“MPI also imposes an obligation not to misuse private information. I accept that a “misuse” may include unintentional use, but it still requires a “use”: that is, a positive action”
“[a]ppropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data”
“In my judgment, the wrong is thus said to have been a “failure” which allowed the Attacker to access the personal data. Despite the way in which Counsel for the Claimant has attractively sought to recharacterise her client’s case, it is clear that the Claimant does not allege any positive conduct by DSG said to comprise a breach or a misuse for the purposes of either BoC or MPI. That is unsurprising, given that DSG was the victim of the cyber-attack. There can be no suggestion that DSG purposefully facilitated the Attack, and that is not pleaded in the claim. In any event, there is no evidence to that effect, and it is contrary to common sense. Rather, the Claimant’s claim is that the DSG failed in alleged duties to provide sufficient security for the Claimant’s data. That is in essence the articulation of some form of data security duty. In my judgment, neither BoC nor MPI impose a data security duty on the holders of information (even if private or confidential). Both are concerned with prohibiting actions by the holder of information which are inconsistent with the obligation of confidence/privacy. Counsel for the Claimant submitted that applying the wrong of MPI on the present facts would be a “development of the law”
“I accept that a “misuse” may include unintentional use, but it still requires a “use”: that is, a positive action. In the language ofart.8 ECHR (the basis for the MPI tort), there must be an “interference” by the defendant, which falls to be justified. I have not overlooked the Claimant’s argument that the conduct of DSG was “tantamount to publication”
“Similarly, the assertion that there is direct liability in respect of breach of confidence or misuse of private information also fails: it was not Morrisons that disclosed the information or misused it: it was Skelton, acting without authority and criminally.”
“9. In any claim for breach of any data protection legislation the claimant must specify in the particulars of claim— (1) the legislation and the provision that the claimant alleges the defendant has breached; (2) any specific data or acts of processing to which the claim relates; (3) the specific acts or omissions said to amount to such a breach, and the claimant’s grounds for that allegation; and (4) the remedies which the claimant seeks.”
“breaches of the Defendant’s IT estate, affecting any of the Claimants, which have yet to be confirmed”