Prison staff deciding whether they can legally open a prisoner's letter to their lawyer are told to check section 15 of the government's own rulebook. The rulebook stops at section 12.
Estimated reading time: 6 minutes
In short. HMPPS's Interception, Monitoring and Security of Prisoner Communications Policy Framework tells every group it applies to that its Requirements section "contains all mandatory actions" (page 1), then states on the next page that "there are no new mandatory requirements in this policy" and "no impact on the resource of establishments" [2]. Across the 35 pages in between, the word "must" appears 252 times, and at least 22 of the framework's own cross-references point staff to sections numbered 13 to 18, including the clause on legally privileged mail, none of which exist under those numbers anywhere in the document [2]. Three documented mistakes: four stars.
Prison Rule 39 protects a prisoner's post from and to their lawyer: it can only be opened if the governor has reasonable cause to believe it contains something illicit or dangerous, and even then only in the prisoner's presence [2]. The document that is supposed to walk staff through exactly when that line can be crossed is the Interception, Monitoring and Security of Prisoner Communications Policy Framework, published by the Ministry of Justice and HM Prison and Probation Service on 11 August 2026 and last updated 23 September [1]. It governs powers under the Investigatory Powers Act 2016 and the Prison Rules, and the Investigatory Powers Commissioner's Office independently inspects prisons to check those powers are used lawfully [2] [4]. Read the 37-page framework itself and its own signposting cannot get a staff member to the answer.
A policy that is mandatory on page 1 and isn't on page 2
The cover sheet leaves no room for doubt about status: "Mandatory Actions: All groups referenced above must adhere to the Requirements section of this Policy Framework, which contains all mandatory actions" (page 1) [2]. The list of groups bound by it runs to HMPPS headquarters, every governor, every public and contracted prison, young offender institutions, the Probation Service and its contracted providers [2].
Two paragraphs later, under "Resource Impact", the same document says: "There are no new mandatory requirements in this policy. There will be no impact on the resource of establishments" (page 2) [2]. What follows is 35 pages of "must": authorisation forms before restriction or monitoring begins, renewal deadlines every one to three months, 24-hour and 72-hour reporting windows, quarterly error reports to the Commissioner's office, translation of foreign-language calls within 48 hours for the highest-risk prisoners, and an auditable electronic log of every call listened to and every letter read [2]. None of that is free, and the document that lists it as mandatory on its own cover sheet cannot also carry no resource impact.
Section 15 does not exist
The framework's own contents page promises four sections: Purpose, Outcomes, a Requirements section running pages 7 to 36, and Annexes on page 37 [2]. Inside Requirements, the printed sub-headings run from "4.0 The Restriction of Communications" through "12.0 Cohort-Specific Monitoring", then jump straight to two orphaned paragraphs numbered "18.11" and "18.12", followed by "19.1 Sanctions" and "20.1 Criminal Offence" (pages 35-36) [2]. Sections 13 to 17 never appear as headings anywhere in the printed text.
That would be a cosmetic slip if the document did not keep sending staff to those missing sections to do their jobs. Paragraph 9.2 tells staff that certain prisoners are "subject to mandatory live monitoring (see section 17)" (page 19) [2]; section 17 does not exist. Paragraph 11.10 sends staff checking a transferred prisoner's risk status to "section 16.9" (page 29) [2]; there is no section 16. Across the document, paragraphs cite "paragraph 13.5", "section 13", "sections 13 and 16", "section 14.4", "paragraphs 13.16", "paragraph 14.6", "paragraph 14.7" and "paragraph 17.20" for procedures that a reader cannot locate under those numbers, at least 22 times in total [2].
The clearest case sits in the definition staff are meant to use when something goes wrong. Paragraph 9.17 defines unauthorised interception as including "the inadvertent interception (and any subsequent monitoring) of privileged (legal and confidential) communications without authorisation or otherwise in accordance with section 15 of this policy framework" (page 22) [2]. Section 15 is where a member of staff would go to check whether opening a prisoner's legal correspondence was lawful in the first place. It is not in the document.
