Sanso Rondon v LexisNexis Risk Solutions UK Ltd

[2021] EWHC 1427 (QB)

Case details

Case citations
[2021] EWHC 1427 (QB)
Court
High Court (Queen's Bench Division)
Judgment date
28 May 2021
Judgment text

This feature is available to zoomLaw Pro members.

Subjects
Tort Data protection Statutory interpretation
Keywords
GDPR Article 27 representative controller liability data protection foreign controller recital 80 effective judicial remedy strike out representative liability
Outcome
claim dismissed
Judicial consideration

This feature is available to zoomLaw Pro members.

Summary

A GDPR representative appointed under Article 27 is not thereby made jointly liable for the controller’s obligations or a substitute defendant in proceedings by data subjects. The representative has a bespoke, active role involving local transparency, record-keeping, communication and regulatory co-operation. Article 27(4) permits supervisory authorities and data subjects to address the representative on processing issues, but Article 27 does not make the representative responsible for remedies requiring control of the personal data. Recital 80 cannot be used to introduce a comprehensive liability regime absent from the operative provisions. The controller remains responsible for its own GDPR obligations, subject to the practical limits of extra-territorial enforcement and international co-operation.

Factual background

The claimant alleged that World Compliance Inc, a company established outside the Union and the controller of a database containing his personal data, had breached the GDPR. The defendant, an English company, was WorldCo’s designated Article 27 representative.

The claimant sought erasure-related relief, notification orders and compensation against the representative on the basis that Article 27 made it liable for breaches committed by the controller. The defendant applied to strike out the claim under CPR rule 3.4 or obtain summary judgment under CPR Part 24. The parties agreed that the application raised a pure question of law: whether Article 27 permits a data subject to sue the representative in place of, or in addition to, the foreign controller.

Held

  1. Application granted. The claim was struck out because there was no legal basis for bringing it against the defendant in its capacity as WorldCo’s Article 27 representative.
  2. Article 27 must be interpreted in the context of the GDPR’s structure. Representatives have directly imposed obligations, including maintaining records, providing information and co-operating with supervisory authorities. Their role is active and more substantial than that of a mere postbox, but it remains ancillary to enforcement against the controller.
  3. Article 27(4), requiring the representative to be addressed by supervisory authorities and data subjects on all issues related to processing, concerns contact, communication, transparency and facilitation. It does not transfer the controller’s substantive obligations or remedies to the representative.
  4. The GDPR does not give representatives the powers or status of controllers or processors. Remedies such as rectification, erasure and subject access require access to, and control over, personal data. The GDPR does not confer those functions on representatives or impose on them the corresponding controller obligations.
  5. Article 27(5), the provisions on controllers, processors and representatives elsewhere in the GDPR, the Data Protection Act 2018, the EDPB Guidelines and the ICO’s practical position all supported the conclusion that any direct liability of a representative is confined to its own specified obligations, including those concerning records and investigation.
  6. Recital 80 was a relevant interpretative aid but had no independent normative effect. Its reference to enforcement proceedings could be understood as permitting enforcement measures against the controller to be addressed or served through the representative. It could not create a comprehensive scheme of representative liability absent from Article 27.
  7. The principle of effectiveness did not require unlimited extra-territorial remedies or dissolution of jurisdictional limits. The GDPR provides effective remedies against foreign controllers insofar as international law permits, with the representative supporting local enforcement and co-operation.

The court’s approach to earlier authorities

This feature is available to zoomLaw Pro members.

Key cases cited

This feature is available to zoomLaw Pro members.

Cases citing this case

This feature is available to zoomLaw Pro members.