Vicarious liability is most commonly seen in employee-employer relationships, whereby employers may be held liable for the actions or omissions of their employees during their period of employment.
In order for the act to be considered "in the course of employment", the employer must have authorised or directed the act or be sufficiently connected. However, an employer is not responsible for actions taken by an employee that are not within the scope of their employment but can extend to employer-sponsored events (conferences, training, workshops), social functions related to work (like Christmas parties) and business trips.
In April 2020, the UK Supreme Court (UKSC) unanimously overturned a 2018 Court of Appeal judgement to rule that WM Morrisons Supermarkets plc (Morrisons) was not vicariously liable for the actions of a rogue employee who leaked the personal payroll data of 98,998 co-workers.
What happened?
Morrisons gave the employee (a member of its internal audit team) access to employee payroll data so that he could provide this information to an external auditor. The data included private information such as salary, bank account details, and national insurance numbers.
After sending the information to the external auditor, the employee, who held a grudge against Morrisons due to a previous disciplinary action against him, published a file online containing the data of its employees and, on the day that Morrisons' financial results were due to be announced, sent the data to several national newspapers.
The employee took a number of steps to hide his conduct, including using a "burner phone" to upload the data and attempting, unsuccessfully, to cast the blame on another employee. The employee was prosecuted and received a custodial sentence.
Subsequently, approximately 9,000 employees whose data was leaked brought proceedings against Morrisons directly and on the basis of its vicarious liability for the employee's acts. Their claims were for breach of statutory duty under the Data Protection Act 1998 (DPA 1998), misuse of private information and breach of confidence.
What did the UKSC decide on vicarious liability?
The UKSC ruled that the lower courts had "misunderstood the principles governing vicarious liability in a number of relevant respects". The UKSC affirmed that "the wrongful conduct must be so closely connected with acts the employee was authorised to do … while acting in the ordinary course of his employment".
The UKSC found that, in the present case, Morrisons was not vicariously liable for the data breach by its employee, which was intended to harm the employer, as it "did not form part of [his] functions or field of activities" and "was not an act which he was authorised to do".
Although the UKSC did not have to rule on the DPA 1998, it also ruled that vicarious liability can be imposed on the employer for an employee's breach of the DPA 1998. It is uncertain whether the same interpretation applies under the General Data Protection Regulation (GDPR) and the Data Protection Act 2018, but under the GDPR, the Information Commissioner's Office (ICO) has the power to issue substantial fines, and it is easier for individuals and consumer groups to bring claims regarding a data breach.
What does this mean?
The UKSC decision will generally be welcome news for data controllers, given that it restates the limited circumstances in which they can be held to be vicariously liable for data breaches arising from the unauthorised actions of a rogue employee. However, the UKSC's finding that the Data Protection Act 1998 does not exclude vicarious liability for statutory, common, and/or equitable wrongs still leaves the door open for such claims.
What can employers do to protect themselves?
Employers can take several steps to protect or minimise the risk of being held vicariously liable, such as:
For more information about vicarious liability or how we can support your businesses, contact our corporate and commercial team.
Questions about
vicarious liability?