“54. Having considered the submissions of both Parties, I am not persuaded that consideration of the law of agency assists with the determination of the central issue in this appeal, which is the extent to which [the Appellant] was controller of the data recovered and whether it bears responsibility for any data protection breaches arising from JPL’s processing activities.”
“(13) In order to ensure a consistent level of protection for natural persons throughout the Union and to prevent divergences hampering the free movement of personal data within the internal market, a Regulation is necessary to provide legal certainty and transparency for economic operators…and to provide natural persons in all Member States with the same level of legally enforceable rights and obligations and responsibilities for controllers and processors. …(82) In order to demonstrate compliance with this Regulation, the controller or processor should maintain records of processing activities under its responsibility… (148) In order to strengthen the enforcement of the rules of this Regulation, penalties including administrative fines should be imposed for any infringement of this Regulation, in addition to, or instead of appropriate measures imposed by the supervisory authority pursuant to this Regulation…The imposition of penalties including administrative fines should be subject to appropriate procedural safeguards in accordance with the general principles of Union law and the Charter, including effective judicial protection and due process… (150)…Imposing an administrative fine…does not affect the application of other powers of the supervisory authorities or of other penalties under this Regulation. …(152) Where this Regulation does not harmonise administrative penalties or where necessary in other cases, for example in cases of serious infringements of this Regulation, Member States should implement a system which provides for effective, proportionate and dissuasive penalties. The nature of such penalties, criminal or administrative, should be determined by Member State law.”
“…(e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed…(‘storage limitation’); and (f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).”
“1. Taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation. Those measures shall be reviewed and updated where necessary. 2. Where proportionate in relation to processing activities, the measures referred to in paragraph 1 shall include the implementation of appropriate data protection policies by the controller.”
“(1) Taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for rights and freedoms of natural persons posed by the processing, the controller shall, both at the time of the determination of the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures…which are designed to implement data-protection principles…in an effective manner and to integrate the necessary safeguards into the processing in order to meet the requirements of this Regulation and protect the rights of data subjects. (2) The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures shall ensure that by default personal data are not made accessible without the individual’s intervention to an indefinite number of natural persons.”
“(1) Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject. …(3)Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller. That contract or other legal act shall stipulate, in particular, that the processor: (a) processes the personal data only on documented instructions from the controller…; (c) takes all measures required pursuant to Article 32; …(f) assists the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 taking into account the nature of processing and the information available to the processor; (g) at the choice of the controller, deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage of the personal data; (h) makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller… …(9) The contract or the other legal act referred to in paragraphs 3 and 4 shall be in writing, including in electronic form. (10) Without prejudice to Articles 82, 83 and 84, if a processor infringes this Regulation by determining the purposes and means of processing, the processor shall be considered to be a controller in respect of that processing.”
“The processor and any person acting under the authority of the controller or of the processor, who has access to personal data, shall not process those data except on instructions from the controller, unless required to do so by Union or Member State law.”
“1. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate: …(b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; (c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; (d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing. (2) In assessing the appropriate level of security account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored of otherwise processed.”
“(1) Each supervisory authority shall ensure that the imposition of fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive. (2) Administrative fines shall, depending on the circumstances of each individual case, be imposed in addition to, or instead of, measures referred to in points (a) to (h) and (j) of Article 58(2). When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to the following: (a) the nature, gravity and duration of the infringement taking into account the nature, scope or purpose of the processing concerned as well as the number of data subjects affected and the level of damage suffered by them; (b) the intentional or negligent character of the infringement; (c) any action taken by the controller or processor to mitigate the damage suffered by data subjects; (d) the degree of responsibility of the controller or processor taking into account technical and organisational measures implemented by them pursuant to Articles 25 and 32; (e) any relevant previous infringements by the controller or processor; (f) the degree of cooperation with the supervisory authority, in order to remedy the infringement and mitigate the possible adverse effects of the infringement; (g) the categories of personal data affected by the infringement; (h) the manner in which the infringement became known to the supervisory authority, in particular whether, and if so to what extent, the controller or processor notified the infringement; (i) where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned with regard to the same subject-matter, compliance with those measures; (j) adherence to approved codes of conduct pursuant to Article 40 or approved certification measures pursuant to Article 42; and (k) any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained, or losses avoided, directly or indirectly from the infringement.”
