![]() |
[Home] [Databases] [World Law] [Multidatabase Search] [Help] [Feedback] [DONATE] | |
England and Wales Court of Appeal (Civil Division) Decisions |
||
|
You are here: BAILII >> Databases >> England and Wales Court of Appeal (Civil Division) Decisions >> WM Morrison Supermarkets Plc v Various Claimants [2018] EWCA Civ 2339 (22 October 2018) URL: https://www.bailii.org/ew/cases/EWCA/Civ/2018/2339.html Cite as: [2019] QB 772, [2019] ICR 357, [2019] 2 WLR 99, [2019] 2 All ER 579, [2018] WLR(D) 653, [2019] IRLR 73, [2018] EWCA Civ 2339 |
||
[New search]
[Context
]
[View without highlighting]
[Printable RTF version]
[Buy ICLR report: [2019] 2 WLR 99]
[Buy ICLR report: [2019] QB 772]
[View ICLR summary: [2018] WLR(D) 653]
[Help]
ON APPEAL FROM THE HIGH COURT OF JUSTICE
QUEEN'S BENCH DIVISION
THE HON. MR JUSTICE LANGSTAFF
Strand, London, WC2A 2LL |
||
B e f o r e :
LORD JUSTICE BEAN
and
LORD JUSTICE FLAUX
____________________
WM MORRISON SUPERMARKETS PLC | Appellant |
|
| - and - |
||
| VARIOUS CLAIMANTS |
Respondent |
____________________
Jonathan Barnes and Victoria Jolliffe (instructed by JMW Solicitors LLP) for the Respondents
Hearing dates: 9 and 10 October 2018
____________________
Crown Copyright ©
Sir Terence Etherton MR, Lord Justice Bean and Lord Justice Flaux:
Introduction
Wm
Morrison
Supermarkets
plc
("
Morrisons"),
which is the defendant in the proceedings, is liable in damages to the claimants, who are over 5,000 employees or former employees of
Morrisons,
for the acts of disclosure of their personal information by a former employee, Andrew Skelton.
Morrisons
is vicariously liable to the claimants for the actions of Mr Skelton.
Background
Morrisons.
Following a disciplinary hearing for an incident involving his unauthorised use of
Morrisons'
postal facilities for his private purposes, he was given a formal verbal warning on 18 July 2013. Mr Skelton was annoyed by the disciplinary proceedings and the sanction. They left him with a grudge against
Morrisons.
Morrisons'
external auditor, requested a number of categories of data from
Morrisons
in order to undertake the annual audit. That request included a copy of
Morrisons'
payroll data. Michael Leighton, of the HR department, copied the data onto an encrypted USB stick. He took the USB stick personally to Mr Skelton, who downloaded the data from the stick onto his laptop computer, which was itself encrypted. Mr Skelton subsequently copied the data onto another encrypted USB stick, which had been supplied by KPMG, and which he returned to KPMG.
Morrisons
on a file sharing website. He used the initials and date of birth of another employee in a deliberate attempt to frame him. Shortly afterwards, links to the website were also placed elsewhere on the web. The data consisted of the names, addresses, gender, dates of birth, phone numbers (home or mobile), national insurance numbers, bank sort codes, bank account numbers and the salary which the employee in question was being paid.
Morrisons
has its head office. The anonymous sender purported to be a concerned person who had worryingly discovered that payroll data relating to almost 100,000
Morrisons'
employees was available on the web. The covering letter with the CD gave a link to the file-sharing site.
Morrisons
of it.
Morrisons
was about to announce its annual financial reports. The revelation of the data leak had serious implications for the share value of
Morrisons.
There was also an immediate concern that the information might be used by outsiders to access the bank accounts of individual employees or used to aid identity theft.
Morrisons'
head management was alerted to the disclosure on 13 March 2014. Within a few hours they had taken steps to ensure that the website had been taken down.
Morrisons
also alerted the police.
The DPA
The proceedings
Morrisons
is primarily liable under those heads of claim but, if not, then
Morrisons
is liable vicariously for the wrongful conduct of Mr Skelton.
Morrisons
served a Defence dated 3 February 2016 denying all liability.
The judgment
Morrisons
was not the data controller at the time of any breach of Data Protection Principles ("DPP") 1, 2, 3 and 5 in respect of the information later disclosed on the web, and accordingly
Morrisons
owed no duty to the claimants under the DPA in respect of which it was in breach, unless it were the duty to comply with DPP 7. Mr Skelton was the data controller in respect of that information.
Morrisons
was not directly liable in respect of any breach of confidence or misuse of private information since it was not
Morrisons
which disclosed the information or misused it. It was Mr Skelton, acting without authority and criminally.