An update that touched one file in six
The 23 September change note on GOV.UK reads simply: "Annexes A to E updated" [1]. The zip file behind that note contains seven files, not five: current versions of Annexes A, B, C and E, two duplicate documents with "D" guidance, and two leftover files still carrying their old filenames, "Interception PF_Annex_C_-Communication_Compact_Jan24 (2).docx" and "Interception_PF_Annex_A-Official_Notification_to_Prisoner_Form_Jan24.docx" [3]. Each Word file carries its own creation and modification timestamps in its metadata. Only one, Annex B, the Confidential Access List, was actually created and modified on 22 September 2026, the day before the change note. Annexes A, C and E carry unchanged timestamps from September 2022; the two stray "Jan24" files date to December 2023 [3]. "Annexes A to E updated" describes what happened to one annex out of five, in a download that still ships two documents nobody meant to publish.
Credit where due
Set the paperwork bugs aside and the substance underneath is careful, not careless. Almost every operative paragraph pairs its power with an explicit necessity-and-proportionality test tied back to the Human Rights Act and specific Prison Rules, rather than asserting authority and moving on [2]. Under-18s get an explicit instruction that intrusion must weigh their age (paragraph 4.4); non-English speakers get certified translation and a 48-hour deadline for the highest-risk cases rather than being left waiting indefinitely (paragraphs 7.7, 12.13); and automated transcription or translation is expressly barred from being the sole basis for any decision affecting a prisoner, citing section 49 of the Data Protection Act 2018 by name (paragraph 9.14) [2]. Unauthorised interceptions of privileged mail have to be reported to the Central Authorities Bureau within 24 hours and rolled up to the Investigatory Powers Commissioner's Office every three months, a real external check rather than a box-ticking one [2] [4]. The failure here is not the policy's judgement. It is that the document meant to carry that judgement to the prison landing cannot reliably point staff to itself.
The claims, tested
| The claim | What the document shows | Verdict |
|---|---|---|
| "This Policy Framework...contains all mandatory actions" (page 1) [2] | Page 2 of the same document: "There are no new mandatory requirements in this policy. There will be no impact on the resource of establishments" [2] | Contradicted one page later |
| Staff facing an interception decision are directed to "section 15", "section 16", "section 17" and "paragraph 13.5" of this policy framework, at least 22 times [2] | The printed document's headings run 4.0 to 12.0, then jump to orphaned paragraphs 18.11 to 20.1; sections 13 to 17 do not exist [2] | The referenced sections were never written |
| "Annexes A to E updated" (GOV.UK change note, 23 September 2026) [1] | Document metadata inside the zip shows only Annex B was created or modified that week; two files are still dated December 2023 [3] | One annex out of five, plus stray files |
Three documented mistakes. (1) The framework's own cover sheet says the Requirements section "contains all mandatory actions"; a page later, under "Resource Impact", it says there are no new mandatory requirements and no impact on resource, despite 252 uses of "must" across the 35 pages that follow. (2) At least 22 cross-references throughout the document, including the clause defining unauthorised interception of a prisoner's legally privileged mail, point staff to sections numbered 13 to 18 that do not appear anywhere in the printed 37-page framework. (3) GOV.UK's 23 September 2026 change note says "Annexes A to E updated"; the files' own metadata shows only one of the five was actually touched that week, and the download still contains two superseded December 2023 drafts. Rated four stars out of five.
Sources
- Interception, monitoring and security of prisoner communications policy framework (GOV.UK publication page, Ministry of Justice and HM Prison and Probation Service, published 11 August 2026, updated 23 September 2026)
- Interception, Monitoring and Security of Prisoner Communications Policy Framework (PDF, 37 pages, issue date 11 August 2026)
- Annexes A to E (zip file, updated 23 September 2026)
- Prisons (Investigatory Powers Commissioner's Office)