“(2) A claim is made for an injunction ordering the defendant to do or refrain from doing an act within the jurisdiction. (9) A claim is made in tort where (a) damage was sustained within the jurisdiction; or (b) the damage sustained resulted from an act committed within the jurisdiction.”
“(11) The whole subject matter of a claim relates to property located within the jurisdiction. (16) A claim is made for restitution where the defendant’s alleged liability arises out of acts committed within the jurisdiction.”
“84 The general rule is that it is not normally appropriate in a summary procedure (such as an application to strike out or for summary judgment) to decide a controversial question of law in a developing area, particularly because it is desirable that the facts should be found so that any further development of the law should be on the basis of actual and not hypothetical facts: e.g. Lonrho Plc. v. Fayed [1992] 1 A.C. 448 , 469 (approving Dyson v Att-Gen[1911] 1 KB 410 , 414: summary procedure "ought not to be applied to an action involving serious investigation of ancient law and questions of general importance ..."); X (Minors) v Bedfordshire County Council[1995] 2 AC 633 at 741 ("Where the law is not settled but is in a state of development … it is normally inappropriate to decide novel questions on hypothetical facts"); Barrett v Enfield London BC[2001] 2 AC 550 , 557 (strike out cases); Home and Overseas Insurance Co. Ltd. v Mentor Insurance Co. (U.K.) Ltd.[1990] 1 WLR 153 (summary judgment). In the context of interlocutory injunctions, in the famous case of American Cyanamid Co v Ethicon Ltd[1975] AC 396 , 407 it was held that the court must be satisfied that the claim is not frivolous or vexatious, in other words, that there is a serious question to be tried. It was no part of the court's function "to decide difficult questions of law which call for detailed argument and mature consideration." 85 In Seaconsar Far East Ltd. v Bank Markazi Jomhouri Islami Iran[1994] 1 AC 438 , 452, Lord Goff said that if, at the end of the day, there remained a substantial question of fact or law or both, arising on the facts disclosed by the affidavits, which the plaintiff bona fide desired to try, the court should, as a rule, allow the service of the writ. The standard of proof in respect of the cause of action could broadly be stated to be whether, on the affidavit evidence before the court, there was a serious question to be tried. 86 There is no reason why the same principle should not apply to the question whether, in a service out of the jurisdiction case …, a claim is "bound to fail" as well as to the question whether there is a "serious issue to be tried"…”
“4.3(b) … is a cookie sent to a browser by a website other than the website the browser is on. A Third Party Cookie may be sent to a browser via an advertisement appearing on the website. In such cases the Third Party Cookie may be used to enable the Tracking and Collation of browsing activity across all sites or advertisements in the network operating the Third Party Cookie. The purpose of such Tracking and Collation is to gather information about the sites visited by a browser over time in order to target advertising to the apparent interests demonstrated by a user’s browsing history.”
