Rudd v Bridle & Anor (Rev 1)

[2019] EWHC 893 (QB)

Case details

Case citations
[2019] EWHC 893 (QB)
Court
High Court (Queen's Bench Division)
Judgment date
10 April 2019
Judgment text

This feature is available to zoomLaw Pro members.

Subjects
Data protection Civil procedure Subject access requests
Keywords
Data Protection Act 1998 subject access request personal data data controller legal professional privilege journalism exemption regulatory activity exemption recipient identities source information proportionate search
Outcome
claim succeeded in part; further subject access response ordered against the first defendant
Judicial consideration

This feature is available to zoomLaw Pro members.

Summary

A data controller responding to a subject access request must conduct a reasonable and proportionate search, but must not apply blanket exemptions to retrieved data. The controller must provide intelligible personal data, descriptions of actual or intended recipients, available information about sources, and descriptions of processing purposes. Recipient identities are not ordinarily required under the recipient-description right, although identities forming an integral part of allegations about the data subject may themselves be personal data. Exemptions must be established by the party asserting them. The court may order a further response where deficiencies are material and the request has a legitimate purpose.

Factual background

Dr Rudd brought proceedings under the Data Protection Act 1998 against John Bridle and J&S Bridle Limited. He alleged that responses to subject access requests were inadequate and sought further information about personal data concerning allegations that he had acted dishonestly as an asbestos expert. The defendants relied on legal professional privilege, journalism and regulatory activity exemptions, and disputed which defendant was the data controller.

At trial, the claimant proceeded only with the subject-access claim and the related discretion under section 7(9). The central issues were the scope of the exemptions, the information required concerning recipients, sources and purposes, the appropriate remedy, and the identity of the data controller.

Held

  1. Issues and pleadings. The court was confined to issues fairly raised by the statements of case. The claims under sections 10 and 13 were not fit for determination because the claimant had not properly pleaded that the processing was unwarranted or had caused compensable distress.
  2. Exemptions. A data controller must establish the applicability of an exemption. The journalism exemption required proof that the data were processed only for the special purposes and that each requirement of section 32(1)(a)–(c) was met. The evidence did not establish those matters. The regulatory activity exemption was also not made out: there was no sufficient evidence of likely prejudice to the proper discharge of regulatory functions. The legal advice privilege claim was sufficiently supported, but the evidence did not establish litigation privilege, including the dominant-purpose requirement.
  3. Scope of section 7. A subject access right concerns information, not documents. A reasonable and proportionate search is sufficient, but retrieved data cannot be withheld by a blanket approach. Section 7(1)(b)(iii) requires a description of recipients or classes of recipients. Where disclosure is made to a single recipient, the recipient must be described specifically; a general class description is insufficient. It does not ordinarily require the recipient’s identity.
  4. The identities of persons, firms or companies presented within the data as collaborators, co-conspirators, victims, or persons to whom allegations about Dr Rudd were made formed an integral and biographically significant part of his personal data. The defendants had not justified withholding those identities under section 7(4)–(6). Section 7(1)(c)(ii) separately required disclosure of any available information about sources. The defendants had failed to provide that information adequately. The data supplied were sufficiently intelligible, and the purposes need not be described item by item, but the Third Schedule contained no adequate description of purposes.
  5. Relief and controller. Applying the discretionary factors identified in Ittihadieh v 5-11 Cheyne Gardens [2017] EWCA Civ 121, the court ordered a further subject access response. It could omit data covered by legal advice privilege, but not data previously withheld under litigation privilege. The response had to include recipient descriptions, specified redacted identities, available source information, purposes for the Third Schedule data, and document dates. Mr Bridle, rather than the Company, was the data controller because he determined the purposes and manner of processing in a personal capacity. No substantive remedy was granted against the Company.

The court’s approach to earlier authorities

This feature is available to zoomLaw Pro members.

Key cases cited

This feature is available to zoomLaw Pro members.

Cases citing this case

This feature is available to zoomLaw Pro members.