Showing posts with label data protection. Show all posts
Showing posts with label data protection. Show all posts

Friday, 20 March 2026

Data Protection Litigation: Pre-action Protocol for Media and Communications Claims

Jane Lambert

 


















There has recently been a surge in claims by individuals seeking to enforce their rights under data protection legislation through litigation.  I have appeared in two such claims this week, one in London and another in the Thames Valley.  I have also advised in writing and in conference on several more. A surprising aspect of the surge is that the United Kingdom General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018 are much more complicated than the Data Protection Act 1998 and the Data Protection Act 1984, which preceded them. Those Acts also provided rights of action, but they were used much less frequently than the present legislation.  Another surprise is the infrequency with which parties refer to the Pre-action Protocol for Media and Communications Claims, even though that protocol applies to all data protection claims.  In both of the cases in which I appeared this week, observance of the protocol would have made a significant difference to the outcome of the litigation.  

Effective Judicial Remedy
Art 79 (1) of the UK GDPR (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) as modified by The Data Protecion, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019) entitles data subjects to an effective judicial remedy if they consider that their rights under the Regulation have been infringed as a result of the processing of their personal data in non-compliance with the regulation.  That includes a right under art 82 (1) to compensation from a controller or processor for any material or non-material damage that may arise as a result of such non-compliance.

Pre-action Protocols
Para 1 of Practice Direction - Pre-action Conduct and Protocols states that pre-action protocols explain the conduct and set out the steps the court would normally expect parties to take before commencing proceedings for particular types of civil claims. Para 2 warns that a person who knowingly makes a false statement in a pre-action protocol letter or other document prepared in anticipation of legal proceedings may be subject to proceedings for contempt of court.  Para 3 states that the objectives of pre-action conduct and protocols are to enable parties to disputes to:
"(a) understand each other’s position;
(b) make decisions about how to proceed;
(c) try to settle the issues without proceedings;
(d) consider a form of Alternative Dispute Resolution (ADR) to assist with settlement;
(e) support the efficient management of those proceedings; and
(f) reduce the costs of resolving the dispute."

Para 4 stresses that a pre-action protocol must not be used by a party as a tactical device to secure an unfair advantage over another party. Only reasonable and proportionate steps should be taken by the parties to identify, narrow and resolve the legal, factual or expert issues.  Para 5 adds that disproportionate costs in complying with any pre-action protocol are likely to be irrecoverable.  Para 6 states that where there is a relevant pre-action protocol, the parties should comply with it before commencing proceedings.  Para 8 reminds parties that litigation should be a last resort. As part of a relevant pre-action protocol, the parties should consider whether negotiation or some other form of ADR might enable them to settle their dispute without commencing proceedings.

Non-compliance with a protocol can be penalized in several ways.  For example, para 16 states that a party at fault may be ordered to pay costs on an indemnity basis or a successful party may be deprived of some or all of his or her costs.

Pre-action Protocol for Media and Communications Claims
Although it is not listed among the "Protocols in Force" in para 18 of PD-Pre-action Conduct and Protocols, para 1.1 of the Pre-action Protocol for Media and Communications Claims states that it applies to data protection claims, including those brought by litigants in person. If a party to a claim becomes aware that another party is a litigant in person, he or she should send a copy of the protocol to the litigant in person at the earliest opportunity.

The aims of the protocol listed in para 2.1 are similar to those of the practice direction, namely enabling parties to prospective claims to:
"(a) understand and properly identify the issues in dispute and to share information and relevant documents;
(b) make informed decisions as to whether and how to proceed;
(c) try to settle the dispute without proceedings or reduce the issues in dispute;
(d) avoid unnecessary expense and control the costs of resolving the dispute; and
(e) support the efficient management of proceedings where court proceedings cannot be avoided."

Para 3.1 requires intending claimants to notify intended defendants of their claims in writing at the earliest reasonable opportunity.   They are also reminded of the need for proportionality in formulating both the letter of claim and response in para 2.2:

"In formulating both the Letter of Claim and Response and in taking any subsequent steps, the parties should act reasonably to keep costs proportionate to the nature and gravity of the case and the stage the complaint has reached."

The following information should be included in the letter of claim: 

  • the name of the claimant;
  • the nature of and basis for the entitlement to the remedies sought by the claimant;
  • any facts or matters relevant to England and Wales being the most appropriate forum for the dispute; and
  • details of any funding arrangement in place.
Para 3.4 adds that letters of claim in data protection cases should also include:

  •  "any further information necessary to identify the data subject;
  • the data controller to which the claim is addressed;
  • the information or categories of information which is claimed to constitute personal data including, where necessary, the information which is said to constitute sensitive personal data or to fall within a special category of personal data;
  • sufficient details to identify the relevant processing;
  • the identification of the duty or duties which are said to have been breached and details of the manner in which they are said to have been breached, including any positive case on behalf of the Claimant;
  • why the personal data ought not to be processed/further processed, if applicable;
  • the nature and any available details as to any particular damage caused or likely to be caused by the processing/breach of duty complained of; and
  • Where a representative data protection claim is intended to be brought on behalf of data subjects, the letter of claim should also: set out the nature of the entity which intends to bring the claim and explain how it fulfils the relevant suitability criteria – see Article 80 of the General Data Protection regulation (GDPR); include details of the data subjects on whose behalf the claim would be brought; and, confirmation that they have mandated the representative body to represent them and receive compensation, where applicable."
Defendants are required by para 3.6 to provide a full response to the letter of claim, as soon as reasonably possible. If a defendant believes that he or she will be unable to respond within 14 days (or such shorter time limit as specified in the letter of claim), then he or she should specify the date by which he/she intends to respond.

Para 3.7 requires letters of response to include:

  • "whether or to what extent the Claimant’s claim is accepted, whether more information is required or whether it is rejected;
  • if the claim is accepted in whole or in part, the Defendant should indicate which remedies it is willing to offer;
  • if more information is required, then the Defendant should specify precisely what information is needed to enable the claim to be dealt with and why;
  • if the claim is rejected, then the Defendant should explain the reasons why it is rejected, including a sufficient indication of any statutory exemptions or facts on which the Defendant is likely to rely in support of any substantive defence;
  • in a defamation or malicious falsehood claim, the defamatory or false imputation(s) the Defendant contends was conveyed by the statement complained of, if any; and
  • where the Claimant to a proposed action has indicated his/her intention to make an application to bring the claim anonymously, the Defendant should indicate whether the Defendant accepts such an order would be appropriate and give an indication of the basis for the Defendant’s position."
Para 3.8 reminds parties that litigation should be a last resort, while para 3.9 suggests the following options for parties to data protection disputes:

"(a) without prejudice discussions and negotiations between the parties;
(b) mediation – a form of facilitated negotiation assisted by an independent neutral third party; [and]
(c) early neutral evaluation (ENE) – a third party giving an informed opinion on the dispute (for example, a lawyer experienced in the field of [data protection] or an individual experienced in the subject matter of the claim)......."

