“[the white powder incident]… was concluded against you, not that in fact there was anything particular that happened by way of discipline of you. One would think that any sensible, reasonable person would have just put that behind them and got on with life and got on with their job. That was not your reaction. Your reaction was to harbour a very considerable grudge and harbour very considerable bad feelings towards Morrisons. That much is evident if nothing else, from the resignation letter that you drafted in November of that year, a few months after the incident and disciplinary proceedings had been concluded. It was rankling very deeply and nastily with you. Your reaction was to set about, in October or November, doing Morrisons some real damage, and you achieved that of course. Over a period of months at the end of the year you set about getting sensitive information from Morrisons – it came legitimately into your hands, trusted as you were in that IT department – the pay roll details and personal details of all the employees at Morrisons, who of course number over 100,000. Having got hold of that material legitimately at work you took it away from work electronically and you, in November and December – so over a period of weeks, not just on the spur of the moment – started to set up what you put into effect in 2014. You created a false email account, you got a pay as you go mobile telephone that could not [be] traced back to you, you started to use the TOR system which we heard about which is a way of seeking and achieving anonymity in terms of what you were to do on the internet. …it was cold and calculating and designed, no doubt, to do as much damage to Morrisons as could be achieved.”
“(1) In this Act, unless the context otherwise requires— “data” means information which— (a) is being processed by means of equipment operating automatically in response to instructions given for that purpose, (b) is recorded with the intention that it should be processed by means of such equipment, (c) is recorded as part of a relevant filing system or with the intention that it should form part of a relevant filing system, (d) does not fall within paragraph (a), (b) or (c) but forms part of an accessible record as defined by section 68; …. “data controller” means, subject to subsection (4), a person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any personal data are, or are to be, processed; “data processor”, in relation to personal data, means any person (other than an employee of the data controller) who processes the data on behalf of the data controller; “data subject” means an individual who is the subject of personal data “personal data” means data which relate to a living individual who can be identified— (a) from those data, or (b) from those data and other information which is in the possession of, or is likely to come into the possession of, the data controller, and includes any expression of opinion about the individual and any indication of the intentions of the data controller or any other person in respect of the individual; “processing”, in relation to information or data, means obtaining, recording or holding the information or data or carrying out any operation or set of operations on the information or data, including— (a) organisation, adaptation or alteration of the information or data, (b) retrieval, consultation or use of the information or data, (c) disclosure of the information or data by transmission, dissemination or otherwise making available, or (d) alignment, combination, blocking, erasure or destruction of the information or data; (2) In this Act, unless the context otherwise requires— (a) “obtaining” or “recording”, in relation to personal data, includes obtaining or recording the information to be contained in the data, and (b) “using” or “disclosing”, in relation to personal data, includes using or disclosing the information contained in the data. (3) In determining for the purposes of this Act whether any information is recorded with the intention— (a) that it should be processed by means of equipment operating automatically in response to instructions given for that purpose, or (b) that it should form part of a relevant filing system, it is immaterial that it is intended to be so processed or to form part of such a system only after being transferred to a country or territory outside the European Economic Area. ……………………” “data” means information which— (a) is being processed by means of equipment operating automatically in response to instructions given for that purpose, (b) is recorded with the intention that it should be processed by means of such equipment, (c) is recorded as part of a relevant filing system or with the intention that it should form part of a relevant filing system, (d) does not fall within paragraph (a), (b) or (c) but forms part of an accessible record as defined by section 68; …. “data controller” means, subject to subsection (4), a person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any personal data are, or are to be, processed; “data processor”, in relation to personal data, means any person (other than an employee of the data controller) who processes the data on behalf of the data controller; “data subject” means an individual who is the subject of personal data “personal data” means data which relate to a living individual who can be identified— (a) from those data, or (b) from those data and other information which is in the possession of, or is likely to come into the possession of, the data controller, and includes any expression of opinion about the individual and any indication of the intentions of the data controller or any other person in respect of the individual; “processing”, in relation to information or data, means obtaining, recording or holding the information or data or carrying out any operation or set of operations on the information or data, including— (a) organisation, adaptation or alteration of the information or data, (b) retrieval, consultation or use of the information or data, (c) disclosure of the information or data by transmission, dissemination or otherwise making available, or (d) alignment, combination, blocking, erasure or destruction of the information or data; (b) “using” or “disclosing”, in relation to personal data, includes using or disclosing the information contained in the data. (a) that it should be processed by means of equipment operating automatically in response to instructions given for that purpose, or (b) that it should form part of a relevant filing system, it is immaterial that it is intended to be so processed or to form part of such a system only after being transferred to a country or territory outside the European Economic Area. ……………………”
“The data protection principles” “4.—. (1) References in this Act to the data protection principles are to the principles set out in Part I of Schedule 1. (2) Those principles are to be interpreted in accordance with Part II of Schedule 1. (3) ……….. (4) Subject to section 27(1), it shall be the duty of a data controller to comply with the data protection principles in relation to all personal data with respect to which he is the data controller.”
