Smeaton v Equifax Plc

[2013] EWCA Civ 108

Case details

Case citations
[2013] EWCA Civ 108 · [2013] CN 263
Court
Court of Appeal (Civil Division)
Judgment date
20 February 2013
Judgment text

This feature is available to zoomLaw Pro members.

Subjects
Data protection Negligence Credit reference agencies
Keywords
fourth data protection principle accuracy of personal data credit reference agency rescinded bankruptcy order reasonable steps duty of care causation credit refusal
Outcome
appeal allowed (unanimous)
Judicial consideration

This feature is available to zoomLaw Pro members.

Summary

A credit reference agency does not breach the fourth data protection principle merely because data, accurately copied from an authoritative third-party source, later becomes inaccurate. Where paragraph 7 of Part II of Schedule 1 applies, the decisive question is whether the agency took reasonable steps to ensure accuracy.

Reasonableness must be assessed in the statutory and regulatory context. It did not require an agency to identify a rare information gap and lobby for a change in the law. A statutory data-protection duty does not itself create a concurrent common-law duty of care. In any event, loss must be proved to have been caused by the inaccurate data; other adverse credit data and events after correction may defeat causation.

Factual background

Equifax retained an entry recording that Keith Smeaton was subject to a bankruptcy order after that order had been rescinded. At the material time Equifax obtained bankruptcy information from the London Gazette. The rescission was neither advertised there nor notified to Equifax.

Mr Smeaton alleged that the inaccurate entry caused National Westminster Bank to refuse finance to Ability Records Ltd, a company he controlled. His credit file also contained an unsatisfied county court judgment and numerous defaults. The High Court held that Equifax had breached the Data Protection Act 1998, owed a co-extensive duty in negligence, and had caused loss: [2012] EWHC 2088 (QB).

Equifax appealed. The central issues were whether it had taken reasonable steps to ensure data accuracy, whether a concurrent tortious duty existed, and whether the alleged breach caused the inability to obtain finance.

Held

Appeal allowed unanimously. Tomlinson LJ gave the principal judgment, with which Davis LJ and Sir Robin Jacob agreed.

  1. The finding of causation could not stand. The National Westminster letters referred to adverse data generally. Mr Smeaton’s file contained significant adverse material apart from the rescinded bankruptcy order. The evidence did not support a finding that either application was rejected solely because of that order.

  2. Even assuming that the inaccurate entry affected the first application, it did not explain a failure to obtain credit after Equifax corrected the file. The claimed later consequences were too remote, and there was a break in the chain of causation. The claim should therefore have been dismissed on that ground.

  3. Equifax had not contravened the fourth data protection principle in Data Protection Act 1998, Schedule 1. Paragraph 7 of Part II required consideration of whether it had taken reasonable steps to ensure accuracy. It had obtained information from the authoritative Gazette, recorded it accurately, corrected it immediately when informed of the rescission, and adopted the electronic insolvency feed when it became available. The rare statutory gap concerning rescissions did not oblige it to seek a legislative or regulatory change.

  4. The insolvency scheme deliberately differentiated rescissions from annulments. It did not require automatic notification of a rescission to the relevant authorities or its advertisement in the Gazette. That context supported the conclusion that Equifax’s procedures were reasonable.

  5. No common-law duty of care co-extensive with the statutory duty arose. A statutory duty cannot itself generate a negligence duty. Nor did the traditional duty-of-care analysis justify one: the detailed statutory regimes supplied the applicable obligations and remedies, and a duty to the public at large would expose Equifax to indeterminate liability.

The High Court’s answers to its first two questions were replaced with “No”; the causation issue did not arise, but would also have been answered “No”.

The court’s approach to earlier authorities

This feature is available to zoomLaw Pro members.

Appellate history

  • Court of Appeal (Civil Division): Allowed Equifax’s appeal and held that the claim should have been dismissed: [2013] EWCA Civ 108.
  • High Court (Queen’s Bench Division): Held that Equifax breached the Data Protection Act 1998, owed a co-extensive duty in tort, and caused loss: [2012] EWHC 2088 (QB).

Lower court decision

Judgment appealed:
Outcome:
appeal allowed (unanimous)

Key cases cited

This feature is available to zoomLaw Pro members.

Cases citing this case

This feature is available to zoomLaw Pro members.