“5.1 Safari is the internet browser installed by Apple on all its products designed to have internet access, namely iMac, Mac, iPad, iPhone and iPod Touch. 5.2 Unlike many other internet browsers, all versions of Safari made available by Apple since the summer of 2011 were and are set by default to block Third Party Cookies. One of the main reasons why Safari was developed with this default setting was to prevent advertising-related tracking of the sort described at paragraph 4.3(b) above occurring by default, that is, without the knowledge or consent of the user (the “default privacy settings”). 5.3 Since the default privacy settings would prevent the use of certain popular web functions, such as the social ‘like’ buttons used to integrate third-party social features into websites, Apple implemented into the default privacy settings a number of specific exceptions to the default block on Third Party Cookies including as follows: (a) Safari allowed Third Party Cookies to be sent to it if, during the process of exchanging information with a third party domain to load third party content, the browser submitted a form to the third party domain (the “Form Submission Rule”) (b) Safari allowed Third Party Cookies to be sent to it if one cookie from that domain was already present on the browser (the “One In, All In Rule”)” (a) Safari allowed Third Party Cookies to be sent to it if, during the process of exchanging information with a third party domain to load third party content, the browser submitted a form to the third party domain (the “Form Submission Rule”) (b) Safari allowed Third Party Cookies to be sent to it if one cookie from that domain was already present on the browser (the “One In, All In Rule”)”
“6.2 … the Defendant’s DoubleClick service provides subscribing advertisers with a service called AdSense. For the purpose of this service, subscribing advertisers provide Adsense with browsing information received as a result of the use of the DoubleClick ID Cookie in relation to the individual browsers visiting their websites, as to which see further paragraph 7 below…7.2 … The cookie value of the Defendant’s DoubleClick ID Cookie is unique to the browser to which it is sent. 7.2 Where an individual browser’s design and settings allow it to accept Third Party Cookies, the DoubleClick ID Cookie is sent to that browser during the normal exchange of information that accompanies the display of a Google advertisement, namely, during the submission of Browser-Generated Information. 7.3 Once the DoubleClick ID Cookie has been sent to an individual browser, the DoubleClick ID Cookie allows the Defendant to recognise when that browser visits a website displaying an advertisement from the Defendant’s vast advertising network and to correlate the Browser-Generated Information for individual browsers, thereby obtaining the following information: (a) The website visited.(b) The date on which the website was visited; (c) The time at which the website was visited; (d) The duration of the visit to the website; (e) The pages of the website visited; (f) The time spent visiting each page of the website; (g) The advertisement(s) viewed; (h) Information as to where the advertisement(s) was/were placed on the website visited; (i) The IP Address of the browser, as a result of which it is often possible to determine approximate geographical location (to the nearest town or city). 7.4 Since the information set out above would be obtained by the Defendant on each occasion that the browser visited any website displaying an advertisement from the Defendant’s advertising network, over time the Defendant thereby obtained not only the information set out at paragraph 7.3 above in relation to each such website but also information as to: (a) the order in which websites were visited; and (b) the frequency with which websites were visited. 7.5 As a result of the placing of a DoubleClick ID Cookie on to a user’s browser, the Defendant was thereby able to and did obtain and collate private and/or personal information relating to users, including information relating to: (a)internet surfing habits as set out at paragraphs 7.3 and 7.4 above;(b) interests, hobbies and pastimes;(c) news reading habits;(d) shopping habits;(e) social class;(f) racial or ethnic origin; (g) political affiliation or opinion;(h) religious beliefs or beliefs of a similar nature; (i) trade union membership; (j) physical health; (k) mental health;(l) sexuality;(m) sexual interests; (n) age; (o) gender;(p) financial situation;(q) geographical location. 7.6 The Defendant then aggregated browsers displaying sufficiently similar patterns, including those of the Claimants, into groups with labels such as “football lovers’, “current affairs enthusiasts,” which group labels its DoubleClick service then offered to advertisers subscribing to Adsense to choose from when selecting the type of people that they wanted to direct their advertisements to.”
“12.1 During the Claimants’ Safari and Google usage as set out at paragraphs 11.1 to 11.3 above the Intermediary Cookie and then the DoubleClick ID Cookie were sent to the Claimants’ browsers which affected the Safari Workaround in the circumstances described at paragraphs 10 above. 12.2 As a result of the operation of the Safari Workaround, the Defendant obtained and recorded personal and/or private information relating to the Claimants and each of them falling within one or more of the categories set out at paragraph 7.5 above (the “Private Information”). Details as to which categories of information were obtained in relation to each Claimant are set out in the Confidential Schedule to the Claimant Specific Particulars of Claim….”
