Employer vicariously liable for deliberate data breach by rogue employee
The Court of Appeal has upheld the High Court’s decision in WM Morrison Supermarkets plc v Various Claimants that an employer was vicariously liable for a data breach by one of its employees who deliberately disclosed his co-workers’ personal data.
Mr Skelton, an internal auditor, developed a grudge against his employer after he was given a formal verbal warning and decided to use his authorised access to payroll data to cause damage to his employer. He had been given an encrypted USB stick containing payroll data to provide to KPMG for auditing purposes. He downloaded this information onto a personal USB stick and set up a file containing personal details such as names, dates of birth, national insurance numbers, bank account and salary details of almost 100,000 Morrisons employees. He put this information on a file-sharing website and anonymously notified a number of newspapers of the data leak shortly before Morrisons was about to announce its annual financial report. This had serious implications for the share value and a concern that the data could be used to access the individuals’ bank accounts or for identity theft. He was convicted of fraud and of offences under the Computer Misuse Act 1990 and the Data Protection Act 1998.
Over 5000 employees brought claims against Morrisons for breach of the Data Protection Act 1998 (DPA), misuse of private information and breach of confidence. The High Court dismissed the all claims for primary liability as Morrisons had not directly misused or permitted the misuse of any personal information. It was not disputed that Mr Skelton was the data controller for DPA purposes. However, the Court did find that Morrisons was vicariously liable under the DPA as this is not specifically excluded under the legislation and there was a sufficient connection between Mr Skelton’s employment and the actions he took.
The Court of Appeal agreed with the conclusions concerning primary liability. It also held vicarious liability was covered by the DPA and went on to consider whether his actions were “in the course of his employment” following the two stage test established by Mohamud v Morrisons. This is whether the actions fell within the “field of activities” entrusted to him and whether there was sufficient connection between the position in which he was employed and his wrongful conduct to make it right under the principle of social justice for Morrisons to be held liable. The Court found that Mr Skelton was entrusted with the payroll data as part of his role and the tortious act of sending it to third parties was in the field of activities assigned to him. His actions were “seamless and continuous” and “an unbroken chain of events”. Therefore Morrisons was vicariously liable.
An unusual feature, and one basis for the appeal, was that although motive is usually irrelevant, in this case Mr Skelton’s objective was to cause damage to his employer. Morrisons argued that in finding it vicariously liable, the Court had become an accessory in furthering Mr Skelton’s criminal aims. However, the Court did not agree that this meant there could be an exception to the principle that motive is irrelevant.
Morrisons has indicated that it intends to appeal to the Supreme Court.
This is a very worrying decision for employers. As the court itself recognised, there is no failsafe system for preventing a rogue employee who is determined to deliberately cause damage to his/her employer in this way. Morrisons was not guilty of any failure which enabled the breach to occur but it ended up with the liability.
This case does not deal with quantum, which will be determined once any appeal to the Supreme Court has been heard. The data breach does not appear to have caused any financial loss to the employees and any amount awarded per individual may be fairly nominal. However, as there are potentially 100,000 employees affected compensation could be significant. It will be interesting to see how the Court approaches this.
This decision was made under the DPA 1998 and is the first group litigation on data breach in 20 years. There are now fears that following the success of the claimants this case, more claims of this nature will be brought. Unfortunately for employers, unless the Supreme Court overturns this decision, this scenario seems more likely given that following the implementation of GDPR businesses are under an obligation to tell individuals about any data breach which will effectively put them on notice that they have a claim.
The Court considered the “potentially ruinous costs” implications raised by Morrisons but decided that this was not an issue as in its view the employer could put insurance in place to cover this. Employers would therefore be well-advised to take steps to investigate and if possible put in place cyber insurance to cover the actions of malicious and dishonest employees. Whether insurance companies will cover this risk remains to be seen.
For more information please contact Nick Hurley.
Flexible working requests: 5 tips for employers
ICO's new Age Appropriate Design Code: The impact on business
Charles Russell Speechlys advises Acora on acquisition of Westgate IT
Westgate IT specialises in providing IT support to businesses in the South West.
Nick Hurley quoted by the Society for HR Management on the UK government's proposals to prevent workplace sexual harassment
The U.K. government introduced legislation in July 2021 for employers to take proactive steps to prevent sexual harassment on the job.
Olivia Crane writes for The Grocer on the importance of robust data protection policies for checkout-less stores
The ‘personal data footprint’ created by this type of service and technology isn’t something that should be overlooked.
Returning to work post-lockdown: FAQs for employers
We look at some of the main issues employers may face and the key steps to consider as restrictions ease.
Covid passports - are they workable or just a shambles?
Amelia Goodwin writes for Civil Society on a recent employment tribunal ruling which found that anxiety constitutes a disability
The tribunal found that an anxiety state constitutes a disability for the purposes of the Equality Act 2010.
Face coverings at work post lockdown
While the legal requirement has been lifted, employers may consider face coverings as an appropriate safety measure in certain workplaces.
Charles Russell Speechlys advises Apposite Capital on acquisition of i2a Diagnostics
i2a is a leading provider of laboratory instruments, software and reagents for the clinical microbiology market in France.
Brace yourselves: dentists could be liable for actions of self-employed staff
Nick Hurley interviewed by GB News on the legal ramifications of employers insisting employees have the COVID-19 vaccine
Nick considers the potential dangers of employers setting a precedent by adopting a 'No Jab, No Job' policy.
Government to introduce duty on employers to prevent sexual harassment
Michael Powner writes for People Management and explains how employers can carry out an equal pay audit
How do employers carry out an equal pay audit?
COVID-19 Vaccination – can an employer make it compulsory for employees?
We review what legal issues to take into account when considering to make vaccination compulsory as an employer.
Changes to Right to Work Checks from 1 July 2021
EEA citizens and their family members are required to evidence immigration status in the UK, in the same way as other foreign nationals.
Changes to Right to Rent Checks from 1 July 2021
Following the UK’s departure from the EU, the right to rent checks grace period of six months will end on 30 June.
Michael Powner and Laurence Whymark write for The Caterer on the implications of the new tipping laws on the hospitality industry
Operators will soon have to pass on tips to staff without deductions.
Post-Brexit business visitors and working in France, Germany, Spain and the UK
Watch the final session in a series of webinars on post-Brexit mobility.
Top 7 Data Protection Tips for Employers
Here are our top 7 data protection tips for employers.