Para 3.10 mentions the need to consider offers under CPR Part 36.  If a dispute is not settled, para 3.11 encourages parties to undertake a further review of their respective positions, to consider the state of the papers and the evidence in order to see if proceedings can be avoided and, at least, narrow the issues between them which can assist efficient case management.  

Finally, parties are referred to other provisions which they might find useful, such as CPR Part 25: Interim Remedies and Security for Costs and CPR PD48 paragraphs 3.1 and 3.2: Part 2 of the Legal Aid, Sentencing and Punishment of Offenders Act 2012 Relating to Civil Litigation Funding and Costs.

Further Information
Anyone wishing to discuss this article further may call me on 020 7404 5252 during UK office hours or send me a message through my contact form at any time.

Friday, 26 December 2025

Data (Use and Access) Act 2025: Structure

Jane Lambert

 







An inkling of the scope and complexity of the Data (Use and Access) Act 2025 can be gained from the introductory text:

"An Act to make provision about access to customer data and business data; to make provision about services consisting of the use of information to ascertain and verify facts about individuals; to make provision about the recording and sharing, and keeping of registers, of information relating to apparatus in streets; to make provision about the keeping and maintenance of registers of births and deaths; to make provision for the regulation of the processing of information relating to identified or identifiable living individuals; to make provision about privacy and electronic communications; to establish the Information Commission; to make provision about information standards for health and social care; to make provision about the grant of smart meter communication licences; to make provision about the disclosure of information to improve public service delivery; to make provision about the retention of information by providers of internet services in connection with investigations into child deaths; to make provision about providing information for purposes related to the carrying out of independent research into online safety matters; to make provision about the retention of biometric data; to make provision about services for the provision of electronic signatures, electronic seals and other trust services; to make provision about works protected by copyright and the development of artificial intelligence systems; to make provision about the creation of purported intimate images; and for connected purposes.

As I said in Data Protection Law Reform, the Act consists of 144 sections divided into 8 parts with 16 schedules.

Structure

The parts of the Act are as follows:

The schedules are as follows:

Schedule 1: National Underground Asset Register (England and Wales): monetary penalties; Schedule 3: Registers of births and deaths: minor and consequential amendments; Schedule 8: Transfers of personal data to third countries, etc: law enforcement processing;Schedule 11: Further minor provision about data protection;
Schedule 12: Storing information in the terminal equipment of a subscriber or user;
Schedule 13: Privacy and electronic communications: Commissioner’s enforcement powers;
Schedule 14: The Information Commission;
Schedule 15: Information standards for health and adult social care in England; and
Schedule 16: Grant of smart meter communication licences.

Further Information

The Departments of State and Ministries concerned with this legislation have prepared explanatory notes on the statute.  Probably the most useful are the Overview (paras 1 to 15) and the Legal Policy (paras 16 to 83).  Also useful are the Guidance on Data Use and Access Act 2025: plans for commencement by the Department for Science, Innovation and Technology ("DSIT"), the Information Commissioner's index page and the DSIT's fact sheets on the UK GDPR and the Data Protection Act, the ICO and the Privacy and Electronic Communications Regulations 2003.

Subsequent articles will discuss particular parts and schedules of the Act.  Anyone wishing to discuss this article may call me on +44 (0)20 7404 5252 during office hours or send me a message through my contact form at any time.

Related Articles

Jane Lambert  Data Protection Law Reform 23 Dec 2025

Tuesday, 23 December 2025

Data Protection Law Reform

Author Robert Harker Licence CC BY-SA 3.0  Source Wikimedia

 














Jane Lambert

Shortly after EU law ceased to apply to the UK, the government of the day proposed changes to this country's data protection laws.  I discussed those proposals in Dowden's Data Protection Plans on 27 Aug 2021.  A consultation was launched on 10 Sept 2021, which I considered in Consultation on Changing the Data Protection Laws on 12 Sept 2021.  Draft legislation was introduced on 17 June 2022, which I mentioned in The Proposed Data Reform Bill on 25 June 2022.  That bill never made it past its first reading because the minister responsible for piloting it through the Commons was replaced when Liz Truss became prime minister.  The new minister introduced the Data Protection and Digital Information Bill, which was more far-reaching than the Data Reform Bill (see the Data Protection and Digital Information (No 2) Bill 2022-2023). That bill fell with the Conservative government when the general election was held.  One of the first acts of the incoming Labour government was to introduce the Data (Use and Access) Bill on 23 Oct 2024.  That bill received royal assent on 19 June 2025.

The Data (Use and Access) Act 2025 consists of 144 sections divided into 8 Parts with 16 schedules.   The Department for Science, Innovation and Technology describes the legislation as "a wide-ranging Act which includes provisions to enable the growth of digital verification services, new Smart Data schemes like Open Banking and a new National Underground Asset Register" in its Guidance.  The new Act "will not replace the UK General Data Protection Regulation (“UK GDPR”), Data Protection Act 2018 or the Privacy and Electronic Communications (EC Directive) Regulations 2003, but it will make some changes to them to make the rules simpler for organisations, encourage innovation, help law enforcement agencies to tackle crime and allow responsible data-sharing while maintaining high data protection standards."

According to the Information Commissioner, the statute updates some laws about digital information matters and changes data protection laws in order to promote innovation and economic growth.   Its provisions will be phased in between June 2025 and June 2026.  The Department for Science, Innovation and Technology has published useful fact sheets on the UK GDPR and Data Protection Act 2018, the Information Commissioner's Office and the Privacy and Electronic Communications Regulations 2003.

Anyone wishing to discuss this article is welcome to call me on +44 (0)20 7404 5252 during UK office hours or send me a message through my contact form at any time.  In subsequent articles, I shall review the Act and analyse its provisions.