“13.1 Each Claimant’s Private Information was information in relation to which that Claimant had a reasonable expectation of privacy….13.3 None of the Claimants had knowledge at any material time of the existence or effect of the Safari Workaround.14.1 The acts set out at paragraphs 9, 10 and 12 above were wrongful and constituted an unjustified infringement of each Claimant’s right to privacy and a misuse of each Claimant’s private information by the Defendant…”
“15(b) In the circumstances the Defendant was well aware, or alternatively ought to have known, that the Private Information was confidential information owned by each Claimant and that any access to or use of it or any part of it by the Defendant save for the purposes identified at paragraph 3.2 above was unauthorised. 15(c) As a result, the Defendant was during the Relevant Period under a duty of confidence towards the Claimants and each of them in relation to the Private Information and each part thereof and was not and is not entitled to access, obtain, record, or otherwise use or disclose it or Track and Collate it without either the prior consent of the Claimant concerned or alternatively adequate prior notice to him or her. 15(d) In breach of confidence and without the consent of the Claimants the Defendant unlawfully Tracked and Collated the Private Information or parts thereof in carrying out the activities set out at sub-paragraphs 12.2 and 12.3 above.”
“By reason of the Defendant’s misuse of the Claimants’ Private Information and/or breach of confidence as set out above, the Claimants and each of them have suffered damage to personal dignity, autonomy, and integrity, and have been caused anxiety and distress. Further or alternatively the Claimants were caused damage and distress, in respect of which each claims compensation pursuant to section 13 of the DPA. Particulars of the matters relied on in support of each Claimant’s claim for damages and/or compensation pursuant to section 13 of the DPA are set out in the Claimant Specific Particulars of Claim.”
“In our judgment, it is clear beyond argument that a claim which is founded on any of the three categories of constructive trust which we have mentioned cannot be said to be “founded on a tort” within the meaning of R.S.C., Ord. 11, r. 1(1)(f). The law of tort has nothing whatever to do with any such claim. In all such cases the wrongful conduct of the defendant occurs against the background of a pre-existing trust and the claim is founded on that trust. As is stated in Salmond & Heuston on Torts, 19th ed., p. 14, under the heading “Tort and Equity:” “No civil injury is to be classed as a tort if it is only a breach of trust or some other merely equitable obligation. The reason for this exclusion is historical only. The law of torts is in its origin a part of the common law, as distinguished from equity, and it was unknown to the Court of Chancery.”” “No civil injury is to be classed as a tort if it is only a breach of trust or some other merely equitable obligation. The reason for this exclusion is historical only. The law of torts is in its origin a part of the common law, as distinguished from equity, and it was unknown to the Court of Chancery.””
“… the doctrine of joint tortfeasorship is normally applied to common law or statutory torts. Strictly speaking, breach of confidence is not a tort: see Kitetechnology BV v Unicor GmbH Plastmaschinen[1995] FSR 765 at 777-778. (Misuse of private personal information may stand in a different position: see Campbell v MGN Ltd[2004] UKHL 22 ,[2004] 2 AC 457 at [14] per Lord Nicholls of Birkenhead.) On the other hand, breach of confidence has been treated as being analogous to a tort in cases such as Seager v Copydex Ltd (No 2)[1969] 1 WLR 809 and Dowson & Mason Ltd v Potter[1986] 1 WLR 1419 , and it is sufficiently akin to a tort to be dealt with in textbooks on tort such as Clerk & Lindsell. At the risk of being accused of muddling equity and the common law, I believe that it is consistent with equitable principle to hold that a person who participates in a common design with a second person to act in breach of the second person's equitable obligation of confidence is jointly liable with the second person.”
