Morrisons Compensation: Addressing The Wrongful Sharing Of Employee Data

Written by

in

In recent years, the issue of data protection has gained significant attention as companies around the world grapple with the consequences of breaches and misuse. One such case that garnered widespread media coverage was the compensation claim against Morrisons, a major British supermarket chain. In this article, we will delve into the details of the Morrisons compensation case and shed light on the implications it had on data protection laws.

The story began in 2013 when Morrisons faced an internal data breach that shook the company and its employees. Andrew Skelton, a senior internal auditor, unlawfully stole the personal and financial details of nearly 100,000 Morrisons employees. Subsequently, Skelton leaked this data on the internet, which resulted in significant distress and inconvenience for the affected individuals.

As news of the data breach broke, Morrisons took immediate action to rectify the situation. The supermarket swiftly notified the police, leading to Skelton’s arrest and criminal conviction. As a responsible corporate entity, Morrisons also strived to support affected employees by providing them with assistance and taking necessary measures to prevent further harm. However, it was later discovered that this was not enough to address the damages caused.

In 2017, a group of over 5,500 employees filed a class-action lawsuit against Morrisons, seeking compensation for the distress caused by the data breach. The case revolved around the central question of whether Morrisons could be held liable for the criminal actions of an individual employee. In 2018, the UK’s High Court ruled in favor of the claimants, holding Morrisons vicariously liable for Skelton’s actions.

The court’s decision sent shockwaves through the business and legal communities. It established a precedent that made organizations potentially responsible for the actions of rogue employees, even when those actions were criminal and against the company’s interests. This ruling prompted concerns about the potential negative impact on businesses and their ability to protect against such unforeseen incidents.

Following the court’s decision, Morrisons appealed to the Court of Appeal, but in October 2019, the court upheld the High Court’s ruling, stating that Morrisons was indeed liable for the data breach. This meant that the supermarket had to compensate each affected employee, an estimated total amounting to tens of millions of pounds.

However, this case was not just about Morrisons compensating its employees; it also highlighted the need to strengthen data protection laws. The case served as a catalyst for increased scrutiny surrounding organisations’ responsibility to safeguard personal information. Consequently, the UK government introduced the Data Protection Act 2018, which clarified the legal landscape with regards to data breaches and the liabilities of organizations.

The Morrisons case demonstrated the significance of implementing robust data protection measures, not only to prevent breaches but also to protect employees should such breaches occur. It emphasized the need for comprehensive cybersecurity strategies, regular risk assessments, and employee training programs to minimize vulnerabilities within an organization.

Furthermore, the case highlighted the importance of monitoring and enforcing data protection protocols. It emphasized the need for companies to invest in advanced security technologies and implement proper access controls to mitigate the risk of internal breaches. By continually reviewing and enhancing these measures, companies can safeguard their employees’ personal information while minimizing the risk of data breaches.

In conclusion, the Morrisons compensation case shed light on the legal and moral obligations faced by organizations in protecting employee data. It emphasized the importance of robust data protection measures and the potential ramifications of failing to implement them. As businesses navigate an increasingly digital landscape, the Morrisons case serves as a cautionary tale, reminding us all of the need to prioritize data security to protect both individuals and companies from the far-reaching consequences of data breaches.