“The judge erred in fact and/or his evaluative judgement when imputing knowledge onto the Defendant of the risk that the ex-partner would unlawfully misappropriate the Claimant's next-of-kin details. The Defendant's knowledge was limited to what it had been told whilst the Claimant was an employee. The Claimant stopped working for the Defendant some time prior to the index event. The Claimant confirmed in her oral evidence that she could not have anticipated what happened, let alone the Defendant. The judge imposed a counsel of perfection.”
“My conclusion from the Claimant’s evidence, linked with the above information from the Defendant’s documents, are that the Defendant well knew that the Claimant had been the victim of frightening criminal conduct on the part of Fletcher and that she was worried that he may try and contact her and that this could have serious consequences. They also either knew, or ought reasonably to have known, how important it was (particularly in the context of stalking and violence) that the Claimant’s contact details were kept safe, secure and confidential.”
“Pretexting is where the perpetrator will impersonate someone else - this could be an authority figure or someone known to you - in order to extract information or money from the victim.”
“It has at all times been common ground that liability for misuse of private information is determined by applying a two-stage test. Stage one is whether the claimant objectively has a reasonable expectation of privacy in the relevant information. If so, stage two is whether that expectation is outweighed by the publisher s right to freedom of expression. This involves a balancing exercise between the claimant’s article 8 right to privacy and the publisher’s article 10 right to freedom of expression.”
“Here, it was not DSG that disclosed the Claimant’s personal data, or misused it, but the criminal third-party hackers.”
“A malicious third party’s ability to unlawfully misappropriate information does not amount to a positive act of misuse of private information by the custodian of that information.”
“Traditionally, there are three requirements for liability for breach of confidence, authoritatively outlined by Megarry J in Coco v AN Clark (Engineers) Ltd[1969] RPC 41 , at 47. First, the information in respect of which relief is sought must have the “necessary quality of confidence about it”: per Lord Greene MR in Saltman Engineering Co Ltd v Campbell Engineering Co Ltd(1948) 65 RPC 203 , at 215. Secondly, the information must have been imparted in circumstances importing an obligation of confidence. The use of the word “imparted”, however, is now clearly too limited for the modern action, it now being established that there is no need for an initial confidential relationship. Thirdly, there must be an unauthorised use or disclosure of that information.”
“The Claimant’s confidential information was kept by the Defendant for three months after the cessation of her work. It seems to me that this is not, per se, unreasonable in that it may have been necessary to contact the Claimant for work-related matters for some short number of months after the termination of her employment.”
“I have also considered the issue of a split to see whether I should say because it applies to part of the claim and that therefore I ought to say that it applies only to certain parts or certain percentages. Again, I am not attracted by that argument. It seems to me that the facts here were fairly composite and whilst three different headings were put on the same facts, those are different legal arguments essentially relating to the first point. If the defendant had, for example, said we admit the misuse of private information but deny the DPA claim, it may well be that my findings would have been different. But in the absence of that sort of splitting approach between the parties, it seems that I should deal with this as one and I find in favour of the claimant for those reasons.”