Morrisons
fell short of its obligations under DPP 7 while it was the data controller: failing to manage/mentor Mr Skelton to prevent a grudge developing; failing to monitor Mr Skelton's IT usage so as to identify that Mr Leighton's initial attempt to send the data to Mr Skelton's computer had bounced back (having been intercepted by
Morrisons'
"quarantine" area, designed to divert for further attention emails that for some reason may be suspicious); failing to identify that Mr Skelton was researching the "TOR" (acronym for "The Onion Router") network (for software which is capable of disguising the individual identity of a computer which has accessed the internet); failing to deny Mr Skelton access to the data; providing the data to Mr Skelton via a USB stick which was not encrypted; and failing to ensure that Mr Skelton deleted the data from his computer by about 21 November 2013.
Morrisons
had provided adequate and appropriate controls in relation to each of those matters. The Judge made the following particular findings, among others, on those particular matters. He said (at [95]) that the incident for which Mr Skelton was disciplined did not itself suggest that Mr Skelton was not to be trusted. The Judge found (at [96]) that the technological and organisational measures current in 2013 and 2014 at their best could not altogether prevent the risk posed by a rogue employee who was trusted and had given no reason to doubt his trustworthiness. The Judge said (at [97]) that no one in employment at
Morrisons
knew, nor ought they to have known, that Mr Skelton bore a grudge against
Morrisons,
and was not to be trusted with data. The Judge found (at [97]) that, even if a senior manager had been aware that the email sent by Mr Leighton to Mr Skelton, attaching the payroll data, had bounced back, it would not have alerted
Morrisons
to the risk which Mr Skelton posed to the data.
Morrisons
should have been aware that Mr Skelton was attempting to research the TOR network on the grounds that it was not feasible, sensible or practicable for
Morrisons
to have implemented a system that could proactively have detected that Mr Skelton was researching the TOR network when he did, and, moreover, any such system would probably have amounted to an unlawful interference with employees' rights to privacy and family life. The Judge added (at [110]) that, even if there had been a failure to monitor employees' internet search usage, it is unlikely that it would have prevented the data disclosure by Mr Skelton. The Judge found (at [111]) that the USB stick used to convey the payroll data to Mr Skelton was encrypted and its use was not a breach of DPP 7, nor did the use of it cause or contribute to the disclosure which later occurred.
Morrisons
fell short of the requirements of DPP 7. He said that, where data is held outside the usual secure repository used for it, there is an unnecessary risk of proliferation and of inadvertent disclosure (let alone deliberate action by an employee) revealing some of that data.
Morrisons
took that risk and did not need to do so. Organisational measures which would have been neither too difficult nor too onerous to implement could have been adopted to minimise it. The Judge also found (at [121]), however, that in the particular circumstances of the present case, by the time it would have been appropriate to conduct any check on deletion, the probability was that the information had already been copied by Mr Skelton; and, accordingly, to the extent that
Morrisons
fell short of DPP 7 in its duty to take appropriate organisational measures to guard against unlawful disclosure and data loss, that failure neither caused nor contributed to the disclosure which occurred.
Morrisons
did not directly misuse or authorise or carelessly permit the misuse of any information personal to the employees, the Judge dismissed (at [124]-[126]) the claims against
Morrisons
in equity and at common law for primary liability for breach of confidence and misuse of personal information.
Morrisons'
vicarious liability. He rejected what he described as two preliminary points on vicarious liability advanced by
Morrisons.
The first was whether the DPA by its terms excludes any possibility of vicarious liability. The second was whether the effect of the DPA was to exclude any scope for vicarious liability under the common law tort of misuse of private information or the equitable action for breach of confidence.
Morrison
Supermarkets
plc
[2016] UKSC 11; [2016] AC 677, Bellman v Northampton Recruitment Ltd [2016] EWHC 3104, QB; [2017] ICR 543, and Various Claimants v Barclays Bank
plc
[2017] EWHC 1929 (QB) 126; [2017] IRLR 1103, rejected both points.
Morrisons,
to make it right for
Morrisons
to be held vicariously liable, whether for breach of duty under the DPA, a misuse of private information, or a breach of the duty of confidence. The findings of fact which led him to that conclusion are set out in [184] of the judgment, which we quote at [73] below.
Grounds of appeal
Morrisons,
and, accordingly, (b) that
Morrisons
was vicariously liable for those wrongful acts.
Respondent's notice
Morrisons
to be held vicariously liable, the Judge ought to have taken into account that Mr Skelton's job included the task or duty delegated to him by
Morrisons
of preserving confidentiality in the claimants' payroll information.
