Summary
Vicarious liability for an employee’s misuse of private information or breach of confidence is not excluded by the Data Protection Act 1998 unless Parliament has done so by necessary implication. The statutory scheme regulates the primary duties of the data controller but does not address an employer’s liability for an employee data controller’s wrongdoing. The ordinary close-connection test applies broadly: the employee’s field of activities is identified first, followed by consideration of the connection between that position and the wrongful conduct. The employee’s motive is irrelevant. Deliberate disclosure outside the workplace may still fall within the course of employment where it forms part of an unbroken sequence linked to the assigned task.
Factual background
More than 5,000 current and former employees brought claims against Morrisons after Andrew Skelton, a former employee, copied payroll data while at work and later disclosed it on the internet. Langstaff J held that Morrisons was not primarily liable under the Data Protection Act 1998, for misuse of private information or for breach of confidence, but was vicariously liable for Skelton’s wrongdoing: [2017] EWHC 3113 (QB).
Morrisons appealed on the grounds that the statutory scheme excluded vicarious liability and the common-law and equitable causes of action, and that Skelton’s conduct was outside the course of employment. The central issues were statutory exclusivity and the application of the close-connection test to a malicious data disclosure made away from work.
Held
Appeal dismissed. The Court of Appeal upheld the finding that Morrisons was vicariously liable for Skelton’s misuse of private information and breach of confidence.
- Statutory exclusion. The relevant question was whether Parliament had intended, by necessary implication, to exclude the common-law remedy. The approach in R (Child Poverty Action Group) v Secretary of State for Work and Pensions [2010] UKSC 54 was applied. A statutory remedy is likely to exclude a common-law remedy only where the schemes cover the same ground and are substantially incompatible. The Data Protection Act 1998 imposed primary duties on the data controller, but said nothing about an employer who was not the data controller. It therefore did not exclude vicarious liability for an employee’s common-law or equitable wrongs.
- Close connection. Following Mohamud v Wm Morrison Supermarkets plc [2016] UKSC 11, the court asked first what field of activities Morrisons had entrusted to Skelton and secondly whether there was a sufficient connection between that position and his wrongful conduct.
- Application. Skelton had been deliberately entrusted with receiving, storing and disclosing payroll data to KPMG. His unauthorised disclosure was closely related to that assigned task. The fact that the disclosure occurred at home, on a Sunday, using personal equipment and after a period of delay was not decisive. The copying, concealment and later publication formed a seamless and continuous sequence. Credit Lyonnais Bank Nederland NV v Export Credits Guarantee Department [2000] 1 AC 486 and Warren v Henlys [1948] 2 All ER 935 were distinguishable.
- Motive. The employee’s motive was irrelevant. There was no exception where the employee intended to harm the employer. Deliberate wrongdoing may attract vicarious liability where the close-connection test is satisfied. The availability of insurance was a legitimate answer to arguments about potentially catastrophic liability, although it was not itself a basis for imposing liability.
The court’s approach to earlier authorities
Available to signed-in members.
Appellate history
- Court of Appeal (Civil Division). The appeal was dismissed, upholding Morrisons’ vicarious liability.
- High Court of Justice, Queen’s Bench Division. Langstaff J held Morrisons vicariously liable for the wrongful disclosure of employee data: [2017] EWHC 3113 (QB) .
Appeal route
- Appealed from[2017] EWHC 3113 (QB)This appealappeal dismissed
- This judgment [2018] EWCA Civ 2339 Court of Appeal (Civil Division)
- Appealed to[2020] UKSC 12Outcomeappeal allowed unanimously
Key cases cited
13 authorities cited.
- The Commissioners for Her Majesty’s Revenue and Customs v The Investment Trust Companies [2017] UKSC 29
- A M Mohamud (in substitution for Mr A Mohamud (deceased)) v WM Morrison Supermarkets plc [2016] UKSC 11
- The Catholic Child Welfare Society and others v Various Claimants and The Institute of the Brothers of the Christian Schools and others [2012] UKSC 56
- The Child Poverty Action Group v Secretary of State for Work and Pensions [2010] UKSC 54
- Campbell (Appellant) v. MGN Limited (Respondents) [2004] UKHL 22
- Dubai Aluminium Company Limited v. Salaam (Original Respondent and 2nd Cross-appellant) and others (Original Appellants and Cross-respondents) and Others and another (Original Respondent and 1st Cross-appellant) [2002] UKHL 48
- Lister and Others v Hesley Hall Ltd [2001] UKHL 22
- Credit Lyonnais Bank Nederland NV (now Generale Bank Nederland NV) v Export Credits Guarantee Department [2000] 1 AC 486
- Lloyd v Grace, Smith & Co [1912] AC 716
- Bellman v Northampton Recruitment Ltd [2018] EWCA Civ 2214
- Omar & Ors, R (on the applicatiom of) v Secretary of State for Foreign & Commonwealth Affairs [2013] EWCA Civ 118
- Criminal proceedings against Lindqvist (Criminal proceedings against Bodil Lindqvist.) Case C-101/01
- Warren v Henlys Ltd [1948] 2 All ER 935
Sign in to see how the court treated each authority. A free account is enough.
Cases citing this case
4 later cases · 3 positive · 1 neutral
Most senior citing decisions:
- BT Group Plc & Anor. v Justin le Patourel [2022] EWCA Civ 593 considered
- London Borough of Haringey v FZO [2020] EWCA Civ 180 applied
- GRAEME SMITH & OTHERS v TALKTALK TELECOM GROUP PLC [2022] EWHC 1311 (QB) followed
- DSG Retail Limited v The Information Commissioner [2024] UKUT 287 (AAC)
Sign in for the full treatment table. A free account is enough.