“11 In this country, unlike the United States of America, there is no over-arching, all-embracing cause of action for 'invasion of privacy': see Wainwright v Home Officehttp://www.bailii.org/uk/cases/UKHL/2003/53.html[2003] 3 WLR 1137 . But protection of various aspects of privacy is a fast developing area of the law, … 13 The common law or, more precisely, courts of equity have long afforded protection to the wrongful use of private information by means of the cause of action which became known as breach of confidence. A breach of confidence was restrained as a form of unconscionable conduct, akin to a breach of trust. Today this nomenclature is misleading. The breach of confidence label harks back to the time when the cause of action was based on improper use of information disclosed by one person to another in confidence. To attract protection the information had to be of a confidential nature. But the gist of the cause of action was that information of this character had been disclosed by one person to another in circumstances 'importing an obligation of confidence' even though no contract of non-disclosure existed: see the classic exposition by Megarry J in Coco v A N Clark (Engineers) Ltd[1969] RPC 41 , 47-48. The confidence referred to in the phrase 'breach of confidence' was the confidence arising out of a confidential relationship. 14 This cause of action has now firmly shaken off the limiting constraint of the need for an initial confidential relationship. In doing so it has changed its nature. In this country this development was recognised clearly in the judgment of Lord Goff of Chieveley in Attorney-General v Guardian Newspapers Ltd (No 2)[1990] 1 AC 109 , 281. Now the law imposes a 'duty of confidence' whenever a person receives information he knows or ought to know is fairly and reasonably to be regarded as confidential. Even this formulation is awkward. The continuing use of the phrase 'duty of confidence' and the description of the information as 'confidential' is not altogether comfortable. Information about an individual's private life would not, in ordinary usage, be called 'confidential'. The more natural description today is that such information is private. The essence of the tort is better encapsulated now as misuse of private information.”
“96 It was not suggested thatsection 9(1) of the Private International Law (Miscellaneous Provisions) Act 1995 is applicable to this case, but we have none the less considered that question. That section governs the choice of law for determining issues relating to tort. The Douglases' claim in relation to invasion of their privacy might seem most appropriately to fall within the ambit of the law of delict. We have concluded, however, albeit not without hesitation, that the effect of shoe-horning this type of claim into the cause of action of breach of confidence means that it does not fall to be treated as a tort under English law, see Kitechnology BV v Unicor GmbH [1995] IL Pr 568;[1995] FSR 795 at paragraph 40, and more generally Clerk & Lindsell on Torts, (18th edition, 2000) at footnotes 2 and 3 to paragraph 27-001. Nor has anyone suggested that the facts of this case give rise to a cause of action in tort under the law of New York (see below). Accordingly we have concluded that the parties were correct to have no regard tosection 9(1) of the 1995 Act . 97 Dicey & Morris on The Conflict of Laws (13th edition, 2000) Vol II suggest somewhat tentatively, at paragraph 34-029 and following, that a claim for breach of confidence falls to be categorised as a restitutionary claim for unjust enrichment and that the proper law is the law of the country where the enrichment occurred. While we find this reasoning persuasive, it does not solve the problem on the facts of this case. Even if the Douglases' claim for invasion of their privacy falls to be determined according to principles of English law, these may themselves require consideration of the law of New York. That indeed is the case advanced on behalf of Hello!... 100 We do not consider that the law of New York has any direct application on the facts of this case. The cause of action is based on the publication in this jurisdiction and the complaint is that private information was conveyed to readers in this jurisdiction. The test of whether the information was private so as to attract the protection of English law must be governed by English law. That test, as established by Campbell v MGN, is whether Hello! knew or ought to have known that the Douglases had a reasonable expectation that the information would remain private. Where the events to which the information relates take place outside England – in this instance in New York – the law of the place where they take place may nonetheless be relevant to the question of whether there is a reasonable expectation that the events will remain private. 101 If, in the present case, the law of New York had provided that any member of the public had a right to be present at a wedding taking place in a hotel and to take and publish photographs of that wedding, then photographs of the wedding would be unlikely to have satisfied the test of privacy. That was not the case, however. The law of New York clearly entitled the Douglases to arrange for their wedding to take place in circumstances designed to ensure that events at the wedding remained private, at least so far as photographic detail was concerned. The fact that photographs taken in violation of that privacy might have been published with impunity in New York has no direct bearing on whether the information fell to be treated as private and confidential in England. The question of whether, if unauthorised photographs of the wedding had actually been published in New York, privacy and confidentiality in England would have been destroyed is a different question, and one relevant to the next question that we have to address. 102 To summarise our conclusion at this stage: disregarding the effect of the OK! contract, we are satisfied that the Douglases' claim for invasion of their privacy falls to be determined according to the English law of confidence. That law, as extended to cover private and personal information, protected information about the Douglases' wedding.”