Morrisons
for breach of its statutory duties under the DPA; and neither side challenges the Judge's finding that Mr Skelton, and not
Morrisons,
was the data controller under the DPA in respect of the data wrongfully copied by Mr Skelton onto his personal USB stick and subsequently disclosed by him on the internet (as to which, see Ittihadieh v 5-11 Cheyne Gardens RTM Co Ltd [2017] EWCA Civ 121, [2018] QB 256 at [70]-[71]).
Discussion
The first and second grounds of appeal
Morrisons'
contention that, in relation to the processing of personal data within the ambit of the DPA, it is a necessary implication of the DPA that there can be no vicarious liability for the common law tort of misuse of private information or for breach of the equitable duty of confidence.
Morrisons
on the ground of vicarious liability for the statutory tort of breach of the DPA by Mr Skelton. The pleaded claim against
Morrisons
under the DPA is in respect of its primary liability for breach of its own direct statutory obligations imposed by the DPA. In the prayer to the Particulars of Claim damages are claimed pursuant to section 13 of the DPA for breach of
Morrisons'
own statutory duties. The other two heads of claim in the prayer to the Particulars of Claim are for damages for misuse of private information and damages for breach of confidence.
Morrisons'
vicarious liability arises, if at all, under those causes of action in respect of Mr Skelton's wrongful acts.
Morrisons'
perspective the issue is simply a plank in its argument that the DPA provides a comprehensive statutory code for the wrongful processing of personal data, and it expressly or impliedly excludes any scope for liability on an employer for the wrongful processing of personal data by an employee, whether the data controller is the employer or the employee.
Morrisons,
made extensive and elaborate submissions on the first and second grounds of appeal but the essence of her argument may be simply stated as follows.
"96 The harmonisation of those national laws is therefore not limited to minimal harmonisation but amounts to harmonisation which is generally complete. It is on that view that Directive 95/46 is intended to ensure free movement of personal data while guaranteeing a high level of protection for the rights and interests of the individuals to whom such data relate.
97 It is true that Directive 95/46 allows the member states a margin for manoeuvre in certain areas and authorises them to maintain or introduce particular rules for specific situations, as a large number of its provisions demonstrate. However, such possibilities must be made use of in the manner provided for by Directive 95/46 and in accordance with its objective of maintaining a balance between the free movement of personal data and the protection of private life.
98 On the other hand, nothing prevents a member state from extending the scope of the national legislation implementing the provisions of Directive 95/46 to areas not included within the scope thereof, provided that no other provision of Community law precludes it.
99 In the light of those considerations, the answer to the seventh question must be that measures taken by the member states to ensure the protection of personal data must be consistent both with the provisions of Directive 95/46 and with its objective of maintaining a balance between freedom of movement of personal data and the protection of private life. However, nothing prevents a member state from extending the scope of the national legislation implementing the provisions of Directive 95/46 to areas not included in the scope thereof, provided that no other provision of Community law precludes it."
"33 If the two remedies cover precisely the same ground and are inconsistent with each other, then the common law remedy will almost certainly have been excluded by necessary implication. To do otherwise would circumvent the intention of Parliament. A good example of this is Marcic, where a sewerage undertaker was subject to an elaborate scheme of statutory regulation which included an independent regulator with powers of enforcement whose decisions were subject to judicial review. The statutory scheme provided a procedure for making complaints to the regulator. The House of Lords held that a cause of action in nuisance would be inconsistent with the statutory scheme. It would run counter to the intention of Parliament.
34 The question is not whether there are any differences between the common law remedy and the statutory scheme. There may well be differences. The question is whether the differences are so substantial that they demonstrate that Parliament could not have intended the common law remedy to survive the introduction of the statutory scheme. The court should not be too ready to find that a common law remedy has been displaced by a statutory one, not least because it is always open to Parliament to make the position clear by stating explicitly whether the statute is intended to be exhaustive. The mere fact that there are some differences between the common law and the statutory positions is unlikely to be sufficient unless they are substantial. The fact that the House of Lords was divided in Total Network SL [2008] AC 1174 shows how difficult it may sometimes be to decide on which side of the line a case falls. The question is whether, looked at as a whole, a common law remedy would be incompatible with the statutory scheme and therefore could not have been intended by coexist with it.
Morrisons
contend that the terms of the DPA expressly or impliedly exclude the continued imposition of vicarious liability under the common law on an employer for breach of the statutory duty of an employee data controller to comply with the DPA.
Morrisons'
proposition in the present case that the DPA has by necessary implication excluded an employer's vicarious liability at common law for an employee's misuse of private information and breach of confidence.
