Brake & Anor v Guy & Ors

[2021] EWHC 671 (Ch)

Case details

Case citations
[2021] EWHC 671 (Ch)
Court
High Court (Chancery Division)
Judgment date
25 March 2021
Judgment text

This feature is available to zoomLaw Pro members.

Subjects
Equity and trusts Privacy and confidentiality Employment
Keywords
breach of confidence misuse of private information business email account reasonable expectation of privacy employee email use confidentiality agreement procuring breach of contract injunction destruction of documents iniquity defence
Outcome
claim dismissed
Judicial consideration

This feature is available to zoomLaw Pro members.

Summary

An employee who uses an employer’s business email account for private correspondence does not necessarily have a reasonable expectation of privacy or confidentiality in that correspondence. The question depends on all the circumstances, including ownership and purpose of the account, access by colleagues, segregation or labelling of private material, and the availability of personal accounts.

Ownership of the account, password protection and a previous confidentiality agreement are relevant context but are not conclusive. Disclosure of private or confidential material to legal or other professional advisers for a reasonable purpose, in confidence and without onward dissemination, is not ordinarily misuse. Statutory provisions creating criminal, regulatory or procedural consequences do not automatically create a separate civil cause of action.

Factual background

The claimants sued in respect of the defendants’ access to, retention and use of emails in three accounts associated with the Axnoller domain. They alleged breach of confidence, misuse of private information, breach of contract, harassment, data-protection breaches and Convention violations. The defendants said that the principal enquiries account was a business asset acquired with the relevant business, although Mrs Brake had used it for personal correspondence.

The trial determined the ownership and status of the accounts, whether the claimants had reasonable expectations of confidentiality or privacy, whether the defendants’ dealings with the emails were actionable, and whether the defendants had procured a breach of a confidentiality agreement. The court also considered the legal availability of an iniquity or public-interest defence, although the claim was dismissed without needing to try that defence.

Held

  1. Ownership. The Axnoller domain was initially registered for Mrs Brake, but the court held that the domain and the relevant 2015 Microsoft Exchange accounts passed to the business carried on by Sarafina Properties Ltd and subsequently to the defendants. The accounts were distinct from the email addresses pointing to them. Alternatively, any residual rights of Mrs Brake were estopped by her knowledge that the purchaser believed the domain and accounts were included in the sale and her failure to correct that belief.
  2. Breach of confidence. The claim failed because the claimants had not shown that the disputed information was imparted to the defendants in circumstances importing an obligation of confidence. The account belonged to the business, was used principally for business purposes, and was accessible to colleagues. The confidentiality agreement with the IT provider could not derogate from the business’s rights in its own account and did not cover retainers for the business.
  3. Misuse of private information. The court applied the broad, objective assessment required when deciding whether there was a reasonable expectation of privacy. Mrs Brake deliberately used a business account, stored private and business emails together, knew colleagues had access, and had other personal accounts available. In those circumstances she had no reasonable expectation of privacy in emails sent or received through the enquiries account.
  4. Use and disclosure. The defendants’ provision of material to lawyers, counsel and professional advisers for legitimate advice and litigation purposes, subject to confidentiality, was not misuse. Nor was supplying information which a trustee in bankruptcy or partnership liquidator would have been entitled to obtain on a proper application. The defendants’ agreed deletion of 5,511 emails meant that no further injunction or destruction order was required.
  5. Other causes of action. Articles 6 and 8 of the European Convention on Human Rights added nothing in this context. Sections 1 and 2 of the Computer Misuse Act 1990, section 170 of the Data Protection Act 2018, the GDPR and the Protection from Harassment Act 1997 did not create an additional civil claim on the pleaded facts. The claim for procuring breach of contract failed because the IT provider had not breached its agreement by unlocking accounts belonging to the business.
  6. Disposition. The claim was dismissed. It was unnecessary to try the iniquity defence or assess damages.

The court’s approach to earlier authorities

This feature is available to zoomLaw Pro members.

Appeal to higher court

Outcome of appeal
appeal dismissed unanimously

Key cases cited

This feature is available to zoomLaw Pro members.

Cases citing this case

This feature is available to zoomLaw Pro members.