The CQC will conduct reviews on a monthly basis of all of the information they hold about services and will use these reviews to prioritise its activity.
Two recent cases illustrate the rather unpredictable nature of these decisions, as confirmed by Lord Justice Irwin noted in the Bellman case below. These cases appear, more than any, to be so reliant on their individual facts and whilst they are important to note, no great sea change has occurred.
As ever when it comes to the Christmas party season the practical advice remains the same. A short, informative but warm email reminding employees that works’ “dos” are a time to have fun and relax, but not at the expense nor discomfort of colleagues, sets the tone. A clear boundary of where the employer’s provisions end in terms of alcohol and food is further useful as is an email to senior employees reminding them of their responsibilities even when in a relaxed setting and the potential perils of failing to do so
Wm Morrison Supermarkets Plc v Various 
Whatever your view is on Morrisons’ food you would be hard-hearted not to feel some sympathy for them following the Court of Appeal’s judgement in this case. They are having to pay an as yet undisclosed sum in damages following the actions of a disgruntled employee.
S worked for Morrisons as an internal IT auditor. Following disciplinary proceedings against him, he developed a grudge against his employer and decided to take action. He copied data which included payroll details of over 100,000 employees onto a USB stick, took the data home and released it on the internet and to a number of newspapers. S had been given access to this information by Morrisons for the purpose of an internal audit.
He was convicted of criminal offences including offences under the Data Protection Act 1998. However, Morrison’s nightmare was not over as 5,000 of the employees whose data had been leaked then bought a claim in the High Court for damages for misuse of private data, breach of confidence and breach of Morrison’s statutory duty under the DPA 1998. Morrisons was held vicariously responsible for S’s actions as the company had appointed S the data controller.
The High Court held that whilst Morrisons had not misused or permitted the misuse of confidential information, there was a sufficient connection between the company and S to deem it vicariously liable for S’s actions. Morrisons, not surprisingly given the monetary cost and reputational damage of such a claim, appealed to the Court of Appeal. They argued on the vicarious liability point that S’s actions did not occur during the course of employment and hence Morrisons was free from liability. They further argued that the DPA 1998 implied that there was no vicarious liability for the misuse of private information since the legislation provided a statutory code to deal with such breaches.
The Court of Appeal, however, did not agree. On the DPA point, they concluded that Parliament had never meant the legislation to exclude vicarious liability. The DPA is silent on the liability of an employer who is not a data controller for breaches made by that data controller and so in the absence of any statutory provision, the only remedy left was through vicarious liability.
As to whether vicarious liability existed in this situation, the Court of Appeal was adamant; the principle still applies even when the wrongdoing is committed away from the workplace provided there was a seamless sequence of events so no event to break the causation chain and the chain of liability. The Judge was empathetic in his comments that S breached the DPA, not for his own gain but to harm Morrisons but nevertheless concluded that Morrisons must still be held vicariously liable.
This case rather leaves employers exposed to the ad hoc actions of disgruntled employees hell-bent on revenge! The only comfort may come from the fact that this case is the first on such a scale that we have seen. Some guidance has suggested larger employers look to insure against these losses. Whilst this may meet legal fees it does not address reputational damage and share price losses. Greater security might be necessary to prevent highly confidential information being downloaded but this might not be reasonably practicable for many employers.
Practically speaking, this should be read as a cautionary tale but there are some learning points to be taken.
- ensure data protection training is up to date (note this case was heard prior to GDPR);
- emphasise to employees the criminal nature of serious breaches of the data protection laws and the tight security that exists to prevent breaches; and
- place where possible restrictions to downloading information and making it more portable.
In June 2021 the Education and Skills Funding Agency ESFA issued its annual update to their Academies Financial Handbook. The purpose of this briefing is to summarise the changes and any particular ac
From 30 September 2021, the costs of issuing certain applications in the Family Court will increase, following the implementation of the Court Fees Order.
Are your board members or trustees doing any of these three things with their emails, which are a risk to both your resources and relationships?
Must a defended possession claim at first hearing be adjourned with directions?
Thomas Starkey has been recruited to help lead Anthony Collins Solicitors housing practice, with the remit of growing ACS’ Manchester office and property team.
The monthly round-up from the Anthony Collins Solicitors charities team.
Since GDPR has come into effect, many companies have struggled to comply with GDPR. In this ebriefing, we look at the shocking data breach at Hackney Council.
The High Court has ruled that retrospective changes to the LGPS exit credits regime were lawful – and gave some helpful guidance around the new discretion to pay an exit credit.
The Government has brought forward draft laws to allow independent schools to close the Teacher’s Pension Scheme to new joiners but to allow existing members to continue.
To receive invitations to our events, as well as information and articles on legal issues and sector developments that are of interest to you, please sign up to Newsroom.