Morrisons'
acceptance that the causes of action at common law and in equity operate in parallel with the DPA in respect of the primary liability of the wrongdoer for the wrongful processing of personal data while at the same time contending that vicarious liability for the same causes of action has been excluded by the DPA is, on the face of it, a difficult line to tread. That is not least because it may be said to present an inconsistency in the application of one of the principal objects of the Directive and of the DPA, namely the protection of privacy and the provision of an effective remedy for its infringement (including by an employee of limited means), rather than their curtailment.
Morrisons,
was the data controller under the DPA in respect of that data. As Ms Proops herself repeatedly emphasised in her submissions, in terms of processing duties and liability, the DPA is only concerned with the primary liability and obligations of the data controller. It has nothing at all to say about the liability of someone else for wrongful processing by the data controller. Parliament has not entered that field at all.
The third ground of appeal
Wm
Morrison
Supermarkets
plc
[2016] AC 667. In that case, a petrol pump attendant (Mr Khan) assaulted a customer. Lord Toulson JSC, with whom all the other Justices agreed (though Lord Dyson MR gave a separate judgment) said at [40] that:-
"The risk of an employee misusing his position is one of life's unavoidable facts."
"44. In the simplest terms, the court has to consider two matters. The first question is what functions or "field of activities" have been entrusted by the employer to the employee, or, in everyday language, what was the nature of his job. As has been emphasised in several cases, this question must be addressed broadly……..
45. Secondly, the court must decide whether there was sufficient connection between the position in which he was employed and his wrongful conduct to make it right for the employer to be held liable under the principle of social justice which goes back to Holt CJ. To try to measure the closeness of connection, as it were, on a scale of 1 to 10, would be a forlorn exercise and, what is more, it would miss the point. The cases in which the necessary connection has been found for Holt CJ's principle to be applied are cases in which the employee used or misused the position entrusted to him in a way which injured the third party. Lloyd v Grace, Smith & Co, Pettersson v Royal Oak Hotel Ltd and Lister v Hesley Hall Ltd were all cases in which the employee misused his position in a way which injured the claimant, and that is the reason why it was just that the employer who selected him and put him in that position should be held responsible. By contrast, in Warren v Henlys Ltd any misbehaviour by the petrol pump attendant, qua petrol pump attendant, was past history by the time that he assaulted the claimant. The claimant had in the meantime left the scene, and the context in which the assault occurred was that he had returned with the police officer to pursue a complaint against the attendant.
46. Contrary to the primary submission advanced on the claimant's behalf, I am not persuaded that there is anything wrong with the Lister approach as such. It has been affirmed many times and I do not see that the law would now be improved by a change of vocabulary. Indeed, the more the argument developed, the less clear it became whether the claimant was advocating a different approach as a matter of substance and, if so, what the difference of substance was.
…
48. Mr Khan's motive is irrelevant. It looks obvious that he was motivated by personal racism rather than a desire to benefit his employer's business, but that is neither here nor there."
"185. …….I find thatMorrisons
deliberately entrusted Skelton with the payroll data. It was not merely something to which work gave him access: dealing with the data was a task specifically assigned to him. Associated with this, I find that in his role with
Morrisons,
day in and day out, he was in receipt of information which was confidential or to have limited circulation only: and he was appointed on the basis that this would happen, and he could be trusted to deal with it safely.
Morrisons
took the risk they might be wrong in placing the trust in him.
186. …..[H]is role in respect of the payroll data was to receive and store it, and to disclose it to a third party. That in essence was his task, so far as the payroll data went: the fact that he chose to disclose it to others than KPMG was not authorised, but it was nonetheless closely related to what he was tasked to do."
Morrisons'
submissions, the original copying in November 2013 was done in the course of employment, the disclosure was not. Ms Proops relied on Credit Lyonnais Bank Nederland NV v Export Credits Guarantee Department [2000] 1 AC 486 for the proposition that every necessary element of the tort which founds liability must occur within the course of employment if vicarious liability is to apply. Lord Woolf MR said at page 495:-
"[the] conduct for which the servant is responsible must constitute an actionable tort and to make the employer responsible for that tort the conduct necessary to establish the employee's liability must have occurred within the course of employment. … Before these can be vicarious liability, all the features of the wrong which are necessary to make the employee liable have to have occurred in the course of the employment."
"whether acts which were committed without the course of employment, which were not in themselves tortious, could be aggregated with acts of another party so as to render the employee a joint tortfeasor with that party, for whose joint acts the employer would be held vicariously liable."
