"The email in question attached a letter on behalf of my firm's client Moon Hall Schools Educational Trust. That letter is attached at pages 1-28 of BJH1 (pages 2, 24 and 28 are blank as they were when the letter was sent by email). … It contained the Claimants' names, their address, the amount of school fees (together with interest and surcharges) owed by the First and Second Claimants to Moon Hall Schools Educational Trust, a statement of account of school fees for the past five years, and reference to proposed legal action which would be taken if the debt was not paid. It does not contain any of the First or Second Claimant's financial information in terms of bank or card details, income or financial position. Nor does it contain any reference to the Third Claimant's location other than the school she attended and her parents' address, in particular there is no information relating to the locations of school trips or details relating to the school bus. 4. Due to a typographical error made by one of the firm's paralegals it was instead sent to an individual with an email address one character different to the Second Claimant. The error was realised swiftly. On the same day the email was sent, the incorrect recipient notified my firm of the error by replying to the email. My colleague asked the individual to delete the item from both their inbox and deleted items folder. They confirmed this the next day. 5. The email was encrypted as is standard for emails sent via our email systems. My firm's Head of IT reviewed the properties of the sent email and has confirmed to me that it was not sent via basic SMTP, but rather by TLS, confirming that transmission between our email gateway and the Gmail receiving server was encrypted and not in plain text. This means that the only person able to view that email between when it was sent and when it was deleted were those with access to the recipients email account."
"I understood it to be common ground that the threshold of seriousness applied to section 13 as much as to MPI [misuse of private information]. That threshold would undoubtedly exclude, for example, a claim for damages for an accidental one-off data breach that was quickly remedied."
"Not every statement about a person's health will carry the badge of confidentiality or risk doing harm to that person's physical or moral integrity. The privacy interest in the fact that a public figure has a cold or a broken leg is unlikely to be strong enough to justify restricting the press's freedom to report it. What harm could it possibly do?"
"On the facts, the Cs cannot have suffered damage or distress above a de minimis level. The court must look at the reality of the personal information in question and the circumstances in which it was inadvertently sent to one third party: a. The nature of the private information in question: i. This is not a case where intimate information about health or a sexual relationship are in play. Names and home address are given, but no further details of home life, no phone numbers are included. There are no bank details or details of the state of the Cs finances. [1] ii. The only financial details are the invoice for school fees (the level of fees being publicly available on the school's website), and the statement of account of school fees for the past 5 years – i.e. the amounts C1 and C2 had paid for C3's schooling. These are 25 pages into the attachments. There are documents asking for other financial information, but these are blank and contain no personal data. Whilst the letter states that C1 and C2 have not paid one term's bill, it gives no information as to why that it. Is does not say they cannot do so, or anything about their financial position. It states the mere fact of non-payment of this bill, and that if payment is not made, legal action may result. iii. Whilst Cs assert that there is data relating to C3's location and transport, the only reference to transport is a fee for it– not giving any details of what this transport is or where this transport takes place, contrary to the assertion at para. 9c POC. Therefore the only location data is the school and the Cs' home address. b. The circumstances of disclosure: i. The information was disclosed to one individual only, accidentally as a result of a typographical error; ii. The individual notified D of the error the same day. The next day, when asked to delete the email and confirm that had been done, the individual did so did so 2½ hours later. There is no reason to think that they did not act in good faith, or even that they read all of the documents in any detail. iii. The email was encrypted; iv. That the email went through Gmail servers is irrelevant to the claim, as C1 and C2 have Gmail accounts themselves, and therefore the email, when sent properly, went through this same system. c. No tangible harm or loss is pleaded or plausible: i. The (unpleaded) inference in the witness statement of Mr Bennett that phishing phone messages were targeted at C1 and C2 because of this incident is an inference that cannot be drawn. Neither the Cs' phone numbers nor any information about who they bank with was in the email or attachments and therefore cannot have been exploited. ii. In his witness statement Mr Bennett quotes from correspondence about the number of hours Mr Rolfe spent dealing with the incident. Firstly, there is no claim made for time spent dealing with the incident. Secondly, the number of hours claimed is wholly implausible. When this claim was made in correspondence D queried it (in particular in relation to an email referred to dated11 August 2019 which did not deal with this matter but rather the matter of the unpaid fees asked for the correspondence between Cs and D/Moon Hall School. The specific point about the 11 August email was not responded to (but it is repeated in Mr Bennett's witness statement), but after chasing, D was sent the documents … which consist of email between 19 and31 July 2019 . … these consist of only a small number of short emails. …This amounts to 6 short emails, the longest of which is 10 lines long (including "
"Loss of control" means something more than one third party briefly having access to this relatively low-level personal information and then confirming they deleted it. In Lloyd it was commercial exploitation of that information on a large scale. There the Court of Appeal found that individuals' "browser generated information" had a value and was of commercial value to Google [at 46,47]. In Gulati v MGN Ltd[2017] QB 149 it was disclosure to journalists who used the personal information as they saw fit, in particular by publishing in a national newspaper. This is very different. On the facts of this case, it is simply not plausible that Cs have suffered distress above a de minimis threshold in relation to the accidental sending of this email to one recipient who quickly deleted it. Whilst unfortunate, the incident is simply not of a sufficiently serious nature to have caused damage over the threshold."