Sunday, 13 February 2022

Privacy and Electronic Communications - Leave.EU Group Ltd v The Information Commissioner

EU-Austritt (47521165961).svg
Author Mrmw Public Domain CCO 1.0









Jane Lambert

Court of Appeal (Sir Geoffrey Vos, Master of the Rolls, Lord Justice Lewison and Lady Justice Asplin) Leave.EU Group Ltd & Anor v The Information Commissioner [2022] EWCA Civ 109 (8 Feb 2022)

On 1 Feb 2020, the Information Commissioner issued a monetary penalty notice for £45,000 against Leave.EU Group Ltd. under s.55A of the Data Protection Act 1998 and an assessment notice under s.146 of the Data Protection Act 2018.  She issued those notices because Leave.EU Group Ltd. had sent email newsletters to some of its supporters that contained unsolicited marketing material relating to Eldon Insurance Services Ltd.   It appears that Eldon Insurance Services Ltd is now known as Somerset Bridge Insurance Services Ltd.

Leave.EU and Eldon appealed unsuccessfully to the First-Tier Tribunal (General Regulatory Chamber) (see Leave.EU Group Limited Eldon Insurance Services Limited v The Information Commissioner 2020 WL 01140646). They appealed to the Upper Tribunal which upheld the First-Tier Tribunal (see Leave.EU Group Limited and another v The Information Commissioner [2021] UKUT 26 (AAC)).  With the Upper Tribunal's permission, they appealed to the Court of Appeal.  On 1 Feb 2022, when the appeal was due to be heard, the Information Commissioner's legal representatives turned up at court but there was nobody from Leave.EU.

The Court asked the Information Commissioner's counsel what they should do. He replied that the Court could either dismiss the appeal for non-prosecution or decide the appeal on the Commissioner's oral and written submissions and Leave.EU's skeleton argument. The Commissioner was neutral as to the course that the Court should adopt but her counsel emphasized the importance of the issues under appeal. The Court decided (i) that it would not be just or appropriate to hear the substantive appeal in the absence of Leave.EU, (ii) that the Court was satisfied that Leave.EU was aware of the appeal hearing and had decided not to attend, and (iii) the appeal should be dismissed and that it would give its reasons in writing later.

The Information Commissioner and the tribunals below had found that Leave.EU and Eldon had contravened art 13 (1) of Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications) OJ L 201, 31.7.2002, p. 37–47. Leave.EU has appealed on the following grounds:
"First it contended that paragraph 22 did not prohibit the inclusion of any direct marketing information in an email which was otherwise solicited and not sent for direct marketing purposes, such as the political newsletters in this case. Secondly, Leave.EU contended that the FTT was wrong to hold that the subscribers had not freely consented to receive marketing information from Eldon, since they had consented to receive such material as Leave.EU felt might interest its subscribers. Thirdly, Leave.EU contended that the Information Commissioner ought to be regarded as having been required to give reasons for her decision, despite the absence of a statutory requirement to do so."

In its reasoned judgment which was delivered on 8 Feb 2022, The Master of the Rolls described those issues as "important and in some respects novel" at para [19]. He was satisfied that the Court had power to hear the appeal in the absence of the appellant under CPR 52.20 and rule 38 of the Tribunal Procedure (Upper Tribunal) Rules 2008 as well as its inherent jurisdiction but thought it undesirable in the circumstances of this case to try to decide such important questions at the level of the Court of Appeal without full oral argument.

Lord Justice Lewison and Lady Justice Asplin agreed.

According to the Commissioner's counsel, Eldon had been sold to a third party on 31 Jan 2022 who had consented to judgment and reached an agreement with the Commissioner (see her Statement on an agreement reached between Somerset Bridge Insurance Services Limited and the ICO of 1 Feb 2022). The solicitors who had acted for both appellants had applied to come off the record a few days earlier. The Court had tried to communicate with Leave.EU's sole director but he did not respond to its approaches.

The failure of Leave.EU to take any steps in the appeal in the days leading up to the hearing is regrettable.  As Sir Geoffrey Vos noted at [19] an appropriately qualified panel of the Court of Appeal had been ready to hear this case for many months.  The issues upon which the Court had been asked to decide are likely to concern other parties and cases of this kind do not come before the Court of Appeal often. 

Anyone wishing to discuss this article or the procedural or standard issues may call me on 020 7404 5252 during normal business hours or send me a message through my contact form.

Sunday, 12 September 2021

Consultation on Changing the Data Protection Laws


 








Jane Lambert

In his press release of 26 Aug 2021 which I discussed in Dowden's Data Protection Plans on 27 Aug 2021, Oliver Dowden MP, Secretary of State for Digital, Culture, Media and Sport, announced a consultation on changes to the UK's data protection laws.  That consultation was launched on 10 Sept 2021 with the publication of the consultation document, Data: a New Direction.  Responses must be submitted by 19 Nov 2021.

The consultation document is 146 pages long and is divided into an introduction, 5 chapters. a page on whom the Department for Digital, Culture. Media and Sport ("DCMA")  is seeking to consult, how to respond and what happens next and a privacy notice.  DCMS states that it is keen to hear from "a representative cross section of society, ensuring diversity and inclusion", It believes that the consultation will have particular relevance to 

  • Individuals 
  • Start-ups and small businesses 
  • Technology companies and data-driven or data-rich companies 
  • Investors in technology and data-driven or data-rich companies 
  • Civil society organisations focused on consumer rights, digital rights, privacy and data protection 
  • Academics, and research and policy organisations with a particular interest in the role of data in the economy and society, or as data controllers in their own right 
  • Organizations involved in international data standards, regulation, and governance 
  • Law firms and other professional business services.
Respondents are urged to use the DCMS's online survey platform but responses can also be submitted by email or post.  The DCMS will publish its response in due course.

The 5 chapters are as follows:
  • Chapter 1- Reducing barriers to responsible innovation
  • Chapter 2 - Reducing burdens on businesses and delivering better outcomes for people
  • Chapter 3 - Boosting trade and reducing barriers to data flows
  • Chapter 4 - Delivering better public services, and 
  • Chapter 5 - Reform of the Information Commissioner's Office.
The reason for reducing barriers to responsible innovation are set out in para 30:

"The government has heard from stakeholders that elements of the law can create barriers to responsible innovation. Some definitions are unclear and lack explanatory case law or regulatory guidance that could take years to develop; organisations may choose not to use data as fully as they could owing to unfounded concerns about legality. For example, the rules for some organisations to use and to re-use personal data for research are difficult to navigate, despite the public being generally in favour of their personal data being used for scientific research that can deliver real benefits to society.5 The government has also heard evidence that uncertainty about when different lawful grounds for processing personal data should be used has led to an overreliance on seeking consent from individuals. This creates an unnecessary burden for consumers as well as for organisations. Finally, the increasing adoption and potential of new data-driven technologies is dependent on clear and consistent rules about the use of personal data."

