Case details
Summary
The purely personal or household activity exception does not apply where an individual shares personal data collected and held by a company in connection with a business relationship, even if the sharing also seeks personal support or advice. A company director who processes data as an agent for the company is not, merely by determining the purposes and means of processing, a separate controller.
Article 15(1)(c) UK GDPR gives a data subject the right to the specific identities of recipients where disclosure is possible and not manifestly excessive. That right remains subject to the rights of others exemption in paragraph 16 of Schedule 2 to the Data Protection Act 2018. The controller is the primary decision-maker and has a wide margin of discretion when balancing the competing interests.
Factual background
The claimant sought orders requiring Mr Cameron and Alasdair Cameron Ltd to comply with subject access requests made under article 15 UK GDPR. The requests concerned recordings of threatening telephone conversations between the claimant and Mr Cameron, and sought the identities of persons to whom the recordings or transcripts had been disclosed.
The issues were whether Mr Cameron’s disclosures to family and friends were outside the UK GDPR as purely personal or household activity; whether he was a controller in his personal capacity; whether article 15(1)(c) required disclosure of recipients’ specific identities; and whether disclosure could be withheld under article 15(4) and paragraph 16 of Schedule 2 to the Data Protection Act 2018.
Held
- Mr Cameron’s processing. The recording of the calls was undertaken at least partly for business reasons and in his capacity as a director of ACL. The recordings were personal data collected and held by ACL. Sharing them with family and friends therefore concerned business data and was not a “purely personal or household activity” under article 2(2)(a) UK GDPR. The claim against Mr Cameron nevertheless failed because he was not a controller.
- Controller status. Applying Ittihadieh v 5-11 Cheyne Gardens RTM Company Ltd and In re Southern Pacific Personal Loans Ltd, a director processing personal data as an agent for the company is not himself a controller. The relevant controller was ACL, which determined the purposes and means of processing. A rogue employee or director may become a controller when acting on their own behalf, but that was not the position on the facts.
- Article 15(1)(c). The court adopted the interpretation in RW v Österreichische Post AG: where data have been disclosed, article 15(1)(c) ordinarily requires the controller to provide the actual identities of recipients, rather than merely their categories, unless identification is impossible or the request is manifestly unfounded or excessive. The provision includes employees and other recipients processing data under the controller’s authority.
- Rights of others exemption. Paragraph 16 of Schedule 2 requires a balance between the requester’s interests and the privacy interests of identifiable other individuals. The controller is the primary decision-maker and has a wide margin of discretion. Relevant considerations included the nature of the information, the absence of consent, the recipients’ reasonable concerns about intimidation and hostile correspondence, the claimant’s conduct, and the limited purpose of the SAR regime. ACL reasonably concluded that disclosure was inappropriate, and the exemption applied.
- The claim against Mr Cameron was dismissed because he was not a controller. The claim against ACL was dismissed because the rights of others exemption applied.
The court’s approach to earlier authorities
This feature is available to zoomLaw Pro members.
Key cases cited
This feature is available to zoomLaw Pro members.
Cases citing this case
This feature is available to zoomLaw Pro members.