Thousands of Morrisons workers due compensation after staff details breach

-

Morrisons staff are to be awarded a payout over a data breach that occurred when a disgruntled former member of its staff  stole the data of thousands of employees and posted it online.

The case is the first data leak class action in the UK.

Morrisons has been found liable for the actions of the employee by the High Court with the ruling opening the possibility for 94,000 people affected to bring a compensation claim, lawyers said.

HRreview Logo

Get our essential weekday HR news and updates.

This field is for validation purposes and should be left unchanged.
Keep up with the latest in HR...
This field is hidden when viewing the form
This field is hidden when viewing the form
Optin_date
This field is hidden when viewing the form

 

Workers brought a claim against the company after employee Andrew Skelton stole the data, which included salary and bank details, of nearly 100,000 staff.

Skelton, then a senior internal auditor at the retailer’s Bradford headquarters,  posted the payroll information in 2014, including names, addresses, bank account details and salaries, online and and sent it to newspapers.

He was jailed for eight years in July 2015 after being found guilty at Bradford Crown Court of fraud, securing unauthorised access to computer material and disclosing personal data.

His motive appeared to have been a grudge over an incident when he was accused of dealing in legal highs at work.
Lawyers said the data theft meant a group of 5,518 former and current employees were exposed to the risk of identity theft and potential financial loss and that the company was responsible for breaches of privacy, confidence and data protection laws.

A second trial will be held to determine the amount Morrisons must pay in damages.

Following the ruling, Nick McAleenan, a partner and data privacy law specialist at JMW Solicitors, who acted for the claimants, said:

“We welcome the judgment and believe that it is a landmark decision, being the first data leak class action in the UK. Every day, we entrust information about ourselves to businesses and organisations. We expect them to take responsibility when our information is not kept safe and secure.

“The consequences of this data leak were serious. It created significant worry, stress and inconvenience for my clients. Data breaches are not a trivial or inconsequential matter. They have real victims. At its heart, the law is not about protecting data or information – it is about protecting people.”

The judge ruled that vicarious liability, but not primary liability, had been established. He said:

‘I hold that the Data Protection Act (DPA) does not impose primary liability upon Morrisons; that Morrisons have not been proved to be at fault by breaking any of the data protection principles, save in one respect which was not causative of any loss; and that neither primary liability for misuse of private information nor breach of confidentiality can be established. A security breach saw payroll data of nearly 100,000 workers being put online

‘I reject, however, the arguments that the DPA upon a proper interpretation is such that no vicarious liability can be established, and that its terms are such as to exclude vicarious liability even in respect of actions for misuse of private information or breach of confidentiality.’ He added: ‘The point which most troubled me in reaching these conclusions was the submission that the wrongful acts of Skelton were deliberately aimed at the party whom the claimants seek to hold responsible, such that to reach the conclusion I have may seem to render the court an accessory in furthering his criminal aims.

‘I grant leave to Morrisons to appeal my conclusion as to vicarious liability, should they wish to do so, so that a higher court may consider it, but would not, without further persuasion, grant permission to cross-appeal my conclusions as to primary liability.’

‘Every day, we entrust information about ourselves to businesses and organisations. We expect them to take responsibility when our information is not kept safe and secure. ‘In the Morrisons case, almost 100,000 bank account details, National Insurance numbers and other data was entrusted to a fellow employee to look after. Instead, however, he uploaded the information to the internet. ‘This private information belonged to my clients. They are Morrisons checkout staff, shelf stackers, factory workers – ordinary people doing their jobs. ‘The consequences of this data leak were serious. It created significant worry, stress and inconvenience for my clients.’

Morrisons has been granted leave to appeal against the decision.

Rebecca joined the HRreview editorial team in January 2016. After graduating from the University of Sheffield Hallam in 2013 with a BA in English Literature, Rebecca has spent five years working in print and online journalism in Manchester and London. In the past she has been part of the editorial teams at Sleeper and Dezeen and has founded her own arts collective.

Latest news

Exclusive: London bus drivers’ ‘dignity’ at risk as strikes loom over welfare concerns

London bus drivers raise concerns over fatigue and lack of facilities as potential strikes escalate long-standing welfare issues.

Whistleblowing reports ‘surge by up to 250 percent’ at councils as new rights take effect

Whistleblowing cases are rising across UK councils as stronger workplace protections come into force, though concerns remain about underreporting of serious issues.

Bullying and harassment to become regulatory breaches under new FCA rules

New rules will bring bullying and harassment into regulatory scope, as firms face rising reports of workplace misconduct.

Personalising the Benefits Experience: Why Employees Need More Than Just Information

This article explores how organisations can move beyond passive, one-size-fits-all communication to deliver relevant, timely, and simplified benefits experiences that reflect employee needs and life stages.
- Advertisement -

Grant Wyatt: When the love dies – when staying is riskier than quitting

When people fall out of love with their employer, or feel their employer has fallen out of love with them, what follows is rarely a clean exit.

£30bn pension savings window opens for employers ahead of 2029 reforms

UK employers could unlock billions in National Insurance savings by expanding pension salary sacrifice schemes before new limits take effect in 2029.

Must read

Tina Wisener: Netflix premieres 12 months paid parental leave for all, but can UK employers pick and choose who gets it?

Netflix has announced that its employees can take as much time off as they wish during the first year after their child’s birth or adoption and still be paid in full.

Nicola Jagielski: How can employers address parental burnout?

Research claims that one in 12 parents are suffering burnout. Burnout is more commonly associated with work—but the stigma around the difficulty of raising children is lifting. Nicola Jagielski provides advice on how employers can help.
- Advertisement -

You might also likeRELATED
Recommended to you