“SCHEDULE 1 The data protection principles PART I The data protection principles The principles (1) Personal data shall be processed fairly and lawfully and, in particular, shall not be processed unless— (a) at least one of the conditions in Schedule 2 is met, and (b) in the case of sensitive personal data, at least one of the conditions in Schedule 3 is also met. (2) Personal data shall be obtained only for one or more specified and lawful purposes, and shall not be further processed in any manner incompatible with that purpose or those purposes. (3) Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed. (4) Personal data shall be accurate and, where necessary, kept up to date. (5) Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes. (6) Personal data shall be processed in accordance with the rights of data subjects under this Act. (7) Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.”
“The first principle 1.— (1) In determining for the purposes of the first principle whether personal data are processed fairly, regard is to be had to the method by which they are obtained, including in particular whether any person from whom they are obtained is deceived or misled as to the purpose or purposes for which they are to be processed. ……… 2.— (1) Subject to paragraph 3, for the purposes of the first principle personal data are not to be treated as processed fairly unless— (a) in the case of data obtained from the data subject, the data controller ensures so far as practicable that the data subject has, is provided with, or has made readily available to him, the information specified in sub-paragraph (3), and (b) in any other case, the data controller ensures so far as practicable that, before the relevant time or as soon as practicable after that time, the data subject has, is provided with, or has made readily available to him, the information specified in sub-paragraph (3). …………… (3) The information referred to in sub-paragraph (1) is as follows, namely— (a) the identity of the data controller, (b) if he has nominated a representative for the purposes of this ……… (a) in the case of data obtained from the data subject, the data controller ensures so far as practicable that the data subject has, is provided with, or has made readily available to him, the information specified in sub-paragraph (3), and (b) in any other case, the data controller ensures so far as practicable that, before the relevant time or as soon as practicable after that time, the data subject has, is provided with, or has made readily available to him, the information specified in sub-paragraph (3). …………… (b) if he has nominated a representative for the purposes of this (c). the purpose or purposes for which the data are intended to be processed, and (d). any further information which is necessary, having regard to the specific circumstances in which the data are or are to be processed, to enable processing in respect of the data subject to be fair. 39. …………. 40. The second principle 5. 41. The purpose or purposes for which personal data are obtained may in particular be specified— (a) in a notice given for the purposes of paragraph 2 by the data controller to the data subject, or (b) in a notification given to the Commissioner under Part III of this Act. 42. ………… The seventh principle 9. Having regard to the state of technological development and the cost of implementing any measures, the measures must ensure a level of security appropriate to— (a). the harm that might result from such unauthorised or unlawful processing or accidental loss, destruction or damage as are mentioned in the seventh principle, and (b). the nature of the data to be protected.”
“13.— Compensation for failure to comply with certain requirements. (1) An individual who suffers damage by reason of any contravention by a data controller of any of the requirements of this Act is entitled to compensation from the data controller for that damage. ………….. (3) In proceedings brought against a person by virtue of this section it is a defence to prove that he had taken such care, as in all the circumstances, was reasonably required to comply with the requirement concerned.”
“70. A data controller is a person who makes decisions about how and why personal data are processed. It is clear from the terms of section 7(1)(a) that the data controller is responsible for persons who process data on his behalf. Thus it follows that a person who processes data as agent for a data controller is not himself a data controller in respect of those data. Even where decisions about data are taken by natural persons, they will not themselves be data controllers if those decisions are made as agents of a company of which they are directors: Re Southern Pacific Personal Loans Ltd[2013] EWHC 2485 (Ch) ; 71. On the other hand, if they are processing personal data on their own behalves they will be data controllers as regards that processing and those data. The question may then arise whether they are entitled to one or more exemptions under the DPA.”