The criticism of the present system is contained in para 139:

"The current legislation is based on a model that prescribes a series of activities and controls that organisations must adopt in order to be considered compliant. Although a key goal of the EU's GDPR was to create a regime that focussed on the accountability of organisations, the current model, in practice, tends towards a ‘box-ticking’ compliance regime, rather than one which encourages a proactive and systemic approach, and risks undermining the intentions of the principle of accountability."

One of those burdens is said to be subject access requests.  It is said that organizations have difficulty in processing such requests and with the threshold for making requests.  One of the solutions canvassed by the DCMS is the reintroduction of a fee for subject access requests and that is one of the proposals on which the Department is consulting. 

On "Boosting trade and reducing barriers to data flows" the DCMS explains at 240:

"Recent legal developments, including the Schrems II judgment, have made it more difficult for UK data exporters to transfer personal data overseas (see explanatory box below). The invalidation of the Privacy Shield by this judgment was particularly disruptive given the volume of trade it supported and the very many small and medium-sized businesses that were relying on it. Outside of the European Union, the UK has an opportunity to consider both the impact of this judgment on its transfers regime and how best to support international data flows in the future."

Data protection law became horrendously complex with the adoption of the General Data Protection Regulation and the implementation of the Law Enforcement Directive by the Data Protection Act 2018 on 25 May 2018.  Brexit has greatly exacerbated that complexity.   A snapshot of the current law since the expiry of the transition or implementation period on 31 Dec 2020 is set out in The Data Protection Legislation which I published on 28 Aug 2021.

Anyone wishing to discuss this article or any of its contents can call me on 020 7404 5252 during normal office hours or send me a message through my contact form at other times.

Friday, 27 August 2021

Dowden's Data Protection Plans


Jane Lambert

In the last few months, this government has made one ambitious promise after another. In his foreword to Global Britain in a competitive age, the Prime Minister wrote that his government's aim is for the UK to become a science and tech superpower by 2030 (see NIPC Brexit 19 March 2021). In his foreword to the UK Innovation Strategy Leading the future by creating it Kwasi Kwarteng, Secretary of State for Business, said that the UK would in science and technology what it is in finance (see UK Innovation Strategy, NIPC Inventors Club 12 Aug 2021). With similar hyperbole, Oliver Dowden, Secretary of State for Culture, Media and Sport has announced "a world-leading data regime" by "forging new global partnerships and designing our own common sense data laws" (see UK unveils post-Brexit global data plans to boost growth, increase trade and improve healthcare DCMS press release 26 Aug 2021).

The Press Release

Mr Dowden's press release makes three announcements:
  • an intention to negotiate "data adequacy partnerships" with Australia, Colombia, the Dubai International Financial Centre, Singapore, South Korea and the USA;
  • the appointment of John Edwards, the New Zealand Privacy Commissioner, as the next Information Commissioner; and 
  • a consultation on changes to the UK's data protection laws "to break down barriers to innovative and responsible uses of data so it can boost growth, especially for startups and small firms, speed up scientific discoveries and improve public services."
Data Protection Legislation 

On 25 May 2018, the General Data Protection Regulation ("GDPR") came into force across the European Union including the UK.  Art 94 of the GDPR repealed Directive 95/46/EC which had been implemented in the UK by the Data Protection Act 1998.  As it was a regulation of the European Council and Parliament, the GDPR took effect automatically.  The UK Parliament enacted the Data Protection Act 2018 which repealed the Data Protection Act 1998, supplemented the GDPR and applied a broadly equivalent regime to certain types of processing to which the GDPR did not apply.  

When the UK left the EU on 31 Jan 2020, the GDPR remained in force in the UK during the transition or implementation period that ended on 31 Dec 2020 pursuant to art 127 of the withdrawal agreement.  At the end of the transition period, the GDPR was incorporated into English, Welsh, Scots and Northern Irish law by s.3 (1) of the European Union  (Withdrawal) Act 2018.  Reg 3 and Sched. 1 of The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (SI 2019 No 418) amended the provisions of the GDPR that have been incorporated into domestic law.   Reg 4 and Sched 2 of those regulations amended the Data Protection Act 2018.  

Transfer of Data Abroad

A fundamental principle of all data protection laws is that personal data should not be transferred abroad without adequate safeguards for its protection.  Art 44 of the GDPR provides:
"Any transfer of personal data which are undergoing processing or are intended for processing after transfer to a third country or to an international organisation shall take place only if, subject to the other provisions of this Regulation, the conditions laid down in this Chapter are complied with by the controller and processor, including for onward transfers of personal data from the third country or an international organisation to another third country or to another international organisation."

One of the conditions on which personal data may be transferred overseas is set out in art 45 (1):

"A transfer of personal data to a third country or an international organisation may take place where the Commission has decided that the third country, a territory or one or more specified sectors within that third country, or the international organisation in question ensures an adequate level of protection. Such a transfer shall not require any specific authorisation."

The decision of whether a third country provides adequate protection depends on a number of elements set out in art 45 (2).   The Commission has already made an adequacy decision in favour of the UK by its Decision of  26 June 2021 which I discussed in Commission Adequacy Decisions on 29 June 2021.  

Amendments to Art 45

Para 38 (2) of  Sched 1 of  The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 changed art 45 (1) of the GDPR to:
"A transfer of personal data to a third country or an international organisation may take place where it is based on adequacy regulations (see section 17A of the 2018 Act) ”. Such a transfer shall not require any specific authorisation."

Para 38 (3) of that Sched deleted most o the rest of the article.  Para 23 of Sched 2 inserted new sections 17A, 17B and 17C into the Data Protection Act 2018.  Those new sections contain new provisions for determining the adequacy of other countries' protection of personal data.  These include the power to make regulations.    

Para 42  of Sched 2 inserted new sections 74A and 74B into the Data Protection Act 2018,   These provide for the transfer abroad of data not covered by the GDPR in accordance with the above-mentioned regulations.   S.74A (4) of the Act is in substantially the same terms as art 45 (2) of the GDPR.

"Adequacy Partnerships"

The pairing of the noun "partnership" with the adjective "adequacy" suggests that adequacy decisions could depend on reciprocity and commercial advantage rather than the criteria in art 45 (1).   The press release reinforces that impression:
"The government believes it can unlock more trade and innovation by reducing unnecessary barriers and burdens on international data transfers, thereby opening up global markets to UK businesses. In turn this will help give UK customers faster, cheaper and more reliable products and services from around the world."

