Insights

Protecting your business from GDPR data breaches by employees

19.04.2018

4 minute read

Authored by

Francesca Wild

Senior Associate Solicitor

Message

Share

LinkedIn icon

Our Employment team discuss a recent case where Morrisons Supermarkets were held liable for a breach of data by an employee. Joanne discusses the steps employers should be aware of when preparing for GDPR.

Following a recent case in which a supermarket was held liable for a data breach by a rogue employee, employers preparing for GDPR will wish to be aware of steps they should be taking to minimise the risk of liability for actions by their employees.

The facts of this case are that, following what the employee considered to be an unfair disciplinary warning by his employer, Morrisons Supermarkets, he deliberately released the payroll details of around 94,480 employees onto the internet.  The employee was duly convicted of offences under the Computer Misuse Act 1990 and the Data Protection Act 1998.

Around 5,000 of his colleagues brought a group claim against Morrisons in various grounds including breach of the Data Protection Act 1998.
The High Court held the supermarket was not itself directly liable because the employee was the data controller at the time of the breach.

It was the employee who decided how the data he had copied was to be handled and not his employer. Neither could it be argued that he was acting as an agent of the supermarket. On this basis, many employers would be very likely to escape any responsibility for the actions of rogue employees.

Unfortunately for Morrisons, and no doubt on public policy grounds, the High Court decided that it was vicariously liable for the employee’s actions. Even though the disclosure took place outside working hours and from the employee’s personal computer there was a close connection with his employment.  The employee was acting as an employee when he received the data. His unauthorised disclosure was close to what he had been authorised to do i.e. to receive and store the financial data and then disclose it to a third party.

This decision leaves employers who do all they reasonably can to comply with the Data Protection Act (and from 25 May 2018, GDPR), at risk from actions by rogue employees. Leave to appeal on this point has been granted to the supermarket.

So, what steps should businesses take to minimise the risk of their employees breaching GDPR requirements?

  • Ensure employees read and comply with your Data Protection Policy and you have evidence they have done so
  • Minimise the risk of inadvertent disclosure by having an effective Data Retention Policy for the retention and deletion of personal data
  • Implement regular data protection training, including specialised training for particular jobs and record when employees have completed the training
  • Issue regular bulletins on data protection issues to all staff
  • Amend your disciplinary procedure so that employees are aware serious breach of your data protection policy can lead to dismissal.

How can Morr & Co help?

If you have any questions or would like any further information on the content of this article, please do not hesitate to contact our Employment team on 01737 854500 or email info@morrlaw.com and a member of our expert team will get back to you.

Disclaimer
Although correct at the time of publication, the contents of this newsletter/blog are intended for general information purposes only and shall not be deemed to be, or constitute, legal advice. We cannot accept responsibility for any loss as a result of acts or omissions taken in respect of this article. Please contact us for the latest legal position.

Stay informed

Receive regular insights and updates from our legal experts.

Get in touch

Please fill out the form below and one of our team will get back to you as soon as we can.

Please choose from the below options so that we can direct your enquiry to the right team member

Sorry, we do not provide criminal law advice.

You may wish to contact your local Citizens Advice Bureau or your local Law Centre, who will be able to help you find support.

Sorry, we do not provide advice on consumer disputes.

You may wish to contact your local Citizens Advice Bureau or your local Law Centre, who will be able to help you find support.

Sorry, we do not provide advice on benefits related disputes.

You may wish to contact your local Citizens Advice Bureau or your local Law Centre, who will be able to help you find support.


Please note that we are currently only providing this service to our existing clients.

You should bear in mind that if your dispute is valued at less than £10,000 you will not be able to recover your legal fees from your opponent.

You may wish to consider consulting the Citizens Advice Bureau or your local Law Centre as an alternative.

In order to enable us to give you an accurate estimate of our likely costs to advise you, we will need to review the key documents. As a guide, our costs for reviewing the key documents and giving you initial advice are likely to be in the region of £1,750+VAT.

Before we can confirm whether we are able to act for you, we need to carry out a conflict check to make sure that we have not previously acted for your opponent.

Assuming our conflict check is clear, we will contact you to arrange a time for you to speak to one of our solicitors. Please can you confirm that you still wish to proceed with this enquiry. *

Our fees for debt recovery work typically start at £1,750 + VAT, so it is unlikely that we would be able to help you on this occasion. You may wish to contact the Citizens Advice Bureau or your local law centre, who may be able to help resolve your issue.

We are sorry that we are not able to help you on this occasion.

You may wish to contact the Citizens Advice Bureau or your local law centre, who may be able to help resolve your issue.

If your claim relates to an incident that took place more than 4 years ago, you may not be able to bring a claim unless you were under 18 years old at the time.

We are sorry, but it is unlikely that we are able to help you with your claim on this occasion.

You may wish to contact the Citizens Advice Bureau or your local law centre, who will be able to help you find support.