Case details
Summary
A data controller’s implied duty to search for personal data in response to a subject access request is limited to searches that are reasonable and proportionate. The court will not generally require access to private email accounts without evidence providing sufficient justification for the intrusion. Legal professional privilege may exempt data from subject access where the privilege claim is established. The iniquity exception requires at least a prima facie case of wrongdoing; speculation that material might reveal criminality or a breach of privacy is insufficient. Inspection of privileged material under the Data Protection Act 1998 should be a last resort, requiring credible evidence that the privilege decision is unreliable or no reasonably practical alternative.
Factual background
The claimant sought orders under section 7(9) of the Data Protection Act 1998 requiring the defendants to comply with narrowed subject access requests concerning alleged investigations and surveillance. The defendants disclosed some material but relied on legal professional privilege for other data and maintained that their searches were adequate.
The issues were whether the searches were reasonable and proportionate, whether the privilege exemption applied, whether the iniquity exception displaced privilege, and whether the court should inspect the disputed data under section 15(2). The court also considered, but did not determine, whether the requests were an abuse of the subject access right.
Held
- Searches. A data controller has an implied obligation to search for relevant personal data, but the obligation is limited by reasonableness and proportionality. The searches undertaken, including searches of corporate systems and Mr Candy’s personal Gmail account, were reasonable and proportionate. There was no sufficient reason to require searches of the private email accounts of other custodians.
- A company may need access to a director’s private account where there is reason to believe that the director processed relevant data on the company’s behalf. However, a private-account search is an intrusion requiring justification. The mere possibility that corporate business might have been conducted through private accounts was insufficient on the evidence.
- Legal professional privilege. The burden of proving the exemption rested on the data controller. The evidence established that the disputed data were covered by litigation privilege relating to the Injunction Proceedings. The privilege claim was not defeated merely because third parties had been instructed to investigate matters for litigation purposes.
- Iniquity. A speculative case that privileged data might reveal wrongdoing cannot displace privilege. At least a prima facie case of wrongdoing was required. The evidence did not establish a sufficient basis for concluding that the USG data evidenced a breach of section 55 of the Data Protection Act 1998 or other criminal conduct. The court rejected the proposed extension of the iniquity principle to any possible breach of a fundamental right. Such an extension would substantially erode legal professional privilege, which itself attracts fundamental-rights protection.
- Inspection. Inspection under section 15(2) should be a last resort. It was inappropriate to inspect the data merely to conduct an inquisitorial examination of whether privacy infringements might be revealed, absent credible evidence of wrongdoing or other exceptional circumstances.
- The court therefore made no order under section 7(9). The claim was dismissed. The court left the abuse issue unresolved because it was unnecessary to determine it on the merits.
The court’s approach to earlier authorities
This feature is available to zoomLaw Pro members.
Key cases cited
This feature is available to zoomLaw Pro members.
Cases citing this case
This feature is available to zoomLaw Pro members.