Select Page

By Mandy Hargun – Privacy Lawyer & Data Protection Specialist

April 2026

At Authorising Officer level, decisions must be lawful, necessary, proportionate, and capable of withstanding scrutiny.

In practice, that standard is not always met, not because the legislation is misunderstood, but because it is not applied properly at the point decisions are made.

This becomes clear when looking at how authorisations are constructed. Many applications assert necessity without demonstrating it. The rationale is often thin, relying on general statements rather than a clear, evidence-based explanation of why the activity is required.

For an Authorising Officer, this is the first point of failure. The role is not to accept the application at face value, but to apply the legal test independently. If necessity is not properly established, any resulting intrusion into private life and any data obtained, lacks a lawful purpose.

Proportionality

Proportionality is where decisions often begin to drift.

It is common to see authorisations that are too broad whether in scope, duration, or the range of activity permitted. Investigations extend beyond their original purpose or include tactics that have not been properly justified.

From a RIPA perspective, this fails the proportionality test. From a data protection perspective, it results in excessive processing. The outcome is the same: the activity becomes difficult, if not impossible, to defend if challenged.

Collateral intrusion and third-party risk

Collateral intrusion is frequently acknowledged but rarely explored in sufficient detail.

In reality, this is where much of the risk sits. Where there is a likelihood of obtaining third-party data, there must be a clear assessment of impact and a strategy to minimise intrusion.

Without that, the authorisation may appear compliant on paper but will not withstand scrutiny. This is exactly the type of issue that attracts attention during inspection or disclosure.

The authorisation must stand alone

A common weakness is over-reliance on the application itself, with the authorisation acting as little more than an endorsement.

This creates a significant vulnerability.

An authorisation must stand on its own. It should clearly articulate the rationale, reflect the intelligence case, and demonstrate that the legal tests have been properly applied. If it cannot do that, it will not withstand challenge.

Data protection is decided at authorisation

Data protection is often treated as something that happens after the activity focused on storage, retention, or disclosure. By that stage, the key decision has already been made.

The Authorising Officer has determined what data will be obtained and how intrusive the activity will be. If those decisions are not properly justified at the outset, no downstream process can correct them.

Bridging RIPA and data protection in practice

The connection between RIPA and data protection is not theoretical, it is operational.

A well-reasoned authorisation will naturally satisfy both frameworks. Necessity, proportionality, and accountability are shared principles. When applied properly, they underpin lawful and defensible investigative practice.

The challenge is that these skills are not developed through policy alone. Guidance can explain the law, but it does not teach Authorising Officers how to apply it in real scenarios, particularly where decisions are complex or time-sensitive.

How The Signature Brand can support you

In practice, most issues are not caused by a lack of awareness, but by a lack of applied confidence in decision-making.  This is where targeted, practical support makes a difference.

We can work with Applicants, Gatekeepers, Authorising Officers and investigative teams from all organisations to strengthen decision-making through:

  • Scenario-based training focused on real-world applications.
  • Authorisation reviews to identify common weaknesses and improve quality.
  • Risk assessment frameworks to support consistent and defensible decisions.
  • Case-based discussions to explore proportionality, necessity, and intrusion in context.
  • Examination of data protection issues in relation to product management.

The focus is not on theory, but on developing the ability to apply the law clearly and confidently in operational settings.

In conclusion, RIPA and data protection do not fail independently. They fail at the same point; the moment an Authorising Officer approves activity that cannot be properly justified.

Everything that follows is simply a consequence of that decision.

Call us now on 0203 883 5843 or email info@thesignaturebrand.co.uk to discuss how we can assist you.

 

 

Image courtesy of Brett Jordan - Unspalsh