“The Directive as a whole is aimed at safe-guarding privacy rights in the context of data management. This is repeatedly emphasised in the recitals: “(2) Whereas data-processing systems are designed to serve man; whereas they must, whatever the nationality or residence of natural persons, respect their fundamental rights and freedoms, notably the right to privacy, and contribute to economic and social progress, trade expansion and the well-being of individuals;…” …(7) Whereas the difference in levels of protection of the rights and freedoms of individuals, notably the right to privacy, with regard to the processing of personal data afforded in the Member States may prevent the transmission of such data from the territory of one Member State to that of another Member State; whereas this difference may therefore constitute on obstacle to the pursuit to a number of economic activities at Community level, distort competition and impede authorities in discharge of their responsibilities under Community law; whether this difference in levels of protection is due to the existence of a wide variety of national laws, regulations and administrative provisions… …(10) Whereas the object of the national laws on the processing of personal data is to protect fundamental rights and freedoms, notably the right to privacy, which is recognised both inArticle 8 of the European Convention for the Protection of Human Rights and Fundamental Freedoms o mom the general principles of Community law; whereas, for that reason, the approximation of those laws must not result in any lessening of the protection they afford but must, on the contrary, seek to ensure a high level of protection in the Community;.. …(11) Whereas the principles of the protection of the rights and freedoms of individuals, notably the right to privacy, which are contained within this Directive, give substance to and amplify those contained in the Council of Europe Convention of28 January 1981 for the Protection of Individuals with regard to Automatic Processing of Personal Data… Article 1 provides for the object of the Directive “1. In accordance with this Directive Member States shall protect the fundamental rights and freedoms of natural persons and in particular their right to privacy with respect to the processing of personal data.” ” “(2) Whereas data-processing systems are designed to serve man; whereas they must, whatever the nationality or residence of natural persons, respect their fundamental rights and freedoms, notably the right to privacy, and contribute to economic and social progress, trade expansion and the well-being of individuals;…” …(7) Whereas the difference in levels of protection of the rights and freedoms of individuals, notably the right to privacy, with regard to the processing of personal data afforded in the Member States may prevent the transmission of such data from the territory of one Member State to that of another Member State; whereas this difference may therefore constitute on obstacle to the pursuit to a number of economic activities at Community level, distort competition and impede authorities in discharge of their responsibilities under Community law; whether this difference in levels of protection is due to the existence of a wide variety of national laws, regulations and administrative provisions… …(10) Whereas the object of the national laws on the processing of personal data is to protect fundamental rights and freedoms, notably the right to privacy, which is recognised both inArticle 8 of the European Convention for the Protection of Human Rights and Fundamental Freedoms o mom the general principles of Community law; whereas, for that reason, the approximation of those laws must not result in any lessening of the protection they afford but must, on the contrary, seek to ensure a high level of protection in the Community;.. …(11) Whereas the principles of the protection of the rights and freedoms of individuals, notably the right to privacy, which are contained within this Directive, give substance to and amplify those contained in the Council of Europe Convention of28 January 1981 for the Protection of Individuals with regard to Automatic Processing of Personal Data… Article 1 provides for the object of the Directive “1. In accordance with this Directive Member States shall protect the fundamental rights and freedoms of natural persons and in particular their right to privacy with respect to the processing of personal data.” ”
“Whereas the principles of protection must be reflected, on the one hand, in the obligations imposed on persons, public authorities, enterprises, agencies or other bodies responsible for processing, in particular regarding data quality, technical security, notification to the supervisory authority, and the circumstances under which processing can be carried out, and, on the other hand, in the right conferred on individuals, the data on whom are the subject of processing to be informed that processing is taking place, to consult the data, to request corrections and even to object to processing in certain circumstances…”
“Whereas the protection of rights and freedoms of data subjects with regard to the processing of personal data requires that appropriate technical and organisational measures are taken, both at the time of the design of the processing system and at the time of the processing itself, particularly in order to maintain security and thereby prevent any unauthorised processing; whereas it is incumbent on the Member States to ensure that controllers comply with these measures; whereas these measures must ensure an appropriate level of security, taking into account the state of the art and the costs of their implementation in relation to the risks inherent in the processing and the nature of the data to be protected”; And Recital 55 says: “Whereas, if the controller fails to protect the rights of data subjects, national legislation must provide for a judicial remedy; whereas any damage that a person may suffer as a result of unlawful processing must be compensated for by the controller, who may be exempted from liability if he proves that he is not responsible for the damage, in particular in cases where he establishes fault on the part of the data subject or in case of force majeure; whereas sanctions must be imposed on any person, whether governed by private or public law, who fails to comply with the national measures taken under this Directive…”
“Member States shall provide that the controller must implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction or against accidental loss or alteration unauthorised disclosure or access, in particular where the processing involves the transmission of data over a network, and against all other unlawful forms of processing. Having regard to the state of the art and the cost of their implementation, such measures shall ensure a level of security appropriate to the risks represented by the processing and the nature of the data to be protected.”
