At the Supreme Court, Morrisons pops data breach liability win into its trolley – but it's not a get-out-of-compo free card for businesses
- Reference: 1585745714
- News link: https://www.theregister.co.uk/2020/04/01/morrisons_wins_data_breach_vicarious_liability_supreme_court/
- Source link:
Grudge-bearing auditor
The case was brought over the actions of Andrew Skelton, a Morrisons auditor, who in 2014 was supposed to be transferring payroll data via encrypted USB stick to KPMG. Holding a grudge after being disciplined for abusing company postage to run his side hustle (a protein powder mail-order biz), Skelton made a separate copy of 99,998 employees' payroll information, dumped it online using Tor to cover his tracks and posted CDs of it to three newspapers.
He timed the breach to coincide with Morrisons' annual results in the hope of damaging its public image. The Bradford Telegraph and Argus refused to publish any news based on the CD's contents, instead informing Morrisons of the breach. For his actions, Skelton was handed an eight-year prison sentence in 2015.
Supreme Court [1]judge Lord Reed ruled : "First, the disclosure of the data on the internet did not form part of Skelton's functions or field of activities," also decreeing that previous findings by the High Court and Court of Appeal were mistaken in law. Whether Skelton had been "acting on his employer's business or for purely personal reasons" was a "highly material" question, remarked the judge, contrasting this with [2]how the Court of Appeal had framed it . Lord Reed's view was:
In a case concerned with vicarious liability arising out of a relationship of employment, the court generally has to decide whether the wrongful conduct was so closely connected with acts the employee was authorised to do that, for the purposes of the liability of his employer, it may fairly and properly be regarded as done by the employee while acting in the ordinary course of his employment.
He duly found that Skelton going off on a tangent of his own to leak the data was not closely connected enough to his job for vicarious liability to be established.
Morrisons off the hook
"Skelton's wrongful conduct was not so closely connected with acts which he was authorised to do that, for the purposes of Morrisons' liability to third parties, it can fairly and properly be regarded as done by him while acting in the ordinary course of his employment," said Lord Reed in a judgment handed down this morning.
While it sets the law on vicarious liability – the legal principle that employers can be held responsible for the actions of employees who commit crimes while on duty – the full judgment will be cold comfort for the 9,000+ Morrisons employees who had their personal details published online and joined the group litigation against the supermarket.
Thanks to this ruling, it is now a clear legal principle that companies can be held vicariously liable for employees' actions that result in a data breach. Nick McAleenan, lead solicitor for the employees, commented: "For the first time, the Supreme Court has established the legal principle that employers can now be legally responsible for data breaches caused by their employees – under the law of vicarious liability."
Lord Reed ruled:
The imposition of a statutory liability upon a data controller is not inconsistent with the imposition of a common law vicarious liability upon his employer, either for the breach of duties imposed by the DPA, or for breaches of duties arising under the common law or in equity.
Unfortunately for the Morrisons workers, the rogue employee in this case had gone too far rogue for the supermarket to be held liable and to pay compensation – a ruling with which Lords Reed, Kerr, Hodge and Lloyd-Jones, along with court president Lady Hale, unanimously agreed.
We can't get a payout for having our data exposed
Lawyers rushed out to comment on the judgment. McAleenan grieved over the main thrust of today's judgment, saying: "My clients entrusted their personal information to their employer, Morrisons, in good faith. When their information was subsequently uploaded to the internet by a fellow employee, it caused an enormous amount of upset and distress to tens of thousands of people. The Supreme Court's decision now places my clients, the backbone of Morrisons' business, in the position of having no legal avenue remaining to challenge what happened to them."
In contrast, Matthew Gill of law firm Wiggin LLP opined: "If the court's decision had gone the other way, Morrisons would have been liable to 100,000 of its employees for a breach of their data despite Morrisons having done everything it reasonably could have to protect that data. Other employers would have faced an untenable risk that if they were hit by a similar theft of data by an employee, they would be left wholly exposed."
The judgment seems likely to please the Information Commissioner's Office, which we revealed [3]had quietly urged the Court of Appeal to dismiss the case last year without even bothering to look at the employees' legal arguments against Morrisons. ®
Bootnote
Our previous coverage of the High Court's judgment is [4]here .
