A TOC is not a designated law enforcement agency.
Therefore they do not, under Data Protection Act 2018, have the legal right to process data for the purpose of preventing, investigating, or detecting crime.
This isn't correct.
Exemptions under DPA apply to people ("competent [authorities]") who have a
"statutory function" (permission granted by an enactment of law) to pursue criminal proceedings. In this case, this is set out in
S29 of the Criminal Justice Act 2003, by reference of a "relevant prosecutor", which is then defined in
S6 of the Criminal Justice Act 2003 (New Method of Instituting Proceedings) (Specification of Relevant Prosecutors) Order 2016, which designates any company holding a license to operate on the railways as a relevant prosecutor for Railway Byelaw offenses (crucially,
not Regulation of Railways Act 1889 or Fraud Act 2006 offenses).
If they are investigating a byelaw offence, then the exemption under the DPA engages.
It's worth noting that just because the DPA exemption engages, there is no
obligation for any other party to actually share any data with them if they (a) do not want to, or (b) they believe that
not sharing the information wouldn't prejudice any investigation, potentially because they already have enough information to prosecute or the information is already accessible to them via other means.
The exemptions
also apply to any third party acting under instruction of a "competent authority", which is why the likes of ITAL and TIL will investigate cases and request information from other industry parties as well.
It's also worth noting that the specific wording of the crime and taxation exemption does
not mean that a hypothetical retailer cannot share information with someone who is not a competent authority. The only requirement is that you must be able to demonstrate that the sharing of the data is necessary for the prevention and detection of crime or the apprehension or prosecution of offenders, and that complying with the DPA 2018 principles will prejudice this purpose.
Anyone can process data for the purpose of preventing or detecting crime, and can share that information as needed to achieve the purposes in the exemption without informing the person
if that would prejudice an investigation. That is very clear from
Schedule 2 Part 1 Paragraph 2(1). The competent authority exemptions
then allow for the data to be used for any investigation or prosecution without needing to inform the person of the source of the data and how it's being processed, or the risk of someone using their Right to be Forgotten, Object, to Data Portability, etc.