"31. In Warren v Henlys Ltd [1948] 2 All ER 935 a customer at a petrol station had an angry confrontation with the petrol station attendant, who wrongly suspected him of trying to make off without payment. The customer became enraged at the manner in which he was spoken to by the attendant. After paying for the petrol, the customer saw a passing police car and drove off after it. He complained to the police officer about the attendant's conduct and persuaded the officer to return with him to the petrol station. The officer listened to both men and indicated that he did not think that it was a police matter, whereupon the customer said that he would report the attendant to his employer. The officer was on the point of leaving, when the attendant punched the customer in the face, knocking him to the ground.
32. Hilbery J held that the assault was not committed in the course of the attendant's employment, applying the Salmond formula. By the time that the assault happened the customer's business with the petrol station had ended, the petrol had been paid for and the customer had left the premises. When he returned with the police officer it was for the purpose of making a personal complaint about the attendant. The attendant reacted violently to being told that the customer was going to report him to his employer, but there was no basis for holding the employer vicariously liable for that behaviour. The judge was right to dismiss the customer's claim against the petrol company. At the time of the incident the relationship between the plaintiff and the attendant had changed from that of customer and representative of the petrol company to that of a person making a complaint to the police and the subject of the complaint. In Lister v Hesley Hall Ltd [2002] 1 AC 215 Lord Millett commented, at para 80, that "the better view may have been that the employer was not liable because it was no part of the duties of the pump attendant to keep order", but there is no suggestion in the report of the case that there was any other employee in practical charge of the forecourt and cash desk area. If the attendant had punched the customer because he believed, rightly or wrongly, that the customer was leaving without payment, I would regard such conduct as occurring within the course of his employment."
"It seems to me that it was an act entirely of personal vengeance. He was personally inflicting punishment, and intentionally inflicting punishment, on the Plaintiff because the Plaintiff proposed to take a step which might affect Beaumont in his own personal affairs. It had no connection whatever with the discharge of any duty for the Defendants. The act of assault by Beaumont was done by him in relation to a personal matter affecting his personal interests and there is no evidence that it was otherwise."
Morrisons.
"… I reject Ms Proops' argument that the disclosure on the web of the payroll data was disconnected by time, place and nature from Skelton's employment. I find, rather, that as Mr Barnes submitted there was an unbroken thread that linked his work to the disclosure: what happened was a seamless and continuous sequence of events. My reasons for this are first that in October, prior to knowing he was again to be a conduit for payroll data between PeopleSoft and KPMG, Skelton showed signs of interest in the TOR network. When he knew (on 1st. November) that he was indeed to be the go-between, he obtained the mobile phone he was later to use just for making the criminal disclosures. He brought in a personal USB stick to work and copied payroll information to it in mid-November. Lying low for a while after that was necessary to create an appearance of separation and to avoid suspicion falling on him too readily. He again investigated TOR in December; adopted the user name and date of birth of a colleague to draw the blame onto him when setting up an account from which to upload the payroll data to the web; sent data to a web-sharing web-site in January, and either because that did not excite any great immediate interest, or because he had planned in advance to cause the maximum embarrassment toMorrisons
immediately prior to the announcement of their financial results, sent the anonymous letters he did to three newspapers in March 2014. These actions were in my view all part of a plan, as the research and careful attempts to hide his tracks indicate. As I have already noted (para. 22 above) this is precisely the same view as that taken by HHJ Thomas QC when sentencing Skelton. This was no sequence of random events, but an unbroken chain beginning even before, but including, the first unlawful act of downloading data from his personal work computer to a personal USB stick."
Morrisons
in these circumstances would render the court an accessory in furthering Mr Skelton's criminal aims. As we said at [32] above, this was the point which troubled the Judge and which appears to have persuaded him to grant
Morrisons
permission to appeal.
Morrisons
and could place on other innocent employers in future cases. These arguments are unconvincing. As it happens Mr Skelton's nefarious activities involved the data of a very large number of employees although, so far as we are aware, none of them has suffered financial loss. But suppose he had misused the data so as to steal a large sum of money from one employee's bank account. If
Morrisons'
arguments are correct, then (save for any possible claim against the bank) such a victim would have no remedy except against Mr Skelton personally. Yet this hypothetical claimant would, as it seems to us, be in essentially the same position as Mrs Lloyd in Lloyd v Grace, Smith.
Morrisons.
Conclusion
Morrisons was vicariously liable for the torts committed by Mr Skelton against the claimants. The appeal is dismissed.
…………………………………………………………………………………..
The following provisions of the Directive were mentioned in oral submissions before us.