The Court of Appeal case coverage is to be found [5]here and [6]here .
Reports of legal arguments before the Supreme Court are to be found [7]here and [8]here .
[1] https://www.supremecourt.uk/cases/uksc-2018-0213.html
[2] https://www.theregister.co.uk/2018/10/23/morrisons_loses_court_appeal_data_theft/
[3] https://www.theregister.co.uk/2019/11/13/ico_told_court_appeal_side_with_morrisons_data_breach/
[4] https://www.theregister.co.uk/2017/12/01/morrisons_data_leak_ruling/
[5] https://www.theregister.co.uk/2018/10/23/morrisons_loses_court_appeal_data_theft/
[6] https://www.theregister.co.uk/2018/10/09/morrisons_data_breach_appeal/
[7] https://www.theregister.co.uk/2019/11/07/morrisons_supreme_court_payroll_data_appeal/
[8] https://www.theregister.co.uk/2019/11/08/morrisons_supreme_court_data_breach_payroll_arguments/
Re: One thing I'm confused about
Internal auditor?
Error or malicious act
Organisations need people to do things. Some of these things can be delicate. The best that an organisation can do is to train people so that they know what they must & must not do and to make it technically hard for them to do the wrong thing.
But there are limits on what can be done to stop an insider, who needs access to sensitive data to do his job, from abusing the trust that they have been given.
This is cold comfort to those who's data was spaffed around the place, but they are victims of Sketon not Morrisons. It is right that Skelton is now eating porridge.
Re: Error or malicious act
I agree to a point. But those "limits" can very much be reduced to small percentages. Stating that Morrisons did "everything" they could to prevent data loss is not entirely consistent with allowing him to manually transfer the entire HR data extract onto a USB stick for delivery to KPMG.
Assume Morrisons IT and OpSec teams haven't heard about secure encrypted file transfer or DLP solutions yet?
"...having done everything it reasonably could have to protect that data."
How about not letting a single person have the capability to access 100,000 peoples personal information? Implement a two-person rule when dealing with masses of data? That sure seems reasonable to me, and is in fact the rule where I used to work at HMRC. Access was via an airgapped network, two people in the room at all times, one watching and one typing the necessary commands.
Auditor
..but he was an Auditor.
Maybe he needed access for his job... like... you know... to Audit how staff data was being managed.?
"So what the hell do they keep behind that big metal door that needs securing with X-Ray screens, retina scanners and a pair of armed guards with sniffer dogs?
"Oh, that's just HR..."
At Last
The Supreme Court doing law, not politics, makes a change!
Re: At Last
Can't believe they got it righ for once
Re: At Last
> also decreeing that previous findings by the High Court and Court of Appeal were mistaken in law.
Third time's the charm. Why does the legal system find it so hard to get it right first time? In any other line of work you'd be sued for such incompetence.
Re: At Last
The supreme court often gets things right because they are proper judges.
Exaggerate much?
My clients entrusted their personal information to their employer, Morrisons, in good faith. When their information was subsequently uploaded to the internet by a fellow employee, it caused an enormous amount of upset and distress to tens of thousands of people .
Sure it's not a nice thing to happen, but I suspect most of the victims didn't suffer enormously . Mostly this lawyer's clients saw an opportunity for some compo, or the lawyers did and then went ambulance-chasing, and cranked up the feigned concern
Chances are many of them are frequently splashing vast amounts of private info all over the internet, without being remotely bothered about it.
Legal avenues
The Supreme Court's decision now places my clients, the backbone of Morrisons' business, in the position of having no legal avenue remaining to challenge what happened to them.
Yep, because the SC has decided they sueing the wrong entity.
They are still free to sue the areshole who actually did the leaking, and would probably win given he's already banged up for it. Phyrric victory though. Somehow doubt he has the funds to settle ~100k of claims.
I blame the lawyers, chasing the deeper pockets and trying to convince the victims Morrison's would be liable for the grossly rogue actions of an employee. Hope this was no-win no-fee.
One thing I'm confused about
If he was an auditor, then wouldn't he be working for KPMG rather than Morrisons?
Or if he was transferring the data from Morrisons to KPMG in order for it to be audited, then wouldn't he be someone in the Morrisons payroll department?