Case details
Summary
Misuse of private information is a tort for the service-out gateway. It is a distinct cause of action from breach of confidence, although its development drew on the law of confidence and gives effect to privacy rights.
Under Data Protection Act 1998, compensation for non-pecuniary damage is available for unlawful data processing. The statutory restriction on compensation for distress in section 13(2) was incompatible with EU law and had to be disapplied to secure an effective remedy.
Data which enables an internet user to be singled out may be personal data even without identification by name. A privacy claim should not be stayed as disproportionate merely because individual damages may be modest where the alleged intrusion and issues of principle are substantial.
Factual background
Three Safari browser users alleged that Google secretly circumvented Safari’s default privacy settings. They said that it used cookies to collect browser-generated information about their internet activity and to target advertising without their knowledge or consent.
They claimed misuse of private information and compensation under the Data Protection Act 1998, without alleging pecuniary loss. Permission had been granted to serve Google in California. Tugendhat J, in [2014] EWHC 13 (QB), upheld jurisdiction over the misuse-of-private-information and data-protection claims, but set aside the breach-of-confidence and injunction claims.
Google appealed on whether misuse of private information was a tort for service-out purposes, whether section 13 permitted compensation for distress without pecuniary loss, whether the browser-generated information was arguably personal data, and whether the claims had sufficient value to proceed.
Held
Appeal dismissed. The court upheld permission to serve the claims out of the jurisdiction.
Misuse of private information is a tort for the purposes of the tort gateway in CPR Practice Direction 6B. It protects privacy, autonomy and dignity, unlike breach of confidence, which protects secret or confidential information. The court approved the development identified in Campbell v MGN Ltd [2004] 2 AC 457 and held that the contrary observations in Douglas v Hello! Ltd (No 3) [2006] QB 125 were obiter. Kitechnology BV v Unicor GmbH remained applicable to a traditional equitable breach-of-confidence claim, but did not govern the distinct tort of misuse of private information.
“Damage” in article 23 of Directive 95/46/EC includes material and non-material damage. A restrictive reading would undermine the Directive’s purpose of protecting data privacy. The discussion of section 13 in Johnson v Medical Defence Union [2007] 96 BMLR 99 was obiter and did not bind the court.
Section 13(2) of the Data Protection Act 1998 could not be read compatibly with the Directive without contradicting a fundamental feature of Parliament’s scheme. But the restriction was incompatible with the right to an effective remedy under article 47 of the Charter. It was therefore disapplied. Compensation under section 13(1) could consequently be claimed for non-pecuniary damage caused by a contravention.
There was a serious issue to be tried that the browser-generated information was personal data. Identification need not mean identification by name. Data capable of singling out a user, or capable of being combined with other information held by the controller, might satisfy section 1(1). The issues concerning third-party identification required factual findings and trial.
The claims were not an abuse under the Jameel v Dow Jones principle. The alleged secret and sustained collection of highly private browsing information was capable of engaging article 8 rights. Modest compensatory awards did not make the litigation pointless, and costs could be controlled through case management.
The court’s approach to earlier authorities
This feature is available to zoomLaw Pro members.
Appellate history
Court of Appeal (Civil Division) Dismissed Google’s appeal and upheld jurisdiction over the misuse-of-private-information and data-protection claims: [2015] EWCA Civ 311.
High Court, Queen’s Bench Division Tugendhat J refused to set aside permission for service out in respect of those claims, but set aside the breach-of-confidence and injunction claims: [2014] EWHC 13 (QB).
Master On 12 June 2013, Master Yoxall granted permission to serve the claim form on Google in California.
Lower court decision
Key cases cited
This feature is available to zoomLaw Pro members.
Cases citing this case
This feature is available to zoomLaw Pro members.