your investigation handling procedures against the ZXC framework. Map your retention schedules to ensure you're not holding investigation data longer than proportionate. Update your DSAR response templates to address accuracy challenges using the AB distinction between recording reports versus adjudicating facts. And build the TU and RE erasure assessment criteria into your Article 17 workflows, particularly the distinction between manifest inaccuracy and disputed claims.
The law in this area is developing through case-by-case adjudication. Your compliance framework needs to be specific enough to provide clear guidance to your team, but flexible enough to account for the particular circumstances of each case.