 Those concerns are at least partially allayed by the "Test for Adequacy" section of the guidance note International data transfers: building trust, delivering growth and firing up innovation published on 26 Aug 2021.  On paper, at least, the test for adequacy is objective and not dissimilar to the test in art 45 (2) of the GDPR. 

Risk of Losing the European Commission Adequacy Finding

A problem of seeking adequacy partnerships with countries operating very different regimes for protecting personal data is that the Commission could revoke its decision on the adequacy of protection in the UK under art 3 (4). That paragraph provides:

"Where the Commission has indications that an adequate level of protection is no longer ensured, the Commission shall inform the competent United Kingdom authorities and may suspend, repeal or amend this Decision."
Such a situation could arise if data were to flow without restriction from the EU to the UK and then from the UK to the USA but not directly from the EU to the  USA.   It would be unfortunate if the UK jeopardized its status in the European Economic Area in a quest for more distant and generally smaller markets overseas. 

Consultation

There is as yet no green paper or consultation on changing the law.   The only indication of what the government has in mind at this stage is that it believes improved data sharing could help deliver more agile, effective and efficient public services and help make the UK a science and technology superpower.   

Further Information

Anyone wishing to discuss this article or data protection generally my call me on 020 7404 5252 during office hours or send me a message through my contact form.

Tuesday, 29 June 2021

Commission Adequacy Decision

European Commission
Author EmDee Licence CC BY-SA 4.0  Source Wikipedia Commons

 









Jane Lambert

The uninterrupted exchange of personal data across borders is vital for the financial and other service industries. As I noted in Another Data Protection Act! "You're joking! Not another one!" - A Short History of Data Protection Legislation in the UK 23 Sept 2017 NIPC Law, it was restrictions on the transfer of personal data from countries that had enacted data protection legislation rather than the Younger and Lindop reports that prompted Parliament to enact the first Data Protection Act in 1984. Until 23:00 on 31 Dec 2020 businesses in the UK could rely on art 1 (3) of the General Data Protection Regulation (Regulation (EU) 2016/679 which provides that the free movement of personal data within the European Union shall be neither restricted nor prohibited for reasons connected with the protection of natural persons with regard to the processing of personal data. That was because EU law continued to apply to the UK between 23:00 on 31 Jan and 23:00 on 31 Dec 2020 pursuant to art 127 (1) of the agreement by which the UK withdrew from the EU.

Upon the expiry of that period, the United Kingdom became a "third country" for the purposes of art 44 of the GDPR.  That article provides:

"Any transfer of personal data which are undergoing processing or are intended for processing after transfer to a third country or to an international organisation shall take place only if, subject to the other provisions of this Regulation, the conditions laid down in this Chapter are complied with by the controller and processor, including for onward transfers of personal data from the third country or an international organisation to another third country or to another international organisation. All provisions in this Chapter shall be applied in order to ensure that the level of protection of natural persons guaranteed by this Regulation is not undermined."

Art 45 (1), however, provides:

"A transfer of personal data to a third country or an international organisation may take place where the Commission has decided that the third country, a territory or one or more specified sectors within that third country, or the international organisation in question ensures an adequate level of protection. Such a transfer shall not require any specific authorisation."
The rest of that article sets out the criteria by which the Commission can make such a decision and the procedure for reaching it.

By a decision dated 28 June 2021 (Commission Implementing Decision of 28.6.2021 pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on the adequate protection of personal data by the United Kingdom (C(2021) 4800 final)), the Commission has decided that for the purposes of art 45 of the GDPR the UK ensures an adequate level of protection for personal data transferred within the scope of the GDPR from the EU to the UK. The decision consists of 93 pages almost all of which are recitals setting out the Commission's reasons.  The decision on adequacy is contained in art 1 (1).  Art 3 (1) of the Decision requires the Commission to "monitor the application of the legal framework upon which this Decision is based, including the conditions under which onward transfers are carried out, individual rights are exercised and United Kingdom public authorities have access to data transferred on the basis of this Decision, with a view to assessing whether the United Kingdom continues to ensure an adequate level of protection within the meaning of Article 1." The Commission has power under art 3 (4) to suspend, repeal or amend the decision where it has indications that an adequate level of protection is no longer ensured.  It can also suspend, repeal or amend the decision under art 3 (5) if a lack of cooperation of the UK government prevents the Commission from determining whether the finding in art 1 (1) is affected.   The decision shall expire on 27 June 2025, unless extended in accordance with art 93 (2) of the GDPR.

Art 1 (2) of the decision makes clear that it does not cover personal data that is transferred for purposes of UK immigration control or that otherwise falls within the scope of the exemption from certain data subject rights for purposes of the maintenance of effective immigration control pursuant to para 4 (1) of Sched. 2 to the Data Protection Act 2018.  Art 2 (2) (d) of the GDPR states that the regulation does not apply to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security.   Such processing is regulated by the Law Enforcement Directive (Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA). 

Art 35 (1) of the directive imposes the following obligation upon EU member states:

"Member States shall provide for any transfer by competent authorities of personal data which are undergoing processing or are intended for processing after transfer to a third country or to an international organisation including for onward transfers to another third country or international organisation to take place, subject to compliance with the national provisions adopted pursuant to other provisions of this Directive, only where the conditions laid down in this Chapter are met, namely:
(a) the transfer is necessary for the purposes set out in Article 1 (1);
(b) the personal data are transferred to a controller in a third country or international organisation that is an authority competent for the purposes referred to in Article 1 (1);
(c) where personal data are transmitted or made available from another Member State, that Member State has given its prior authorisation to the transfer in accordance with its national law;
(d) the Commission has adopted an adequacy decision pursuant to Article 36, or, in the absence of such a decision, appropriate safeguards have been provided or exist pursuant to Article 37, or, in the absence of an adequacy decision pursuant to Article 36 and of appropriate safeguards in accordance with Article 37, derogations for specific situations apply pursuant to Article 38; and
(e)  in the case of an onward transfer to another third country or international organisation, the competent authority that carried out the original transfer or another competent authority of the same Member State authorises the onward transfer, after taking into due account all relevant factors, including the seriousness of the criminal offence, the purpose for which the personal data was originally transferred and the level of personal data protection in the third country or an international organisation to which personal data are onward transferred."
Art 36 of the Law Enforcement Directive is very similar to art 45 of the GDPR.  By Commission Implementing Decision of 28.6.2021 pursuant to Directive (EU), 2016/680 of the European Parliament and of the Council on the adequate protection of personal data by the United Kingdom (C(2021) 4801 final) the Commission found that the UK ensures an adequate level of protection for personal data transferred from the EU to UK public authorities responsible for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties for the purposes of art 36. The decision requires the Commission to monitor the UK government's compliance with the legal framework and enables the Commission to suspend, repeal or amend the decision in the event of non-compliance or non-cooperation.  Subject to that provision, the decision also remains in force until 27 June 2025.