“to ensure our business is conducted appropriately, including:- • to establish facts where the content of the communication is disputed • to investigate and detect usage in breach of our policies • for training purposes • for preventing and detecting crime • to ensure the effective operation of our systems • we will not read all your correspondence, however if an anomaly of concern is found we will investigate this thoroughly.”
“60. It would not have been necessary for Mr Skelton to retain the payroll data for long after it had been passed to KPMG. He might retain it for a relatively short while in case any queries arose, for example, completeness of the data. After that, I would have expected him to delete it, and in his capacity as an IT internal auditor, he would know professionally that it should be deleted. Senior auditors are expected to manage data responsibly. 61. In fact, I recall discussing with Mr Skelton the retention of the file structure and headings and the deletion of the contents and, later on, asked if he had deleted it and he confirmed to me that he had. My best recollection is that I asked Mr Skelton if the data had been deleted relatively shortly after it had been provided to KPMG because in the normal course and working closely with Mr Skelton that is a conversation he and I would naturally have. I would normally ask this where any sensitive data has been provided to my team and not merely payroll data. I would not have asked to see Mr Skelton’s computer to verify this fact, although later on (I do not recall when) I did see the headings that had been left after the data had been deleted from the spreadsheet. I would not, though, usually ask whether a member of my team had deleted data because I would trust them to do it.”
“…vicarious liability is legal responsibility imposed on an employer, although he is himself free from blame for a tort committed by his employee in the course of his employment. Fleming, in The Law of Torts 9th ed. (1998), pp 409-410, observed that this formula represents: “A compromise between two conflicting policies: on one hand, the social interest in furnishing an innocent tort victim with recourse against a financially responsible defendant; on the other, a hesitation to foist any undue burden on a business enterprise”
“…the court is not required in each case to conduct a retrospective assessment of the degree to which the employee would have been considered to present a risk. As Immanuel Kant wrote: “out of the crooked timber of humanity, no straight thing was ever made.”
“it looks obvious that he was motivated by personal racism rather than a desire to benefit his employer’s business, but that is neither here nor there.”
“46. The alleged sexual assault occurred during the course of a medical examination which the defendant required the claimants to undergo in respect of present and future employment. The task of carrying out the medical examination was entrusted to Dr. Bates by the defendant. The task assigned to Dr. Bates put him in a position to deal with the claimants. On the alleged facts he abused that position. It is difficult to see how it can sensibly be argued that his acts did not fall within the activity tasked to him… on the facts I find that alleged sexual abuse was inextricably interwoven with the carrying out by the doctor of his duties pursuant to his engagement by the bank. In the circumstances I find the tort is so closely connected with that employment or engagement to satisfy the second stage. ”
“unless the Statute expressly or impliedly indicates otherwise, the principle of vicarious liability is applicable where an employee commits a breach of his statutory obligations sounding in damages while acting in the course of his employment.”
“Since Section 17(5) occurs within this very particular context, it is plain that it was intended to abolish only the common law powers relating to entry for the purpose of arrest. The subsection was not intended to affect the common law relating to searches for evidence carried out when someone has been arrested.”
“33. If the two remedies cover the precisely the same ground and are inconsistent with each other, then the common law remedy will almost certainly have been excluded by necessary implication. To do otherwise would circumvent the intention of Parliament. A good example of this is Marcic, where a sewerage undertaker was subject to an elaborate scheme of statutory regulation which included an independent regulator with powers of enforcement whose decisions were subject to judicial review. The statutory scheme provided a procedure for making complaints to the regulator. The House of Lords held that a cause of action in nuisance would be inconsistent with the statutory scheme. It would run counter to the intention of Parliament. 34. The question is not whether there are any differences between the common law remedy and the statutory scheme. There may well be differences. The question is whether the differences are so substantial that they demonstrate that Parliament could not have intended the common law remedy to survive the introduction of the statutory scheme. The court should not be too ready to find that a common law remedy has been displaced by a statutory one, not least because it has always been open to Parliament to make the position clear by stating explicitly whether the Statute is intended to be exhaustive. The mere fact that there are some differences between the common law and the statutory positions is unlikely to be sufficient unless they are substantial. The fact that the House of Lords was divided in Total Network SL[2008] AC1174 shows how difficult it may sometimes be to decide on which side of the line a case falls. The question is whether looked at as a whole, a common law remedy would be incompatible with the statutory scheme and therefore could not have been intended to coexist with it.”