“(1) The rules in this Part apply for choosing the law (in this Part referred to as “the applicable law”) to be used for determining issues relating to tort or (for the purposes of the law of Scotland) delict. (2) The characterisation for the purposes of private international law of issues arising in a claim as issues relating to tort or delict is a matter for the courts of the forum…. (4) The applicable law shall be used for determining the issues arising in a claim, including in particular the question whether an actionable tort or delict has occurred.”
“As the law has developed breach of confidence, or misuse of confidential information, now covers two distinct causes of action, protecting two different interests: privacy, and secret (“confidential”) information. It is important to keep these two distinct. In some instances information may qualify for protection both on grounds of privacy and confidentiality. In other instances information may be in the public domain, and not qualify for protection as confidential, and yet qualify for protection on the grounds of privacy. Privacy can be invaded by further publication of information or photographs already disclosed to the public. Conversely, and obviously, a trade secret may be protected as confidential information even though no question of personal privacy is involved.”
“35 The issue between the parties is therefore one of construction of the rule. I am told there is no English authority which determines the matter but that there are Australian and Canadian cases which support the Claimant's construction. 36 I shall start (and perhaps ought to finish) with the words of the rule themselves. CPR6.20(8)(a) refers to a claim in tort where "damage was sustained within the jurisdiction". There is no reference to the damage which completes the cause of action.The Civil Procedure Act 1997 s.2(7) enjoined the Rules Committee to try "to make rules which are both simple and simply expressed." Having regard to this I do not consider it appropriate to interpret damage in CPR6.20(8)(a) as meaning "the damage which completed the cause of action in tort." It should be given its ordinary and natural meaning, namely, harm which has been sustained by the claimant, whether physical or economic. Further, it is to be observed that CPR6.20(8)(b) refers to a claim in tort where "the damage sustained resulted from an act committed within the jurisdiction." The definite article is used here whereas it is not used in CPR6.20(8)(a). This suggests that it is sufficient for the purposes of sub-paragraph (a) that some damage (not all of the damage) is sustained within the jurisdiction.”
“significant damage occurred in England where the [claimant’s] server was improperly accessed [from Russia] and the confidential and privileged information was viewed and downloaded… I also consider that substantial and efficacious acts occurred in London as well as in Russia. That is where the hacking occurred and where access to the server was achieved”
“74 … Procedural rules should be the servant not the master of the rule of law. Lord Woolf, by his Reports on Access to Justice, brought about a sea change in the attitude of the court to such rules. This included the adoption of the "overriding objective" with which the new CPR begins.CPR 1.1 states that the overriding objective of the Rules is to enable the court to deal with cases justly, and that this involves saving expense and ensuring that cases are dealt with expeditiously. 75 Where an application is made to amend a pleading the normal approach is to grant permission where to do so will cause no prejudice to the other party that cannot be dealt with by an appropriate order for costs. This accords with the overriding objective. Where all that a refusal of permission will achieve is additional cost and delay, the case for permitting the amendment is even stronger. I can see no reason in principle why similar considerations should not apply where an application is made for permission to serve process out of the jurisdiction. It is, of course, highly desirable that care should be taken before serving process on a person who is not within the jurisdiction. But if this is done on a false basis in circumstances where there is a valid basis for subjecting him to the jurisdiction, it is not obvious why it should be mandatory for the claimant to be required to start all over again rather than that the court should have a discretion as to the order that will best serve the overriding objective.”
“(1) An individual who suffers damage by reason of any contravention by a data controller of any of the requirements of this Act is entitled to compensation from the data controller for that damage.