In an ICO statement in response to the EU Commission’s announcement on the approval of the UK’s adequacy, the Information Commissioner said:
“This is a positive result for UK businesses and organisations.
Approved adequacy means that businesses can continue to receive data from the EU without having to ake any changes to their data protection practices.
Adequacy is the best outcome as it means organisations can carry on with data protection as usual. And people will continue to enjoy the protections that their data will be used fairly, lawfully and transparently.
The result is also a testament to the strength of the UK’s data protection regime.”

Anyone wishing to discuss this article or data protection generally my call me on 020 7404 5252 during office hours or send me a message through my contact form. 

Friday, 4 October 2019

Lloyd v Google LLC

Author Gciriani
Licence CC BY-SA 4.0
Source Wikipedia Google























Jane Lambert

Court of Appeal (Dame Victoria Sharp P, Sir Geoffrey Vos C, Lord Justice Davis) Lloyd v Google LLC [2019] EWCA Civ 1599 (2 Oct 2019)

This was an appeal against Mr Justice Warby's refusal to allow the claimant, Richard Lloyd ("Mr Lloyd"), to serve proceedings on Google LLC ("Google") outside the jurisdiction claiming damages on behalf of 4 million i-phone users for  allegedly tracking secretly their internet activity for commercial purposes between 9 Aug 2011 and 15 Feb 2012.  The appeal was heard on 16 and 17 July 2019 by the President of the Queen's Bench Division, the Chancellor and Lord Justice Davis. Judgment was given on 2 Oct 2019. The lead judgment was delivered by the Chancellor, Sir Geoffrey Vos.

The Issues
The facts in this appeal were very similar to those in Google Inc v Vidal-Hal and others [2015] 3 WLR 409, [2015] CP Rep 28, [2015] FSR 25, [2015] 3 CMLR 2, [2015] WLR(D) 156, [2015] EMLR 15, [2015] EWCA Civ 311, [2016] QB 1003, [2016] 2 All ER 337 where the Court of Appeal dismissed Google's appeal against Mr Justice Tugendhat's decision to allow a similar claim to be served  outside the jurisdiction (see Vidal-Hall and others v Google Inc [2014] EWHC 13 (QB) (16 Jan 2014)  [2014] EMLR 14, [2014] 1 WLR 4155, [2014] WLR 4155, [2014] FSR 30, [2014] 1 CLC 201, [2014] WLR(D) 21, [2014] EWHC 13 (QB)). However, the Chancellor pointed out at paragraph [3] of his judgment that there was one crucial difference between the two cases.   In Vidal-Hall, the individual claimants claimed damages for distress as a result of Google's breaches of the Data Protection Act 1998 ("DPA").  In the present case, Mr Lloyd claimed a uniform amount by way of damages on behalf of each person within the defined class without seeking to allege or prove any distinctive facts affecting any of them, save that they did not consent to the abstraction of their data.

The Chancellor analysed Mr Justice Warby's decision between paragraphs [25] and [39] of his judgment.  According to the Chancellor, the grounds on which the application had been refused were  "that: (a) none of the represented class had suffered 'damage' under section 13 of the Data Protection Act 1998 (the 'DPA'), (b) the members of the class did not anyway have the 'same interest' within CPR Part 19.6 (1) so as to justify allowing the claim to proceed as a representative action, and (c) the judge of his own initiative exercised his discretion under CPR Part 19.6 (2) against allowing the claim to proceed."

His lordship summarized the main issues raised by the appeal as follows:
"(a) whether the judge was right to hold that a claimant cannot recover uniform per capita damages for infringement of their data protection rights under section 13 of the DPA, without proving pecuniary loss or distress, (b) whether the judge was right to hold that the members of the class did not have the same interest under CPR Part 19.6 (1) and were not identifiable, and (c) whether the judge's exercise of discretion can be vitiated."
The Facts
Sir Geoffrey adopted the following paragraphs from Mr Justice Warby's judgment:
"[7]. The case concerns the acquisition and use of browser generated information or "BGI". This is information about an individual's internet use which is automatically submitted to websites and servers by a browser, upon connecting to the internet. BGI will include the IP address of the computer or other device which is connecting to the internet, and the address or URL of the website which the browser is displaying to the user. As is well-known, "cookies" can be placed on a user's device, enabling the placer of the cookie to identify and track internet activity undertaken by means of that device.
[8]. Cookies can be placed by the website or domain which the user is visiting, or they may be placed by a domain other than that of the main website the user is visiting ("Third Party Cookies"). Third Party Cookies can be placed on a device if the main website visited by the user includes content from the third party domain. Third Party Cookies are often used to gather information about internet use, and in particular sites visited over time, to enable the delivery to the user of advertisements tailored to the interests apparently demonstrated by a user's browsing history ("Interest Based Adverts").
[9]. Google had a cookie known as the "DoubleClick Ad cookie" which could operate as a Third Party Cookie. It would be placed on a device if the user visited a website that included content from Google's Doubleclick domain. The purpose of the DoubleClick Ad cookie was to enable the delivery and display of Interest Based Adverts.
[10]. Safari is a browser developed by Apple. At the relevant time, unlike most other internet browsers, all relevant versions of Safari were set by default to block Third Party Cookies. However, a blanket application of these default settings would prevent the use of certain popular web functions, so Apple devised some exceptions to the default settings. These exceptions were in place until March 2012, when the system was changed. But in the meantime, the exceptions enabled Google to devise and implement the Safari Workaround. Stripped of technicalities, its effect was to enable Google to set the DoubleClick Ad cookie on a device, without the user's knowledge or consent, immediately, whenever the user visited a website that contained DoubleClick Ad content.
[11]. This enabled Google to identify visits by the device to any website displaying an advertisement from its vast advertising network, and to collect considerable amounts of information. It could tell the date and time of any visit to a given website, how long the user spent there, which pages were visited for how long, and what ads were viewed for how long. In some cases, by means of the IP address of the browser, the user's approximate geographical location could be identified. Over time, Google could and did collect information as to the order in which and the frequency with which websites were visited. It is said by the claimant that this tracking and collating of BGI enabled Google to obtain or deduce information relating not only to users' internet surfing habits and location, but also about such diverse factors as their interests and habits, race or ethnicity, social class, political or religious views or affiliations, age, health, gender, sexuality, and financial position.
[12]. Further, it is said that Google aggregated BGI from browsers displaying sufficiently similar patterns, creating groups with labels such as "football lovers", or "current affairs enthusiasts". Google's DoubleClick service then offered these groups to subscribing advertisers, allowing them to choose … the type of people that they wanted to direct their advertisements to".
Proceedings in the USA
The US Federal Trade Commission bought proceedings for misrepresenting to Safari users that it would not place tracking cookies on their browsers or send targeted advertising which Google settled by agreeing to pay a civil penalty of US$22.5 million.  It also settled an action by 37 states and the District of Columbia on behalf of their consumers by agreeing to pay US$17 million damages and giving certain undertakings.

