I think it comes down to common sense - something that the act does not exhibit here. If you are going to say something in a reference that can be substantiated, go ahead and say it. If it cannot be substantiated, do not say it at all. Under those circumstances it doesn't matter whether you, as issuer of the reference, withhold or not (nor has it ever mattered, because the person can obtain the reference from the recipient). If there is a real and present danger to the issuer from the individual, do not offer any form of reference. I worked at one time for an organisation whose sole reference for all employees is simply to confirm dates, job title and pay. There was no comment on whether they left under a cloud or their leaving was regretted. Bailey, Trish wrote: > > Sorry I have confused the hell out of all of you now. The DPA > exemption I referred to only applies to the Data Controller providing > the reference and not the recipient organisation. Therefore, as a > recipient organisation and ICO recommendations what have others done, > have you released or withheld and if you have withheld under what in > the DPA did you withhold under? > > > > Sorry for not making myself clear the first time around. > > > > Many thanks > > Regards > > */trish/* > > Trish Bailey > -- ------------------------------------------------------------------------ *Tim Trent* - Consultant */Tel/*: +44 (0)7710 126618 */web/*: ComplianceAndPrivacy.com <http://complianceandprivacy.com> - where busy executives go to find the news first */personal blog/*: timtrent.blogspot.com/ <http://timtrent.blogspot.com/> Marketing by Permission <http://feeds.feedburner.com/%7Er/MarketingByPermission/%7E6/1> *Important*: This message is private and confidential. If you have received this message in error, please notify us and remove it from your system. This email and any attachment(s) are believed to be virus-free, but it is the responsibility of the recipient to make all the necessary virus checks. This email and any attachments to it are copyright of Meadowood Associates, owners of Compliance And Privacy, unless otherwise stated. Their copying, transmission, reproduction in whole or in part may only be undertaken with the express permission, in writing, of Meadowood Associates, at Meadowood House, 30 Redditch, Bracknell, Berkshire, RG12 0TT. ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ All archives of messages are stored permanently and are available to the world wide web community at large at http://www.jiscmail.ac.uk/lists/data-protection.html If you wish to leave this list please send the command leave data-protection to [log in to unmask] All user commands can be found at http://www.jiscmail.ac.uk/help/commandref.htm Any queries about sending or receiving messages please send to the list owner [log in to unmask] Full help Desk - please email [log in to unmask] describing your needs To receive these emails in HTML format send the command: SET data-protection HTML to [log in to unmask] (all commands go to [log in to unmask] not the list please) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^