Recitals
(2) Whereas data-processing systems are designed to serve man; whereas they must, whatever the nationality or residence of natural persons, respect their fundamental rights and freedoms, notably the right to privacy, and contribute to economic and social progress, trade expansion and the well-being of individuals;
(4) Whereas increasingly frequent recourse is being had in the Community to the processing of personal data in the various spheres of economic and social activity; whereas the progress made in information technology is making the processing and exchange of such data considerably easier;
(5) Whereas the economic and social integration resulting from the establishment and functioning of the internal market within the meaning of Article 7a of the Treaty will necessarily lead to a substantial increase in cross-border flows of personal data between all those involved in a private or public capacity in economic and social activity in the Member States; whereas the exchange of personal data between undertakings in different Member States is set to increase; whereas the national authorities in the various Member States are being called upon by virtue of Community law to collaborate and exchange personal data so as to be able to perform their duties or carry out tasks on behalf of an authority in another Member State within the context of the area without internal frontiers as constituted by the internal market;
(7) Whereas the difference in levels of protection of the rights and freedoms of individuals, notably the right to privacy, with regard to the processing of personal data afforded in the Member States may prevent the transmission of such data from the territory of one Member State to that of another Member State; whereas this difference may therefore constitute an obstacle to the pursuit of a number of economic activities at Community level, distort competition and impede authorities in the discharge of their responsibilities under Community law; whereas this difference in levels of protection is due to the existence of a wide variety of national laws, regulations and administrative provisions;
(8) Whereas, in order to remove the obstacles to flows of personal data, the level of protection of the rights and freedoms of individuals with regard to the processing of such data must be equivalent in all Member States; whereas this objective is vital to the internal market but cannot be achieved by the Member States alone, especially in view of the scale of the divergences which currently exist between the relevant laws in the Member States and the need to coordinate the laws of the Member States so as to ensure that the cross-border flow of personal data is regulated in a consistent manner that is in keeping with the objective of the internal market as provided for in Article 7a of the Treaty; whereas Community action to approximate those laws is therefore needed;
(10) Whereas the object of the national laws on the processing of personal data is to protect fundamental rights and freedoms, notably the right to privacy, which is recognized both in Article 8 of the European Convention for the Protection of Human Rights and Fundamental Freedoms and in the general principles of Community law; whereas, for that reason, the approximation of those laws must not result in any lessening of the protection they afford but must, on the contrary, seek to ensure a high level of protection in the Community;
(11) Whereas the principles of the protection of the rights and freedoms of individuals, notably the right to privacy, which are contained in this Directive, give substance to and amplify those contained in the Council of Europe Convention of 28 January 1981 for the Protection of Individuals with regard to Automatic Processing of Personal Data;
SECTION I
PRINCIPLES RELATING TO DATA QUALITY
Article 6
1. Member States shall provide that personal data must be:
(a) processed fairly and lawfully;
(b) collected for specified, explicit and legitimate purposes and not further processed in a way incompatible with those purposes. Further processing of data for historical, statistical or scientific purposes shall not be considered as incompatible provided that Member States provide appropriate safeguards;
(c) adequate, relevant and not excessive in relation to the purposes for which they are collected and/or further processed;
(d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that data which are inaccurate or incomplete, having regard to the purposes for which they were collected or for which they are further processed, are erased or rectified;
(e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the data were collected or for which they are further processed. Member States shall lay down appropriate safeguards for personal data stored for longer periods for historical, statistical or scientific use.
2. It shall be for the controller to ensure that paragraph 1 is complied with.
SECTION IV
INFORMATION TO BE GIVEN TO THE DATA SUBJECT
Article 10
Information in cases of collection of data from the data subject
Member States shall provide that the controller or his representative must provide a data subject from whom data relating to himself are collected with at least the following information, except where he already has it:
(a) the identity of the controller and of his representative, if any;
(b) the purposes of the processing for which the data are intended;
(c) any further information such as
- the recipients or categories of recipients of the data,- whether replies to the questions are obligatory or voluntary, as well as the possible consequences of failure to reply,- the existence of the right of access to and the right to rectify the data concerning him
in so far as such further information is necessary, having regard to the specific circumstances in which the data are collected, to guarantee fair processing in respect of the data subject.
Article 11
Information where the data have not been obtained from the data subject
1. Where the data have not been obtained from the data subject, Member States shall provide that the controller or his representative must at the time of undertaking the recording of personal data or if a disclosure to a third party is envisaged, no later than the time when the data are first disclosed provide the data subject with at least the following information, except where he already has it:
(a) the identity of the controller and of his representative, if any;
(b) the purposes of the processing;
(c) any further information such as
- the categories of data concerned,- the recipients or categories of recipients,- the existence of the right of access to and the right to rectify the data concerning him
in so far as such further information is necessary, having regard to the specific circumstances in which the data are processed, to guarantee fair processing in respect of the data subject.
