This article examines the case law surrounding the General Data Protection Regulation (GDPR), which came into effect on 25 May 2018. It is the second part of a two‑part series on the GDPR. The first part, which explores the data protection developments that led to the GDPR.
Following the discovery that data rights were not being adequately protected under the Data Protection Directive 1995, which was implemented in the UK through the Data Protection Act 1998, the European Commission announced in 2012 that it was developing the GDPR.
Subsequent legal cases, including those led by Max Schrems and David Carroll, as well as the leaks by Edward Snowden and the Cambridge Analytica scandal, made the need for stronger regulation even more urgent.
With just over one year of the new regulation in force, The Student Lawyer examines the case law that has emerged under the GDPR and considers what this may mean for the future.
We also examine cases involving fines imposed on Google, British Airways and Marriott International, the Enforcement Notice issued to Aggregate IQ Data Services Ltd (AIQ), and action taken by the Information Commissioner’s Office (ICO) against organisations that failed to pay the new data protection fee.
A brief recap of GDPR
GDPR allows EU citizens greater control over the data held about them, including the right to be forgotten. It updates and modernises data rules for governments and businesses and makes privacy by design a legal requirement.
Under GDPR, data must be collected and processed fairly and transparently. Requests to process personal data must be clear and easy to locate, and the right to withdraw consent has been strengthened. Data must be accurate and up to date, held only for the minimum time necessary, and protected against unauthorised access.
GDPR applies to personal data such as names, phone numbers, location data and online identifiers, as well as sensitive personal data including ethnicity, sexuality, political affiliation, religion, biometric data, medical conditions and criminal convictions.
Penalties for breaches or unlawful sales of data to third parties include limits or bans on data processing, compulsory audits of data handling, and fines of up to four per cent of global group turnover or twenty million euros, whichever is higher. Enforcement operates through a one‑stop‑shop system.
GDPR has been incorporated into UK domestic law through the Data Protection Act 2018, which implements the EU Law Enforcement Directive and provisions left to Member States to determine. It is preserved under article 3 of the European Union (Withdrawal) Act 2018 in the event of a no‑deal Brexit.
The first organisations to fall foul of GDPR
The largest fine to date is the one hundred and eighty‑three million pound penalty issued to British Airways by the ICO in July 2019. This represented approximately one and a half per cent of BA’s worldwide turnover.
The airline failed to protect customers from a cyberattack in which hackers stole the personal and financial data of around five hundred thousand people. The attack took place between 21 August and 5 September and was carried out by a group previously responsible for the Ticketmaster breach in June 2018.
This ruling marked a significant shift away from the relatively modest fines issued under the old regime.
The following day, the ICO issued its second largest fine to Marriott International. Marriott was fined ninety‑nine million pounds after hackers stole the personal data of three hundred and thirty‑nine million customers worldwide, including seven million in the UK.
The breach originated in Starwood’s IT systems, which Marriott inherited when it acquired the company in 2016. Both BA and Marriott have indicated that they will appeal the ICO’s decisions.
In September 2018, the ICO issued its first Enforcement Notice and took action against organisations that had failed to pay the new data protection fee. Aggregate IQ Data Services Ltd, a Canadian political consultancy and technology company, received the first formal notice due to its involvement in the Cambridge Analytica scandal.
AIQ provided software used to harvest personal data for political targeting during the Vote Leave and BeLeave campaigns in the UK’s 2016 EU referendum. The fact that a Canadian company was subject to GDPR demonstrated the effectiveness of one of the regulation’s core objectives.
In France, Google was fined fifty million euros by the Commission nationale de l’informatique et des libertés (CNIL) in January 2019. Google had made it too difficult for users to opt out of data processing for personalised advertising.
Although significant at the time, the fine was small compared to the potential maximum of four billion euros and has since been overshadowed by the penalties imposed on BA and Marriott.
Those who narrowly avoided GDPR penalties
Several organisations escaped the higher fines introduced under GDPR because their offences occurred before the regulation took effect.
Facebook’s involvement in the Cambridge Analytica scandal resulted in a five hundred thousand pound fine from the ICO in October 2018, the maximum available under the Data Protection Act 1998.
This amount is negligible compared to the five billion dollar settlement Facebook later reached with the Federal Trade Commission in the United States. Had the case fallen under GDPR, Facebook could have faced a fine exceeding six hundred million pounds.
Equifax was also fined five hundred thousand pounds in September 2018 by the ICO after a cyberattack compromised the personal data of one hundred and forty‑six million people worldwide, including fifteen million in the UK.
The company had ignored warnings about critical vulnerabilities in its systems. Although headquartered in the United States, Equifax’s UK branch was held liable for the failure to protect British customers.
Another organisation that narrowly avoided GDPR penalties was Bounty UK, a pregnancy and parenting club.
Bounty was fined four hundred thousand pounds in April 2019 after the ICO found that between June 2017 and April 2018 it had illegally shared personal data with third parties for marketing purposes without informing the fourteen million people affected. The data included information collected from new mothers, mothers‑to‑be and young children, such as dates of birth and gender.
Conclusion
The ICO has demonstrated that it is no longer the weak and inflexible authority it was once perceived to be. Elizabeth Denham, the Information Commissioner, has emphasised that organisations entrusted with personal data must take proper care of it.
This new regulatory attitude will concern major technology companies. Google is currently under investigation by the ICO for a breach affecting fifty million users of its G+ platform, and Facebook is under investigation for a cyberattack affecting fifty million users in September 2018.
Another significant case awaiting resolution is the Morrisons appeal to the Supreme Court, which concerns whether the company is liable for data stolen by a rogue employee.
The appeal in Various Claimants v Morrisons Supermarkets Plc is scheduled for November and, although decided under the old Data Protection Act 1998, may have implications for the effectiveness of GDPR if overturned.
For now, the number of GDPR complaints received by the ICO continues to rise as individuals become more aware of their rights over their personal data.
Not sure how close you are to qualifying?
The path-fit quiz reads your situation and shows you which routes you are ready for, and exactly what to do next. Four minutes, no account needed to start.
Check your readiness