“(2) The first type of failure is where a controller or processor has failed, or is failing, to comply with any of the following – (a) a provision of Chapter II of the GDPR [Articles 5 to 11]… (b) a provision of Articles 12 to 22 of the GDPR…; (c) a provision of Articles 25 to 39 of the GDPR…”
“…as the duty to consider whether there are grounds for remission only arises in so far as the facts of the case warrant it, the burden of proving that there is reason to remit is, in effect, on the taxpayer.”
“39…the issues are quite narrow. They are: (1) How much weight was the district judge entitled to give to the decision of the licensing authority? (2) More particularly, was he right to hold that he should only allow the appeal if satisfied that the decision of the licensing authority was wrong?... 41…the licensing function of a licensing authority is an administrative function. By contrast, the function of the district judge is a judicial function. The licensing authority has a duty, in accordance with the rule of law, to behave fairly in the decision-making procedure, but the decision itself is not a judicial or quasi-judicial act. It is the exercise of a power delegated by the people as a whole to decide what the public interest requires… 42. Licensing decisions often involve weighing a variety of competing considerations…They involve an evaluation of what is to be regarded as reasonably acceptable in the particular location… 43. The statutory duty of the licensing authority to give reasons for its decision serves a number of purposes. It informs the public, who can make their views known to their elected representatives if they do not like the licensing sub-committee’s approach. It enables a party aggrieved by the decision to know why it has lost and to consider the prospects of a successful appeal. If an appeal is brought, it enables the magistrates’ court to know the reasons which led to the decision. The fuller and clearer the reasons, the more force they are likely to carry. …45. Given all the variables, the proper conclusion to the first question can only be stated in very general terms. It is right in all cases that the magistrates’ court should pay careful attention to the reasons given by the licensing authority for arriving at the decision under appeal, bearing in mind that Parliament has chosen to place responsibility for making such decisions on local authorities. The weight which the magistrates should ultimately attach to those reasons must be a matter for their judgment in all the circumstances, taking into account the fullness and clarity of the reasons, the nature of the issues and the evidence given on the appeal. …48. It is normal for an appellant to have the responsibility of persuading the court that it should reverse the order under appeal…We see no indication that Parliament intended to create an exception in the case of appeals under the 2003 Act.”
“Criminal law connotes only the quality of such acts or omissions as are prohibited under appropriate penal provisions by authority of the state. The criminal quality of an act cannot be discerned by intuition; nor can it be discovered by reference to any standard but one: Is the act prohibited with penal consequences?”
“…in my judgment a person accused of corrupt practice before an electoral court should only be held to have committed it if the allegation is proved beyond reasonable doubt. The subsection refers to a person being “guilty” of corrupt practice, and that connotes a criminal offence. It would not be desirable to have a different standard of proof in different courts on the same issue.”
“(1) In the determination of his civil rights and obligations or of any criminal charge against him, everyone is entitled to a fair and public hearing within a reasonable time by an independent and impartial tribunal established by law… (2) Everyone charged with a criminal offence shall be presumed innocent until proved guilty according to law. (3) Everyone charged with a criminal offence has the following minimum rights: (a) to be informed promptly, in a language which he understands and in detail, of the nature and cause of the accusation against him; (b) to have adequate time and facilities for the preparation of his defence; (c) to defend himself in person or through legal assistance of his own choosing or, if he has not sufficient means to pay for legal assistance, to be given it free when the interests of justice so require; (d) to examine or have examined witnesses against him and to obtain the attendance and examination of witnesses on his behalf under the same conditions as witnesses against him; (e) to have the free assistance of an interpreter if he cannot understand or speak the language used in court.”
“The weight which the magistrates should ultimately attach to those reasons must be a matter for their judgment in all the circumstances, taking into account the fullness and clarity of the reasons, the nature of the issues and the evidence given on the appeal.”
“It is clear that the data were not processed securely: the documents were left outside, in unlocked containers (“the Breach”).”