2. Paragraph 1 shall not apply where, in particular for processing for statistical purposes or for the purposes of historical or scientific research, the provision of such information proves impossible or would involve a disproportionate effort or if recording or disclosure is expressly laid down by law. In these cases Member States shall provide appropriate safeguards.
CONFIDENTIALITY AND SECURITY OF PROCESSING
Article 17
Security of processing
1. Member States shall provide that the controller must implement appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access, in particular where the processing involves the transmission of data over a network, and against all other unlawful forms of processing.
Having regard to the state of the art and the cost of their implementation, such measures shall ensure a level of security appropriate to the risks represented by the processing and the nature of the data to be protected.
2. The Member States shall provide that the controller must, where processing is carried out on his behalf, choose a processor providing sufficient guarantees in respect of the technical security measures and organizational measures governing the processing to be carried out, and must ensure compliance with those measures.
3. The carrying out of processing by way of a processor must be governed by a contract or legal act binding the processor to the controller and stipulating in particular that:
- the processor shall act only on instructions from the controller,
- the obligations set out in paragraph 1, as defined by the law of the Member State in which the processor is established, shall also be incumbent on the processor.
4. For the purposes of keeping proof, the parts of the contract or the legal act relating to data protection and the requirements relating to the measures referred to in paragraph 1 shall be in writing or in another equivalent form.
CHAPTER III JUDICIAL REMEDIES, LIABILITY AND SANCTIONS
Article 23
Liability
1. Member States shall provide that any person who has suffered damage as a result of an unlawful processing operation or of any act incompatible with the national provisions adopted pursuant to this Directive is entitled to receive compensation from the controller for the damage suffered.
2. The controller may be exempted from this liability, in whole or in part, if he proves that he is not responsible for the event giving rise to the damage.
…………………………………………………………………………………………
1. Basic interpretative provisions
(1)In this Act, unless the context otherwise requires—
"data" means information which—
(a) is being processed by means of equipment operating automatically in response to instructions given for that purpose,
(b) is recorded with the intention that it should be processed by means of such equipment,
(c) is recorded as part of a relevant filing system or with the intention that it should form part of a relevant filing system, or
(d) does not fall within paragraph (a), (b) or (c) but forms part of an accessible record as defined by section 68;
(e) is recorded information held by a public authority and does not fall within any of paragraphs (a) to (d);
"data controller" means, subject to subsection (4), a person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any personal data are, or are to be, processed;
"data processor", in relation to personal data, means any person (other than an employee of the data controller) who processes the data on behalf of the data controller;
"data subject" means an individual who is the subject of personal data;
"personal data" means data which relate to a living individual who can be identified—
(a) from those data, or
(b) from those data and other information which is in the possession of, or is likely to come into the possession of, the data controller,
and includes any expression of opinion about the individual and any indication of the intentions of the data controller or any other person in respect of the individual;
"processing", in relation to information or data, means obtaining, recording or holding the information or data or carrying out any operation or set of operations on the information or data, including—
(a) organisation, adaptation or alteration of the information or data,
(b) retrieval, consultation or use of the information or data,
(c) disclosure of the information or data by transmission, dissemination or otherwise making available, or
(d) alignment, combination, blocking, erasure or destruction of the information or data;
(2)In this Act, unless the context otherwise requires—
(a)"obtaining" or "recording", in relation to personal data, includes obtaining or recording the information to be contained in the data, and
(b)"using" or "disclosing", in relation to personal data, includes using or disclosing the information contained in the data.
4. The data protection principles
(1)References in this Act to the data protection principles are to the principles set out in Part I of Schedule 1.
(2)Those principles are to be interpreted in accordance with Part II of Schedule 1.
(3) ….
(4)Subject to section 27(1), it shall be the duty of a data controller to comply with the data protection principles in relation to all personal data with respect to which he is the data controller.
13. Compensation for failure to comply with certain requirements
(1)An individual who suffers damage by reason of any contravention by a data controller of any of the requirements of this Act is entitled to compensation from the data controller for that damage.
(2)An individual who suffers distress by reason of any contravention by a data controller of any of the requirements of this Act is entitled to compensation from the data controller for that distress if—
(a)the individual also suffers damage by reason of the contravention, or
(b)the contravention relates to the processing of personal data for the special purposes.
(3)In proceedings brought against a person by virtue of this section it is a defence to prove that he had taken such care as in all the circumstances was reasonably required to comply with the requirement concerned.
5 Unlawful obtaining etc. of personal data
(1)A person must not knowingly or recklessly, without the consent of the data controller—
(a)obtain or disclose personal data or the information contained in personal data, or
(b)procure the disclosure to another person of the information contained in personal data.
