https://www.bailii.org/ew/cases/EWHC/KB/2023/1668.html
Summary: This case regards a claim in the High Court for the misuse of private information and breach of rights under the General Data Protection Regulation (“GDPR”), both of which succeeded and led to an award of £6000 in damages. Mr Yao Bekoe, the claimant, lived in the London Borough of Islington (“LBI”) and had his private information accessed and shared (without proper authorisation) with the County Court as part of proceedings related to LBI’s acquisition of his neighbour’s property. LBI also breached his GDPR rights in failing to respond to a Data Subject Access Request (“DSAR”) effectively, failing to disclose further information and destroying/losing his personal data relating to ongoing proceedings.
The relevance of this case for adult social care services lies in the implication that HAD there been a proper justification under s42 safeguarding functions, internal sharing might not have been unlawful.
Background
The Deputy High Court Judge, Alegre J, noted the complex factual background of the case and summarised its most essential points. Since 1962, Mr Bekoe lived in and owned property in LBI. The Mayor and Burgesses of LBI (the defendant) made a claim in 2015 and 2016 (“the Possession Claim”) for property (“the Property”) belonging to Mrs Sobesto (now deceased), Mr Bekoe’s elderly neighbour.
In 2014 and 2015, as part of deputyship proceedings (“the Court of Protection Proceedings”), LBI was appointed as Deputy to Mrs Sobesto who was taken into a care home in 2013 as her health declined. Mr Bekoe challenged the deputyship proceedings unsuccessfully and said that before them, he had an informal arrangement with Mrs Sobesto whereby he managed, helped maintain and let out flats in the Property on her behalf, using the income to help pay for her care.
Mr Bekoe made three main claims:
- The defendant misused private and confidential information relating to his finances by accessing it without legal basis and sharing it with the County Court during its Possession Claim.
- The defendant breached a DSAR starting on 18 June 2019, which it admitted to doing.
- The defendant delayed responding to the DSAR and further infringed his rights under the GDPR, including failing to disclose further data and destroying his personal data related to ongoing proceedings.
Alegre J went on to note the chronology of events relating to the first claim: misuse of private information. LBI applied for deputyship for Mrs Sobesto in 2014 but Mr Bekoe did not learn about the deputyship until after its grant, after being informed by a recently-housed tenant in the property of a letter from LBI. Later that year, LBI reported suspicions of fraud perpetrated by Mr Bekoe to the police. The police later reported that there was no evidence of criminality and stopped pursuing the matter.
Against the background of the Possession Claim, which started in Spring 2015, LBI inquired about Mr Bekoe’s financial affairs in July 2015 and acquired private information relating to them. This act, and how LBI would later handle his information, formed the subject of his claim. Internal communications within LBI detailed how there was supposedly evidence of fraud by Mr Bekoe and that LBI needed to acquire his financial information. A Legal Officer at LBI, Ms Wentworth, acquired Mr Bekoe’s account numbers through a Local Government Officer also at LBI, which information was then put before the County Court on an application for disclosure. Mr Bekoe was ordered in August 2015 to give specific disclosure to LBI about the seven bank and building society accounts identified in LBI’s investigation. Ms Wentworth then contacted the same Local Government Officer to acquire branch details. As with the account numbers, the information was put to the Court and specific orders for disclosure were made against the seven identified banks and building societies.
Alegre J then turned to the GDPR claim. The effective date from which the timing related to the GDPR claim started to run was when LBI acknowledged receipt of the DSAR from Mr Bekoe, in May 2019. Ms Wentworth left LBI in December 2020 and the legal file about the Possession Claim was destroyed around that time. An exchange of witness statements dated August 2022 saw LBI reveal important information, including internal emails relating to the DSAR of June 2019, which referred to and discussed the possibility of a Mr Knightley having undertaken “an Equifax search in respect of Mr Bekoe”, and an account of November 2019 by Ms Wentworth of the content of her legal file and the likelihood of other departments involved having “disclosable records”.
Discussion
Alegre J reproduced the relevant law and guidance on evidence and inferences, the misuse of private information, and the GDPR, which included the following: the general rule concerning the evidence of witnesses as set out at CPR r.32.2; the commentary on the rule in the White Book 2023; Calver J’s summary of the relevant principles’ application (Active Media Services Inc); a leading case on the misuse of private information (ZXC); Article 8 of the ECHR; s.42 of the Care Act 2014 as well as relevant paragraphs, articles, parts and sections of the GDPR and Data Protection Act (“DPA”) 2018. Alegre J then moved on to her judgment about the misuse of private information, adverse inferences and the GDPR before dealing with the quantum of damages.
Alegre J cited the abundance of authority suggesting that financial information can be categorised as “private information” for the purpose of the tort of misuse of private information (Gulati; The Law of Privacy and the Media). There is therefore a reasonable expectation that it should be kept private and that “[a] reasonable person with ordinary sensibilities placed in the same position as [Mr Bekoe] would expect that a comprehensive snapshot of their general financial information would be kept private”. The cross-examination revealed the scale of his information’s misuse, and the fact that one of the accessed accounts also related to Mr Bekoe’s son demonstrated the disproportionate nature of LBI’s access to Mr Bekoe’s information, extending far beyond the information relevant to the letting of the Property. This was also the reason for the failure of the argument that Mr Bekoe could not have a reasonable expectation of his information being private.
