Thousands of Morrisons workers due compensation after staff details breach

-

Morrisons staff are to be awarded a payout over a data breach that occurred when a disgruntled former member of its staff  stole the data of thousands of employees and posted it online.

The case is the first data leak class action in the UK.

Morrisons has been found liable for the actions of the employee by the High Court with the ruling opening the possibility for 94,000 people affected to bring a compensation claim, lawyers said.

HRreview Logo

Get our essential weekday HR news and updates.

This field is for validation purposes and should be left unchanged.
Keep up with the latest in HR...
This field is hidden when viewing the form
This field is hidden when viewing the form
Optin_date
This field is hidden when viewing the form

 

Workers brought a claim against the company after employee Andrew Skelton stole the data, which included salary and bank details, of nearly 100,000 staff.

Skelton, then a senior internal auditor at the retailer’s Bradford headquarters,  posted the payroll information in 2014, including names, addresses, bank account details and salaries, online and and sent it to newspapers.

He was jailed for eight years in July 2015 after being found guilty at Bradford Crown Court of fraud, securing unauthorised access to computer material and disclosing personal data.

His motive appeared to have been a grudge over an incident when he was accused of dealing in legal highs at work.
Lawyers said the data theft meant a group of 5,518 former and current employees were exposed to the risk of identity theft and potential financial loss and that the company was responsible for breaches of privacy, confidence and data protection laws.

A second trial will be held to determine the amount Morrisons must pay in damages.

Following the ruling, Nick McAleenan, a partner and data privacy law specialist at JMW Solicitors, who acted for the claimants, said:

“We welcome the judgment and believe that it is a landmark decision, being the first data leak class action in the UK. Every day, we entrust information about ourselves to businesses and organisations. We expect them to take responsibility when our information is not kept safe and secure.

“The consequences of this data leak were serious. It created significant worry, stress and inconvenience for my clients. Data breaches are not a trivial or inconsequential matter. They have real victims. At its heart, the law is not about protecting data or information – it is about protecting people.”

The judge ruled that vicarious liability, but not primary liability, had been established. He said:

‘I hold that the Data Protection Act (DPA) does not impose primary liability upon Morrisons; that Morrisons have not been proved to be at fault by breaking any of the data protection principles, save in one respect which was not causative of any loss; and that neither primary liability for misuse of private information nor breach of confidentiality can be established. A security breach saw payroll data of nearly 100,000 workers being put online

‘I reject, however, the arguments that the DPA upon a proper interpretation is such that no vicarious liability can be established, and that its terms are such as to exclude vicarious liability even in respect of actions for misuse of private information or breach of confidentiality.’ He added: ‘The point which most troubled me in reaching these conclusions was the submission that the wrongful acts of Skelton were deliberately aimed at the party whom the claimants seek to hold responsible, such that to reach the conclusion I have may seem to render the court an accessory in furthering his criminal aims.

‘I grant leave to Morrisons to appeal my conclusion as to vicarious liability, should they wish to do so, so that a higher court may consider it, but would not, without further persuasion, grant permission to cross-appeal my conclusions as to primary liability.’

‘Every day, we entrust information about ourselves to businesses and organisations. We expect them to take responsibility when our information is not kept safe and secure. ‘In the Morrisons case, almost 100,000 bank account details, National Insurance numbers and other data was entrusted to a fellow employee to look after. Instead, however, he uploaded the information to the internet. ‘This private information belonged to my clients. They are Morrisons checkout staff, shelf stackers, factory workers – ordinary people doing their jobs. ‘The consequences of this data leak were serious. It created significant worry, stress and inconvenience for my clients.’

Morrisons has been granted leave to appeal against the decision.

Rebecca joined the HRreview editorial team in January 2016. After graduating from the University of Sheffield Hallam in 2013 with a BA in English Literature, Rebecca has spent five years working in print and online journalism in Manchester and London. In the past she has been part of the editorial teams at Sleeper and Dezeen and has founded her own arts collective.

Latest news

Transgender staff excluded from single-sex toilets under new equality guidance

Transgender people must be excluded from single-sex toilets and changing rooms that correspond with their lived gender under updated...

Simon Coker: Closing the emotional gap – why AI in the workplace is as much a human challenge as a technological one

AI adoption is transforming how work gets done across every sector. But its deeper impact is less visible: it is reshaping how people feel about their work.

Employment tribunal delays stretch towards 2030 as lawyers warn system is nearing collapse

Employment tribunal hearings are being delayed for years as lawyers warn mounting backlogs are undermining workplace justice.

Keeping culture and purpose at the centre of a growing fintech

A fintech people leader explains how culture, wellbeing and purpose are being protected during rapid business growth.
- Advertisement -

Migrant worker with no right to work in UK wins discrimination case against employer

An employment tribunal has ruled that a migrant worker without the legal right to work in Britain can still pursue successful discrimination claims.

Government to replace some GP sick notes with return-to-work plans

Workers in four English regions will be directed towards personalised health and employment support as ministers test alternatives to GP-issued fit notes.

Must read

John O’Reilly: Why wellbeing programmes should address sleep

The fast-changing world of work and its constant demands ion employers and employees means that our grasp of workplace well-being can never stand still and sleep is becoming a big issue. So how can we address this?

Ian Butterworth: What is the most important thing people look for in a new job?

Candidates may be swayed by salary, but there are a variety of other factors they look for when considering a new role.
- Advertisement -

You might also likeRELATED
Recommended to you