Hi All, I don't think we can really call this one based on the info in the original query, but have added some thoughts / questions I'd ask if the same case landed on my desk -
"Employee of A is entitled and has a lawful basis to access confidential data of a subject - no breach of confidentiality would arise.
Subject S has told B (after an incident) that under no circumstances should any employee of A access the data ever again."
- this would appear to be a Section 10 request in DPA'98 terms, an Art 18 request in GDPR terms and / or a withdrawal of consent under either regime (i.e. it would appear S believes B holds some sway over the processing of the data by A)
"B has not told A, and has not blocked A's access so A's employee, being unaware of any withdrawal of consent, accesses data in the normal course of events for A's legitimate purposes. A and B controllers in common. Assume A at some stage gave proper PN to S."
- we don't currently know whether or not S's request would have to be acceded to, and as such can't really gauge whether or not B would reasonably have been expected to tell A or block A's access to the data. GDPR would indicate A should at least been advised of S's approach.
"Subject receives compensation from B. Subject now sues A for breach of confidentiality / unlawful processing. Surely no case to answer?"
- what was the compensation for? Was the compensation awarded by the Court or was S compensated by B as a means of closing the matter down in Full & Final? Was A involved in the process that resulted in B compensating S? Was the compensation a joint offer from A&B?
"Would it matter if the PN was missing / defective e.g. S can argue that if A had given the right PN he would have known to tell A direct?"
- it might matter, but the extent involved could also depend on details in the unknowns above.
Owen
Owen Thomas
Deputy Data Protection Officer
Data Protection Office
Strategy, Performance and Transformation Directorate
Sunderland City Council
0191 5611263
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
All archives of messages are stored permanently and are
available to the world wide web community at large at
http://www.jiscmail.ac.uk/lists/data-protection.html
If you wish to leave this list please send the command
leave data-protection to [log in to unmask]
All user commands can be found at https://www.jiscmail.ac.uk/help/subscribers/subscribercommands.html
Any queries about sending or receiving messages please send to the list owner
[log in to unmask]
Full help Desk - please email [log in to unmask] describing your needs
To receive these emails in HTML format send the command:
SET data-protection HTML to [log in to unmask]
(all commands go to [log in to unmask] not the list please)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
|