Proceedings in the UK
 Mr Justice Warby had noted at paragraph [14] of his judgment that similar proceedings had not been brought in the UK by the Information Commissioner but he mentioned Vidal-Hall's claim that I discussed above. 

Applicable Law
Sir Geoffrey referred to paragraphs (2), (7), (8), (10), (11) and (55) of the recitals and arts 1, 22 and 23 of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data ("the Directive").  He also referred to ss.1 (1) (a) and (b), 3, 4 (1) and (4), 13 (1) and (2) and 14 (4) of the Data Protection Act 1998. Finally, he referred to CPR 19.6 (1), (2), (3) and (4).

Was the judge right to hold that a claimant cannot recover uniform per capita damages for infringement of their data protection rights under section 13 without proving pecuniary loss or distress?
The Chancellor affirmed that s.13 of the Data Protection Act 1998 has to be construed in accordance with art 23 of the Directive which had been adopted to give effect to art 8 of the European Convention on Human Rights. He also noted that the parties had agreed that there was a de minimis threshold for an award of damages. After considering the Court of Appeal's decisions in Gulati and others v MGN Ltd [2015] WLR(D) 232, [2015] EWHC 1482 (Ch) which was a case on the misuse of personal information, Halliday v Creation Consumer Finance Ltd (CCF) [2013] EWCA Civ 333 (15 March 2013) which was on damages under s.13 of the Data Protection Act 1998 and other authorities, his lordship concluded at [70] "that damages are in principle capable of being awarded for loss of control of data under article 23 and section 13, even if there is no pecuniary loss and no distress."  He added that it was only by construing the legislation in this way that individuals can be provided with an effective remedy for the infringement of their rights under the Act.

Was the judge was right to hold that the members of the class did not have the same interest under CPR Part 19.6(1) and were not identifiable?
CPR 19.6 (1) provides:
"Where more than one person has the same interest in a claim –
(a) the claim may be begun; or
(b) the court may order that the claim be continued,
by or against one or more of the persons who have the same interest as representatives of any other persons who have that interest."
Mr Justice Warby had held that a representative claim was disqualified unless (a) "every member of the class [had] suffered the same damage (or their share of a readily ascertainable aggregate amount [was] clear)", and (b) different potential defences were not available in respect of claims by different members of the class.  In the present case, for example, some in the claimant class would have been heavy internet users with much BGI taken; it was not credible that all the specified categories of data were obtained by Google from each represented claimant. The same variations would apply if the user principle were applied. Neither the breach of duty nor the impact of it was uniform across the entire class membership.

Sir Geoffrey believed that Mr Justice Earby had applied too stringent a test of "same interest" partly because of his earlier finding on recoverable damages.  H observed at [75]:
"Once it is understood that the claimants that Mr Lloyd seeks to represent will all have had their BGI – something of value - taken by Google without their consent in the same circumstances during the same period, and are not seeking to rely on any personal circumstances affecting any individual claimant (whether distress or volume of data abstracted), the matter looks more straightforward. The represented class are all victims of the same alleged wrong, and have all sustained the same loss, namely loss of control over their BGI. Mr Tomlinson disavowed, as I have said, reliance on any facts affecting any individual represented claimant. That concession has the effect, of course, of reducing the damages that can be claimed to what may be described as the lowest common denominator. But it does not, I think, as the judge held, mean that the represented claimants do not have the same interest in the claim. Finally, in this connection, once the claim is understood in the way I have described, it is impossible to imagine that Google could raise any defence to one represented claimant that did not apply to all others. The wrong is the same, and the loss claimed is the same. The represented parties do, therefore, in the relevant sense have the same interest. Put in the more old-fashioned language of Lord Macnaghten in The Duke of Bedford at [8], the represented claimants have a 'common interest and a common grievance' and 'the relief sought [is] in its nature beneficial to all'".
Mr Justice Warby had also held that a class of claimants having the same interest could not be identified. The Chancellor disagreed.  He said at [81]:  Havi
"In my judgment, therefore, the judge ought to have held that the members of the represented class had the same interest under CPR Part 19.6(1) and that they were identifiable."
Can the judge's exercise of discretion be vitiated?
Having reached a different conclusion on the other two issues, the Chancellor considered that it was appropriate for the court to exercise its discretion afresh.  Having considered carefully all the factors raised by both sides he concluded that this was a claim which, as a matter of discretion, should be allowed to proceed.

Conclusion
The President of the Queen's Bench Divison and Lord Justice Davis agreed with the Chancellor's judgment.  The appeal was therefore allowed and permission was granted to the claimants to serve their claim on Google in the USA.

Anyone wishing to discuss this appeal pr data protection generally should call me on +44 (0)20 7404 5252 or send me a message through my contact form. 

Wednesday, 24 October 2018

The Morrisons Appeal - Vicarious Liability for Enployees' Breaches of Confidence and Statutory Duty

Royal Courts of Justice
Author Rafa Esteve
Licence Creative Commons Attribution Share Alike 4.0 International
Source Wikipedia



















Jane Lambert

Court of Appeal (Sir Terence Etherton MR and Lords Justices Bean and Flaux) Various Claimants v W M Morrison Supermarkets Plc  [2018] EWCA Civ 2339 (22 Oct 2018)

In  Various Claimants v WM Morrisons Supermarkets Plc (Rev 1) [2017] EWHC 3113 (QB), [2018] 3 WLR 691, Mr Justice Langstaff held that W M Morrisons Supermarket Plc ("Morrisons") was vicariously liable to its employees for the unauthorized act of one Skelton, an internal auditor, who had posted the names, addresses, gender, dates of birth, phone numbers (home or mobile), national insurance numbers, bank sort codes, bank account numbers and salaries of Morrisons' employees to a file sharing website. Skelton had acted as he did out of spite.  He had a grudge against Morrisons and wanted to injure the company.  The judge acknowledged at para [198] of his judgment that the effect of his judgment was to accomplish that injury and for that reason he gave the supermarket chain permission to appeal.  I commented on the case in Morrisons - Primary and Vicarious Liability for Breaches of Data Protection Act 1998 11 Dec 2017.