“62 Part of the judge's reasoning which led to his striking out David's claim under the DPA was his conclusion that article 8 was not engaged and that BPL was entitled to publish or procure the publication of the Photograph in the exercise of its right to freedom of expression contained in article 10. If the trial judge were to hold that article 8 is engaged and that the article 8/10 balance should be struck in David's favour, it would follow that BPL's admitted processing of David's personal data was unlawful. The judge expressly recognised the position in [72]. It would also follow that the processing was unfair and that none of the conditions of schedule 2 to the DPA (including the only condition relied upon, namely that in paragraph 6(1)) was met: see [76]. 63 In these circumstances, the issues under the DPA should be revisited by the trial judge in the light of his or her conclusions of fact. Those issues include the other issues considered by Patten J under this head, notably (but not restricted to) those relating to causation and damage. Given that there is now to be a trial, we do not think that the claims under the DPA should be struck out, whatever the conclusions of fact may be. They seem to us to raise a number of issues of some importance, including the meaning of 'damage' in section 13(1) of the DPA. It seems to us to be at least arguable that the judge has construed 'damage' too narrowly, having regard to the fact that the purpose of the Act was to enact the provisions of the relevant Directive. All these issues should be authoritatively determined at a trial.”
“The extensive collection and storage of search histories of individuals in a directly or indirectly identifiable form invokes the protection under Article 8 of the European Charter of Fundamental Rights. An individual's search history contains a footprint of that person's interests, relations, and intentions. These data can be subsequently used both for commercial purposes and as a result of requests and fishing operations and/or data mining by law enforcement authorities or national security services.”
“In its Opinion (WP 136) on the concept of personal data, the Working Party has clarified the definition of personal data. An individual's search history is personal data if the individual to which it relates, is identifiable. Though IP addresses in most cases are not directly identifiable by search engines, identification can be achieved by a third party. Internet access providers hold IP address data. Law enforcement and national security authorities can gain access to these data and in some Member States private parties have gained access also through civil litigation. Thus, in most cases – including cases with dynamic IP address allocation – the necessary data will be available to identify the user(s) of the IP address. The Working Party noted in its WP 136 that ‘… unless the Internet Service Provider is in a position to distinguish with absolute certainty that the data correspond to users that cannot be identified, it will have to treat all IP information as personal data, to be on the safe side’,. These considerations will apply equally to search engine operators.”
“When a cookie contains a unique user ID, this ID is clearly personal data. The use of persistent cookies or similar devices with a unique user ID allows tracking of users of a certain computer even when dynamic IP addresses are used. The behavioural data that is generated through the use of these devices allows focusing even more on the personal characteristics of the individual concerned. This is in line with the fundamental logic of the dominant business model.”
“Article 23 – Liability 1. Member States shall provide that any person who has suffered damage as a result of an unlawful processing operation or of any act incompatible with the national provisions adopted pursuant to this Directive is entitled to receive compensation from the controller for the damage suffered. 2. The controller may be exempted from this liability, in whole or in part, if he provides that he is not responsible for the event giving rise to the damage.”
“the collection and storage of personal information relating to the applicant's telephone, as well as to her e-mail and internet usage, without her knowledge, amounted to an interference with her right to respect for her private life and correspondence within the meaning of Article 8.”
“There have been two recent developments which have rendered the court more ready to entertain a submission that pursuit of a libel action is an abuse of process. The first is the introduction of the new Civil Procedure Rules. Pursuit of the overriding objective requires an approach by the court to litigation that is both more flexible and more pro-active. The second is the coming into effect of the Human Rights Act. Section 6 requires the court, as a public authority, to administer the law in a manner which is compatible with Convention rights, insofar as it is possible to do so. Keeping a proper balance between the Article 10 right of freedom of expression and the protection of individual reputation must, so it seems to us, require the court to bring to a stop as an abuse of process defamation proceedings that are not serving the legitimate purpose of protecting the claimant's reputation, which includes compensating the claimant only if that reputation has been unlawfully damaged.”
“Claims for misuse of private information/breach of confidence raise precisely the same Article 8/Article 10 issues as libel claims”