(2)Subsection (1) does not apply to a person who shows—
(a)that the obtaining, disclosing or procuring—
(i)was necessary for the purpose of preventing or detecting crime, or(ii)was required or authorised by or under any enactment, by any rule of law or by the order of a court,
(b)that he acted in the reasonable belief that he had in law the right to obtain or disclose the data or information or, as the case may be, to procure the disclosure of the information to the other person,
(c)that he acted in the reasonable belief that he would have had the consent of the data controller if the data controller had known of the obtaining, disclosing or procuring and the circumstances of it, or
(d)that in the particular circumstances the obtaining, disclosing or procuring was justified as being in the public interest.
(3)A person who contravenes subsection (1) is guilty of an offence.
(4)A person who sells personal data is guilty of an offence if he has obtained the data in contravention of subsection (1).
(5)A person who offers to sell personal data is guilty of an offence if—
(a)he has obtained the data in contravention of subsection (1), or
(b)he subsequently obtains the data in contravention of that subsection.
(6)For the purposes of subsection (5), an advertisement indicating that personal data are or may be for sale is an offer to sell the data.
(7)Section 1(2) does not apply for the purposes of this section; and for the purposes of subsections (4) to (6), "personal data" includes information extracted from personal data.
(8)References in this section to personal data do not include references to personal data which by virtue of section 28 are exempt from this section.
Part I The principles
1Personal data shall be processed fairly and lawfully and, in particular, shall not be processed unless—
(a)at least one of the conditions in Schedule 2 is met, and
(b)in the case of sensitive personal data, at least one of the conditions in Schedule 3 is also met.
2 Personal data shall be obtained only for one or more specified and lawful purposes, and shall not be further processed in any manner incompatible with that purpose or those purposes.
3 Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed.
4 Personal data shall be accurate and, where necessary, kept up to date.
5 Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes.
6 Personal data shall be processed in accordance with the rights of data subjects under this Act.
7 Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.
8 Personal data shall not be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.
Part II Interpretation of the principles in Part I
The first principle
1(1)In determining for the purposes of the first principle whether personal data are processed fairly, regard is to be had to the method by which they are obtained, including in particular whether any person from whom they are obtained is deceived or misled as to the purpose or purposes for which they are to be processed.
(2)Subject to paragraph 2, for the purposes of the first principle data are to be treated as obtained fairly if they consist of information obtained from a person who—
(a)is authorised by or under any enactment to supply it, or
(b)is required to supply it by or under any enactment or by any convention or other instrument imposing an international obligation on the United Kingdom.
2(1)Subject to paragraph 3, for the purposes of the first principle personal data are not to be treated as processed fairly unless—
(a)in the case of data obtained from the data subject, the data controller ensures so far as practicable that the data subject has, is provided with, or has made readily available to him, the information specified in sub-paragraph (3), and
(b)in any other case, the data controller ensures so far as practicable that, before the relevant time or as soon as practicable after that time, the data subject has, is provided with, or has made readily available to him, the information specified in sub-paragraph (3).
(2)In sub-paragraph (1)(b) "the relevant time" means—
(a)the time when the data controller first processes the data, or
(b)in a case where at that time disclosure to a third party within a reasonable period is envisaged—
(i)if the data are in fact disclosed to such a person within that period, the time when the data are first disclosed,(ii)if within that period the data controller becomes, or ought to become, aware that the data are unlikely to be disclosed to such a person within that period, the time when the data controller does become, or ought to become, so aware, or(iii)in any other case, the end of that period.
(3)The information referred to in sub-paragraph (1) is as follows, namely—
(a)the identity of the data controller,
(b)if he has nominated a representative for the purposes of this Act, the identity of that representative,
(c)the purpose or purposes for which the data are intended to be processed, and
(d)any further information which is necessary, having regard to the specific circumstances in which the data are or are to be processed, to enable processing in respect of the data subject to be fair.
The seventh principle
9Having regard to the state of technological development and the cost of implementing any measures, the measures must ensure a level of security appropriate to—
(a)the harm that might result from such unauthorised or unlawful processing or accidental loss, destruction or damage as are mentioned in the seventh principle, and
(b)the nature of the data to be protected.
10The data controller must take reasonable steps to ensure the reliability of any employees of his who have access to the personal data.
11Where processing of personal data is carried out by a data processor on behalf of a data controller, the data controller must in order to comply with the seventh principle—
(a)choose a data processor providing sufficient guarantees in respect of the technical and organisational security measures governing the processing to be carried out, and
(b)take reasonable steps to ensure compliance with those measures.
Note 1 The paragraph numbers in the Weekly Law Reports differ from those on BAILII because the latter has two paragraph 35s. This judgment uses the numbers in the reports.
[Back]