The Court of Appeal has dismissed an appeal concerning a complaint to the Data Protection Commission (DPC) arising from a cyber-attack on the Health Service Executive (HSE), finding that the original complaint related only to the appellant’s personal accounts and did not extend to work-related personal data.
Delivering judgment for the Court of Appeal, Mr Justice Meenan held that, having regard to the terms of the appellant’s original complaint to the HSE, it was clear that the complaint concerned personal accounts unrelated to his work. The court also rejected the argument that the DPC was under a duty to look beyond the complaint actually made, finding that doing so would have created a “clear breach of procedural fairness” to the HSE by requiring it to defend a complaint that had never been made.
The appellant was employed by the HSE as a fire prevention officer. In February 2020, he was provided with a HSE laptop and mobile phone for work purposes, although he also used the phone for personal matters, including email, a Fitbit account and a Binance cryptocurrency account.
In April or May 2021, the HSE was subject to a major cyber-attack which resulted in a data breach affecting more than 90,000 data subjects. Shortly afterwards, the appellant discovered that his personal email accounts accessed through the HSE mobile phone had been compromised and that cryptocurrency worth approximately €1,400 had been stolen from his Binance account.
The appellant complained to the HSE and subsequently to the DPC. The DPC dismissed the complaint, finding that the HSE could not be regarded as the controller of the appellant’s personal data stored on the HSE phone where that data had been stored without the HSE’s knowledge or agreement. The DPC confirmed its position by email on 21 June 2022.
The appellant subsequently sought judicial review of the DPC’s decision, arguing, among other matters, that his complaint concerned both work-related personal data and unauthorised non-work-related data. He also challenged the DPC’s conclusion that the HSE was not a “data controller” for the purposes of Article 4(7) of the General Data Protection Regulation (EU) 2016/679.
The High Court dismissed the application. The trial judge found that the “clear gravamen” of the appellant’s complaint was that his work device contained personal data unrelated to his employment. Having examined the correspondence between the parties, the court was satisfied that the complaint concerned the alleged compromise of the appellant’s Gmail, Yahoo, Binance and Fitbit accounts.
The High Court held that it would be “entirely oppressive” to require the DPC not only to investigate the complaint actually made but also to speculate about additional matters that might potentially warrant investigation but had not been raised by the complainant.
The court concluded that the DPC had conducted an appropriate and proportionate investigation of the complaint before it and found no evidential basis for the appellant’s allegation that his personal accounts had been compromised as a result of the HSE cyber-attack.
On appeal, the appellant argued that the High Court had erred in finding that his complaint was confined to non-work-related data and in its conclusions concerning the HSE’s status as a data controller.
The Court of Appeal noted that it was not disputed that the HSE was not a data controller in respect of non-work-related data stored on the phone, while it could be a data controller in respect of work-related personal data. The issue was therefore whether the appellant’s complaint had actually extended to the latter category.
Mr Justice Meenan examined the appellant’s original complaint to the HSE and found that its terms clearly concerned his personal accounts and repeatedly referred to “this personal data breach”. The HSE’s response further clarified the position, recording that the appellant had initially informed his line manager that the breach related to his personal Yahoo account, which he had accessed using his HSE phone. The appellant did not correct that description at the time.
The court noted that the issue of work-related personal data was only raised by the appellant in May 2022, after the DPC had communicated its decision. Mr Justice Meenan observed that, had the HSE’s understanding of the complaint been incorrect, the appellant would reasonably have been expected to correct it at the time.
The Court of Appeal also rejected the appellant’s argument that the DPC should have looked beyond the terms of his complaint. Mr Justice Meenan identified three difficulties with that proposition. First, it was for the appellant to formulate his own complaint and the DPC was not required to investigate matters that were not raised. Second, requiring the HSE to defend a complaint that had never been made would create obvious procedural unfairness. Third, the appellant had not been granted leave to pursue judicial review on that particular ground.
The court therefore found no error in the High Court’s decision and dismissed the appeal.
Click here to read the judgment.