LBI failed to show that it was justified in accessing and sharing Mr Bekoe’s private information within its own communication channels and with the County Court in the Possession Claim. No evidence was adduced to support LBI’s claim that this was done to protect Mrs Sobesto under s.42 of the Care Act, nor was evidence adduced to show that LBI’s contact with the police went beyond reporting Mr Bekoe. LBI did not show how it would have pursued an enquiry under s.42 and what it actually did. No evidence was brought in to make up for the fact that many of LBI’s officers involved with Mr Bekoe had left the Council. For the same reason LBI could not rely on the Care Act, it could also not rely on Article 8 of the ECHR as it failed to show its interference with Mr Bekoe’s right was in accordance with the law.
Having dealt with liability for the misuse of private information, Alegre J turned to the claim under the GDPR. LBI failed to effectively respond to Mr Bekoe’s DSAR from 19 June 2019 until at least 8 June 2023, representing a delay of almost four years. Alegre J thought it was likely that there were or are further personal data belonging to Mr Bekoe that had not been disclosed by LBI. Leila Ridley, the Head of Information Governance and DPO within the Resources Department of LBI, confirmed that certain types of documents containing personal data would have been created by LBI in reporting Mr Bekoe and contacting his credit reference company. These documents should have been disclosed as per the GDPR. There was no evidence to document what happened to Mr Bekoe’s legal file, which had either been destroyed or lost.
As for remedies, Alegre J noted how the award of damages for the tort of misuse of private information is wider than under the GDPR. Compensation can take into consideration the loss or diminution of the right to control the use of one’s private information (Gulati; Lloyd). The fact that Mr Bekoe’s claim was brought under the heads of both misuse of private information and breach of GDPR, and that there was significant overlap in terms of the impact of both aspects of the claim on him, led Alegre J to consider damages for both claims together as a single figure. Alegre J also found it appropriate to award aggravated damages, which are higher than normal, which was triggered by the way that the trial and the litigation as a whole were conducted by LBI, revealing a lack of respect for legal requirements related to privacy and data protection.
Judgment
As to the misuse of private information, LBI’s comprehensive acquisition of Mr Bekoe’s private information compromised both his and his son’s financial affairs. The absence of witnesses from LBI demonstrated that there was no evidence to support the defence of enquiring under s.42 of the Care Act 2014, which also led to the rejection of the defence under Article 8 of the ECHR. For these reasons, Alegre J held that LBI misused Mr Bekoe’s private information in July 2015 by accessing details relating to a collection of bank accounts and mortgage accounts associated with him (and others) without lawful authority.
LBI breached the GDPR in several ways: firstly, it failed effectively to respond to Mr Bekoe’s DSAR for almost four years; secondly, given the likelihood of LBI having further personal data belonging to Mr Bekoe, this information had not been disclosed; thirdly, the loss or destruction of Mr Bekoe’s legal file represented a clear failure to provide adequate security for his personal data. In light of this, Alegre J held that LBI breached Mr Bekoe’s GDPR rights under Articles 5, 12 and 15, which were its duties to lawfully process personal data, provide a data subject with transparent information, communication and modalities, and uphold a data subject’s right of access.
In relation to remedies, Alegre J concluded that the breach of the DPA 1998 crossed the “threshold of seriousness” (Lloyd). In consideration of the misuse of private information, the loss of the right to control the information and the level of distress caused by the GDPR breaches along with the aggravating factors, Alegre J gave an award of £6000 in damages.
Comment
The case demonstrates the importance of councils dealing with their residents’ private information responsibly and in accordance with tort law, the GDPR, the Care Act 2014, ECHR and DPA 1998. It is a good example of a systematic application of the relevant legal tests and principles to hold a local authority accountable, especially in light of the distress experienced by the claimant.
The case reveals several useful points about the tort of misuse of information. There is the uncontentious point that financial information can be classified as private information, leading judges readily to onclude that there is a reasonable expectation for claimants to want their general financial information to be kept private.
LBI’s treatment of Mr Bekoe’s private information was indefensible but LBI was also completely unable to provide any compelling reason as to why it had thought it was entitled to take such steps in the context of an enquiry under s.42 of the Care Act 2014.
If a council is unable to justify its interference with their private information under s.42, data subjects will not have to go through the arduous process of satisfying a separate set of legal requirements to make out a breach of Article 8 of the ECHR. Failure to justify enquiry under s.42, means that defendants will not have acted in accordance with the law, which is a requirement for justification under Article 8.
As for the GDPR, potential litigators should be aware of the fact that cases can still be subject to the old GDPR, which was amended on 31 December 2020 to become the “UK GDPR”, if the relevant chronology of events falls before the GDPR’s amendment. Even so, the English data protection framework has not yet undergone a fundamental change since at least the DPA 1998. The case underlines that an excessively delayed response to a DSAR (such as almost four years) is a clear violation of the GDPR. Ms Ridley, a witness for LBI, made the very interesting point that since councils usually create certain types of documents containing personal data when reporting a constituent to the police and contacting their credit reference company, they must be prepared to produce such documents as per the GDPR. It follows that a council’s failure to locate important stored personal information due to it being destroyed/lost can provide a judge with ample reason to view it as likely to have breached the GDPR for failing to secure personal data.
A few valuable points can also be made about the determination of remedies. The larger portion of the £6000 award may be rooted in a misuse of private information claim. Since the GDPR breach was relatively minor, damages for breach would be narrower. Due to the overlaps between both claims’ impact on claimants (such as in terms of distress), judges can consider the award for both as a single figure. However, aggravated (i.e. greater than normal) damages were awarded for the misuse of private information claim, the judge commenting on the council’s lax conduct throughout the trial and litigation process overall.