"Where A becomes liable to B as a joint tortfeasor with C in the tort of deceit practised by C on B on the basis that A and C have a common design to defraud B and A renders assistance to C pursuant to and in furtherance of the common design, does D, A's employer, become vicariously liable to B, simply because the act of assistance, which is not itself the deceit, is in the course of A's employment with D?"
“The conduct for which the servant is responsible must constitute an actionable tort and to make the employer responsible for that tort the conduct necessary to establish the employee's liability must have occurred within the course of the employment. If the tort is committed jointly, then it is conduct which is within the course of the employment sufficient to constitute the tort, irrespective of which tortfeasor performed the acts, which is necessary. As both tortfeasors are responsible for the tortious conduct as a whole in the case of joint torts it is not necessary to distinguish between the actions of the different tortfeasors. For vicarious liability what is critical, as long as one of the joint tortfeasors is an employee, is that the combined conduct of both tortfeasors is sufficient to constitute a tort in the course of the employee's employment. Were the position otherwise, you could have the extraordinary result that if an employee carried out all the acts complained of there would be no liability on the employer, but if the acts were carried out partly by the employee and partly by a non-employee, the employer would be liable. The obverse situation is the same. If an employer would be liable if the employee personally took the action complained of the situation is no different because some of the acts were done by some one who was not an employee as part of a joint enterprise with the employee.”
“The truth is that it was an act of passion and resentment done neither in furtherance of the master’s interests nor under his express and implied authority nor as an incident to or in consequence of anything the barmaid was employed to do. It was a spontaneous act of retributive justice. The occasion for administering it and the form it took may have arisen from the fact that she was a barmaid, but retribution was not within the scope of her employment as a barmaid.”
“..had signed documentation which reminded her of her obligation to maintain confidentiality in information whose disclosure had not been authorised. For someone who occupied such a sensitive position it is in my judgment appropriate to view her job as including the task to preserve that confidentiality. ……. she must have learned of that information in the course of her work. I can see no other way that it could have reached her….Of course, for the purpose of examining this issue, I must assume (contrary to my earlier finding) that Ms Jordan-Barber's disclosure to Mr Kay was actionable at the suit of the Claimant. It is only if she committed a tort against him that any issue of vicarious liability could arise. But if that was the case, there is a clear and obvious connection between that wrong and that part of her job which required her to keep such information confidential. If this was the case, then it would seem to me to be just to require the MOD to assume vicarious responsibility. This is not simply an example of the employment being the opportunity for the wrong to be committed. As part of her work, she needed to have access to security sensitive and confidential information. As part of her work she shared office space with the J9 Pol/Ops PJOBS team and was likely to learn other information in consequence. There is always an inherent risk that those entrusted with such information will abuse the trust reposed in them, but rather than this being a reason why vicarious liability should not be imposed, I think, on the contrary, it is a reason in its favour. True it is that Ms Jordan-Barber's activity did nothing to further the MOD's aims, it was carried on without their knowledge, and it received no encouragement from the MOD. What she did was prohibited. However, those features do not preclude vicarious liability (and [counsel for the Ministry] did not suggest they did). Notwithstanding them, if I had held that [the source] had committed a tort (contrary to my findings), I would have concluded that that hypothetical tort would have been sufficiently closely connected with her job for it to be just for the MOD to be vicariouslyliable.”
“The relationship that gives rise to vicarious liability is in the vast majority of cases that of employer and employee under a contract of employment. The employer will be vicariously liable when the employee commits a tort in the course of his employment. There is no difficulty in identifying a number of policy reasons that usually make it fair, just and reasonable to impose vicarious liability on the employer when these criteria are satisfied: i) The employer is more likely to have the means to compensate the victim than the employee and can be expected to have insured against that liability; ii) The tort will have been committed as a result of activity being taken by the employee on behalf of the employer; iii) The employee's activity is likely to be part of the business activity of the employer; iv) The employer, by employing the employee to carry on the activity will have created the risk of the tort committed by the employee; v) The employee will, to a greater or lesser degree, have been under the control of the employer.”