The defendant appealed on the following grounds:
"First, the Judge ought to have concluded that, on its proper interpretation and having regard to the nature and purposes of the statutory scheme, [the Data Protection Act 1998 ("the DPA")] excludes the application of vicarious liability. Second, the Judge ought to have concluded that, on its proper interpretation, the DPA excludes the application of causes of action for misuse of private information and breach of confidence and/or the imposition of vicarious liability for breaches of the same. Third, the Judge was wrong to conclude (a) that the wrongful acts of Mr Skelton occurred during the course of his employment by Morrisons, and, accordingly, (b) that Morrisons was vicariously liable for those wrongful acts."
By their respondents' notice, the claimants sought to uphold the judge's order on the additional ground "that, in evaluating whether there was a sufficient connection between Mr Skelton's employment and his wrongful conduct to make it right for Morrisons to be held vicariously liable, the Judge ought to have taken into account that Mr Skelton's job included the task or duty delegated to him by Morrisons of preserving confidentiality in the claimants' payroll information." The appeal came on before the Master of the Rolls and Lord Justices Bean and Flaux who heard the appeal on the 9 and 10 Oct and delivered judgment on 22 Oct 2018.

Their lorsdhips dismissed Morrisons' appeal.

As for the first and second grounds, the Court concluded at para [48] that it was clear that the vicarious liability of an employer for misuse of private information by an employee and for breach of confidence by an employee had not been excluded by the Data Protection Act 1998.  The applicable principle for determining that issue was whether, on the true construction of the statute in question,  Parliament had intended to exclude vicarious liability.  The appropriate test was:
"If the statutory code covers precisely the same ground as vicarious liability at common law, and the two are inconsistent with each other in one or more substantial respects, then the common law remedy will almost certainly have been excluded by necessary implication. As Lord Dyson said in the Child Poverty Action Group case (at [34]) the question is whether, looked at as a whole, the common law remedy would be incompatible with the statutory scheme and therefore could not have been intended to coexist with it."
Their lordships reasoned that if Parliament had intended to exclude that cause of action, it would have said so expressly. Secondly, Morrisons' counsel had conceded in her submissions that the Act had not excluded the action for breach of confidence or misuse of personal information.   Their lordships observed at [56]:
"Morrisons' acceptance that the causes of action at common law and in equity operate in parallel with the DPA in respect of the primary liability of the wrongdoer for the wrongful processing of personal data while at the same time contending that vicarious liability for the same causes of action has been excluded by the DPA is, on the face of it, a difficult line to tread."
They added at [57}:
"......  the difficulty of treading that line becomes insuperable on the facts of the present case because, as was emphasised by Mr Barnes [the claimants' counsel], the DPA says nothing at all about the liability of an employer, who is not a data controller, for breaches of the DPA by an employee who is a data controller."
The concession that the causes of action for misuse of private information and breach of confidence are not excluded by the Act in respect of the wrongful processing of data within the ambit of the statute, and the complete absence of any provision addressing the situation of an employer where an employee data controller breaches the requirements of the Act, led inevitably to the conclusion that the Mr Justice Langstaff was correct to hold that the common law remedy of vicarious liability of the employer was not expressly or impliedly excluded by the Act.

In respect of the third ground of appeal, the Court referred to the judgment of Lord Toulson in Mohamud v WM Morrison Supermarkets Plc   [2016] UKSC 11, [2016] IRLR 362, [2016] ICR 485, [2016] 2 WLR 821, [2017] 1 All ER 15, [2016] AC 677, [2016] PIQR P11, [2016] WLR(D) 109.  At para [44] Lord Toulson had asked "what functions or "field of activities" have been entrusted by the employer to the employee, or, in everyday language, what was the nature of his job?"  Next "the court must decide whether there was sufficient connection between the position in which he was employed and his wrongful conduct to make it right for the employer to be held liable under the principle of social justice which goes back to Holt CJ."  As to Lord Toulson's first question, the Court of Appeal endorsed the trial judge's finding that Morrisons had entrusted Skelton with payroll data. It was part of his job to disclose it to a third party.  He had clearly exceeded his authority but that did not matter because his wrongdoing was nonetheless closely related to the task that he had to do.  As to the second part of Lord Toulson's test. the Court endorsed the Mr Justice Langstaff's finding that there was an unbroken thread that linked his work to the disclosure,

As noted above, the trial judge had been troubled by the thought that the court was facilitating Skelton's wrongdoing.  The Court of Appeal noted at para [75] that it had not been shown any  reported case in which the motive of the employee committing the wrongdoing was to harm his employer rather than to achieve some benefit for himself or to inflict injury on a third party.  Morrisons submitted that it would be wrong to impose vicarious liability on an employer in circumstances such as this especially as there were so many potential claimants.   Their lordships had no trouble in rejecting those submissions.  Motive was irrelevant and to have held otherwise would have left thousands of hapless data subjects without remedy.

In Mohamud, Lord Toulson had remarked at paea [40] of his judgment that:
"The risk of an employee misusing his position is one of life's unavoidable facts."
The solution for employers was to insure against liability for the misdeeds of their staff.   As the Master of the Rolls put it at [78]:
"There have been many instances reported in the media in recent years of data breaches on a massive scale caused by either corporate system failures or negligence by individuals acting in the course of their employment. These might, depending on the facts, lead to a large number of claims against the relevant company for potentially ruinous amounts. The solution is to insure against such catastrophes; and employers can likewise insure against losses caused by dishonest or malicious employees. We have not been told what the insurance position is in the present case, and of course it cannot affect the result. The fact of a defendant being insured is not a reason for imposing liability, but the availability of insurance is a valid answer to the Doomsday or Armageddon arguments put forward by Ms Proops on behalf of Morrisons."
 That last paragraph will be one of the reasons why this case will appear in countless skeleton arguments and law reports in the future.  The other is the Court's analysis of the circumstances when a statutory code displaces common law remedies.

Anyone wishing to discuss this case or data protection generally should call me on 020 7404 5252 or send me a message through my contact form.