ENSafrica
April 28, 2020 - South Africa
South Africa: Coronavirus (COVID-19) - How to Avoid Vicarious Liability for Data Protection Breaches by Employees in an Online Environment during Lockdowns
|
The UK’s highest court recently ruled that Morrisons, a supermarket group, was not vicariously liable for the criminal act of an employee with a grudge who leaked the payroll data of about 100 000 members of staff. Many companies sighed in relief on hearing that the Supreme Court of Appeal did not hold Morrisons vicariously liable. Vicarious liability is the legal principle of holding someone responsible for the acts or omissions of another, and it is most often applied in the employer-employee context. The principle is an equitable one and is common in most jurisdictions, including South Africa. While English law and South African law share many similarities, we caution that when it comes to the application of the principles of vicarious liability, South African courts have developed slightly different rules. Despite this, the case serves as an important reminder that it is possible for an employer to be held vicariously liable for a data breach caused by an employee, in the event that the act or omissions by the employee that led to the data breach occurred in the course and scope of the employee’s work. The determination of whether an employer may be held liable for the acts or omissions of its employee will need to be determined in light of the facts in each case. This means that there is no general rule to avoid this risk, but there are some general guidelines that should be followed to mitigate it. The risk of an employee being the cause of a data breach is generally high. There are numerous statistics that show that the weakest link in a company’s cybersecurity is often employees and contractors. With a large number of employees now working from home, this risk has increased. Valuable insights in respect of risk reduction can be drawn from the Morrisons case. The facts of the Morrisons case, briefly, were that Mr Skelton (a disgruntled employee) had been delegated the task of providing payroll data to Morrisons’ external auditors (KPMG in this instance). Once Mr Skelton was granted access to the payroll data, he dutifully passed it on to KPMG. However, he also went on to upload a file containing the data of 98 998 of the employees to a publicly accessible file-sharing website, with links to the data posted on other websites. It turns out he was actually trying to frame another colleague and anonymously informed the press about the leak of data.. In light of this case, we set out a few tips on how to mitigate the risk of being held vicariously liable for a data breach caused by an employee.
Disgruntled employees causing a data leak would be as much a data breach, as an employee being duped by a phishing scam. It is essential to ensure that your potential liability is reduced in both as well as related scenarios. If you need assistance with formulating the appropriate data retention and processing policies, contact our experts at ENSafrica. Era Gunning Banking and Finance Director egunning@ENSafrica.com +27 82 788 0827 Jessica Steele Corporate Commercial Candidate Attorney jsteele@ENSafrica.com +27 72 455 2135 |