GRAEME SMITH & OTHERS v TALKTALK TELECOM GROUP PLC

[2022] EWHC 1311 (QB)

Case details

Case citations
[2022] EWHC 1311 (QB) · [2022] 1 WLR 5213 · [2022] WLR(D) 285
Court
High Court (Queen's Bench Division)
Judgment date
27 May 2022
Judgment text

This feature is available to zoomLaw Pro members.

Subjects
Tort Data protection Misuse of private information
Keywords
misuse of private information data breaches data security failure to protect personal data criminal hacking joint tortfeasors pleading by inference strike out summary judgment Data Protection Act 1998
Outcome
claim dismissed in part; strike-out application dismissed in part
Judicial consideration

This feature is available to zoomLaw Pro members.

Summary

A claim for misuse of private information requires conduct by the defendant which itself amounts to a misuse of the information. A failure to secure data, or conduct which merely enables criminals to obtain and misuse it, does not satisfy that requirement, even where the conduct is described as knowing or reckless. The distinction between acts and omissions is not decisive; the court must examine the substance and practical reality of the alleged conduct.

A data-protection claim may nevertheless proceed on a properly pleaded inferential case where the claimant cannot know which security incident affected the data and that information lies principally with the defendant.

Factual background

The claimants brought claims under the Data Protection Act 1998 and in misuse of private information arising from alleged 2014 and 2015 breaches of TalkTalk’s systems. They also advanced a claim concerning alleged breaches which had not been publicly confirmed.

The defendant applied to strike out the misuse of private information claim and the unconfirmed-breaches claim, sought summary judgment on the former, and opposed amendments. The central issues were whether the pleaded system failures and alleged facilitation of criminal access could constitute misuse by TalkTalk, and whether the unconfirmed-breaches claim was sufficiently pleaded.

Held

  1. Misuse of private information. The claimants’ reformulated case remained substantially a complaint that TalkTalk had failed to protect information, or had created vulnerabilities which criminals exploited. The court rejected the view that the acts-or-omissions distinction controlled the analysis. The question was whether the defendant’s own conduct was a misuse of the information.
  2. Applying Warren v DSG Retail Ltd, the court held that system-design failures, inadequate security measures, publication of vulnerable webpages, and failure to prevent or report access did not themselves constitute misuse. The misuse which caused the alleged loss and distress was the subsequent obtaining and use of the information by criminals. Describing the defendant’s conduct as knowing, reckless, or enabling did not alter that conclusion.
  3. The court accepted that a person with actual knowledge of unlawful access might, on an appropriate pleading, be a joint tortfeasor where a common design with the criminal actors could be established. No such tenable case was pleaded. The actual-knowledge allegations were also fanciful and contradicted by other parts of the pleading.
  4. Effect of Swinney v Chief Constable of Northumbria Police Force. That decision concerned a possible duty of care and a parallel breach-of-confidence claim arising from a special relationship. It did not establish that the defendant had misused information for the purposes of the modern misuse-of-private-information tort.
  5. The misuse-of-private-information claim was struck out and permission to amend it was refused.
  6. Unconfirmed breaches. The claimants’ inference that scammers who possessed TalkTalk customer information had obtained it through an unauthorised access to TalkTalk’s systems was permissible at the pleading stage. The pleading identified, albeit imperfectly, the legislation, alleged data breach, data-protection principles, and remedy. The claim should not be struck out merely because the claimants could not identify the precise breach before disclosure, particularly where the relevant technical information was principally held by TalkTalk.
  7. The unconfirmed-breaches claim required clearer pleading. The strike-out application concerning it was dismissed, and the claimants were directed to prepare an amended pleading. The application for further information remained outstanding.

The court’s approach to earlier authorities

This feature is available to zoomLaw Pro members.

Appellate history

First-instance decision. No prior appellate decision is stated in the judgment.

Key cases cited

This feature is available to zoomLaw Pro members.

Cases citing this case

This feature is available to zoomLaw Pro members.