WM Morrison Supermarkets plc v Various Claimants

[2020] UKSC 12

Case details

Case citations
[2020] UKSC 12 · [2020] AC 989 · [2020] 2 WLR 941 · [2020] ICR 874 · [2021] 1 All ER (Comm) 189 · [2020] 4 All ER 1
Court
United Kingdom Supreme Court
Judgment date
1 April 2020
Judgment text

This feature is available to zoomLaw Pro members.

Subjects
Tort Vicarious liability Data protection
Keywords
close connection test course of employment employee misconduct personal vendetta payroll data data breach misuse of private information breach of confidence employee data controller
Outcome
appeal allowed unanimously
Judicial consideration

This feature is available to zoomLaw Pro members.

Summary

An employer is vicariously liable only where an employee’s wrongful conduct is so closely connected with authorised acts that it may fairly and properly be regarded as done in the ordinary course of employment. A temporal or causal connection, or the mere opportunity provided by employment, is insufficient. Whether the employee was furthering the employer’s business or pursuing purely personal ends is highly material.

Statutory vicarious liability remains available unless the relevant statute expressly or impliedly excludes it. The Data Protection Act 1998 did not exclude vicarious liability for an employee data controller’s statutory breach, misuse of private information or breach of confidence, provided the employee acted in the course of employment.

Factual background

An employee of the appellant supermarket obtained payroll data while authorised to transmit it to external auditors. Motivated by a grudge against his employer, he secretly copied the data and later published it online. Thousands of affected employees claimed damages for breach of the Data Protection Act 1998, misuse of private information and breach of confidence.

The High Court held that the employer had no primary liability but was vicariously liable: [2017] EWHC 3113 (QB); [2019] QB 772. The Court of Appeal dismissed the employer’s appeal: [2018] EWCA Civ 2339; [2019] QB 772.

The Supreme Court considered whether the disclosure was sufficiently connected with the employee’s authorised activities and, if so, whether the 1998 Act excluded vicarious liability for statutory, common-law or equitable wrongs.

Held

  1. Appeal allowed unanimously. Lord Reed, with whom Lady Hale, Lord Kerr, Lord Hodge and Lord Lloyd-Jones agreed, held that the employee’s disclosure was not so closely connected with his authorised activities that it could fairly and properly be regarded as occurring in the ordinary course of employment. The employer was therefore not vicariously liable.
  2. The governing close-connection test asks what functions or field of activities the employer entrusted to the employee and whether the wrongdoing was so closely connected with authorised acts that it may fairly and properly be regarded as done in the ordinary course of employment. The words “fairly and properly” require principled reasoning from decided cases. They do not invite a decision based on a judge’s personal sense of social justice.
  3. The courts below had misunderstood Mohamud v WM Morrison Supermarkets plc [2016] UKSC 11. References there to an “unbroken sequence” and “seamless episode” concerned the capacity in which the employee acted, not merely temporal or causal continuity. Although the employee’s authorised task gave him the opportunity to copy the payroll data, opportunity and causal sequence were insufficient. Publication fell outside his assigned functions. He was pursuing a personal vendetta intended to harm his employer, rather than furthering its business.
  4. The five factors discussed in Various Claimants v Catholic Child Welfare Society [2012] UKSC 56 concerned whether a relationship was akin to employment. They did not determine whether particular wrongdoing was sufficiently connected with employment.
  5. Although unnecessary to the disposition, the court held that the Data Protection Act 1998 did not expressly or impliedly exclude vicarious liability. Its fault-based liability for a data controller was compatible with an employer’s strict vicarious liability. Vicarious liability may therefore arise for an employee data controller’s breach of the Act, misuse of private information or breach of confidence, provided the employee committed the wrong in the course of employment.

The court’s approach to earlier authorities

This feature is available to zoomLaw Pro members.

Appellate history

  1. United Kingdom Supreme Court: The employer’s appeal was allowed unanimously: [2020] UKSC 12. The Court of Appeal’s conclusion that the employer was vicariously liable was reversed.
  2. Court of Appeal: The employer’s appeal was dismissed: [2018] EWCA Civ 2339; [2019] QB 772. The court held that the disclosure fell within the employee’s assigned field of activities and formed part of a seamless sequence of events.
  3. High Court: The employer was held not primarily liable but vicariously liable for the employee’s statutory breach, misuse of private information and breach of confidence: [2017] EWHC 3113 (QB); [2019] QB 772.

Lower court decision

Judgment appealed:
Outcome:
appeal allowed unanimously

Key cases cited

This feature is available to zoomLaw Pro members.

Cases citing this case

This feature is available to zoomLaw Pro members.