UNAPPROVED NO REDACTION NEEDED
THE COURT OF APPEAL
CIVIL
Court of Appeal Record Number: 2025/207
High Court Record Number: 2022/699 JR
Hyland J. Neutral Citation Number [2026] IECA 141
Meenan J.
Collins J.
BETWEEN/
EAMON MCSHANE
APPLICANT/APPELLANT
- AND –
DATA PROTECTION COMMISSION
DEFENDANT/RESPONDENT
- AND –
HEALTH SERVICE EXECUTIVE
NOTICE PARTY
JUDGMENT of Mr. Justice Charles Meenan delivered on the 24th day of July 2026
-2-
Introduction: -
1. This is an appeal from a refusal of the High Court (O’Donnell J. (Barry)) to grant the
following reliefs by way of judicial review: –
(i) an order of certiorari quashing the dismissal of the appellant's complaint
against the notice party dated 15 December 2021 that was dismissed by the
respondent on 23 May 2022
(ii) an order of mandamus compelling the respondent to investigate the appellant’s
complaint to the respondent on 15 December 2021 that was dismissed by the
respondent on 23 May 2022
(iii) a declaration that the process followed by the respondent in the appellant's
case, with regard to the respondent’s finding on 23 May 2022 that the notice
party was not a data controller under the General Data Protection Regulation
(EU) 2016/679, and or dismissing the appellant’s complaint on foot of same,
was unlawful under the circumstances.
Background: –
2. The appellant was at all material times employed by the notice party (the “HSE”) as
a fire prevention officer. In or around February 2020 the appellant was provided with a
laptop computer and smart mobile phone by the HSE for him to use in connection with his
employment for work related matters including work-related phone calls, emails, and
messages. The appellant also used that smart phone for his personal use, including
personal emails, a Fitbit account and a Binance account.
-3-
3. In or around April/May 2021 the HSE was the subject of a serious data breach
involving some 90,000 data subjects who were notified of the breach.
4. In or around June/July 2021 the appellant discovered that his personal email accounts
on the HSE provided smart phone had been hacked or accessed by unknown third parties.
Further, his “Binance’’ account had been unlawfully accessed and crypto currency to the
value of €1400 had been stolen.
5. In July 2021 the appellant made a complaint to his Line Manager in the HSE stating
that he believed his work phone had been compromised. That complaint was not escalated
to the HSE’s Data Protection Officer. Thereafter the appellant submitted a formal written
complaint to the HSE by way of letter dated 24 September 2021. The response by the HSE
to this complaint was contained in a letter dated 17 December 2021. Meanwhile, the
appellant, on 15 December 2021, submitted a complaint to the respondent.
6. In its decision, dated 23 May 2022, the respondent dismissed the appellant’s
complaint on the basis that the HSE could not be considered to be “a Data Controller”
under the provisions of Art. 4(7) of the GDPR Regulation.
7. The appellant accepted that there was personal, non-work-related, data on the said
smart phone. He further accepted that he should not have used the HSE supplied smart
phone for personal use.
The complaint: –
8. It is necessary to consider the terms of the complaint that was made so as to identify
what issue(s) the respondent was being called on to consider:
(i) Letter of complaint of 24 September 2021: –
-4-
9. This letter was written by a solicitor instructed by the appellant and directed to the
HSE Data Protection Officer. The letter stated: –
“As a result of the said breach, a number of our client's online accounts were
accessed without his consent or authority in or around June/July 2021. These
included his Gmail account, Yahoo account and Fitbit account. Most seriously, our
client's Binance account was also accessed. As a result, crypto currency to the value
of approximately €1400 (subject to confirmation once account has been recovered)
was---”
and: –
“Please note that this personal data breach is entirely unacceptable to our client.
We are satisfied from our instructions that the HSE is responsible for the personal
data breach and therefore liable to compensate our client for all damage, loss,
inconvenience and expense, as well as the associated mental and emotional distress,
suffered by him as a result.
Firstly, we request that the HSE admits to this personal data breach, confirming that
it will not repeat same along with its proposals for compensation in light of the
above in an open letter within (14) days from the date hereof.”
(ii) Response of the HSE: –
10. The HSE responded to the letter of 24 September 2021 by letter dated 17 December
2021 to the appellant’s solicitors. This letter stated, inter alia,: –
-5-
“The HSE manager confirmed she spoke with Mr McShane and he informed her that
the breach related to his personal Yahoo account which he states he accessed on his
HSE provided mobile phone.”
The letter then quoted from the HSE ICT’s Acceptable Use policy as follows: –
“The HSE’s Information Technology (IT) resources are to be used primarily for HSE
business-related purposes. However at the discretion of their line management
occasional personal use may be permitted… The HSE has the final decision on
deciding what constitutes excessive personal use.”
and: -
“Confidential and restricted information must only be stored on HSE laptop, mobile
computer device or smart device with the authorisation of the user’s Line
Manager…”
and: –
“Users must not:
2. Connect any HSE IT devices and equipment, laptop or smart device to an external
network without the prior authorisation of the ICT Directorate.”
(iii) Complaint to the respondent: –
11. The complaint to the respondent was made via submitting an online form. In answer
to the question “what is the basis of your complaint?’’ the appellant referred to attached
correspondence, which consisted of the letters of 24 September 2021 and 17 December
-6-
2021 and a number of emails that had passed between the appellant and the respondent.
Those emails neither altered or broadened the terms of the complaint.
Decision of respondent: –
12. Following an exchange of correspondence the respondent gave its decision by way of
email dated 23 May 2022. This decision stated: –
“Based on the information you have provided to this office, there is no basis for
which the HSE could be considered the controller of your client’s personal data that
he himself stored on his HSE issued phone without their apparent knowledge or
agreement.”
and: –
“Based on the information provided, I am unable to identify a contravention of data
protection legislation by the HSE. This office will now conclude our file on this
matter.”
13. The appellant responded to the decision in an email dated 27 May 2020: –
“We understand the points you raise but we feel you are limiting your investigation
to our client’s complaint to that concerning personal data allegedly on his HSE-
issued phone without authority or consent from his employer, the HSE. However,
our client’s HSE issued phone was not used solely to hold such data; it was also used
to hold significant personal data with the authority and consent of his employer. that
data was also subject of the breach. It is our view that the HSE, as employer, is
controller of such data and therefore obligated pursuant to data protection law to
ensure any such data is safely processed…”
-7-
14. The decision of the respondent was confirmed by email dated 21 June 2022, which
also informed the appellant of his right under s.117 of the Data Protection Act to bring a
data protection action in the Circuit Court.
Application for judicial review: –
15. Following an ex parte application, the High Court directed that the application for
leave be on notice to the respondent and the notice party. In granting leave Bolger J. ruled:
–
“Defining data controller
9. The applicant has established an arguable case that his complaint included his
work-related personal data as well as his unauthorised non-work related data. If
that is found to be so, then there is also an arguable case with a reasonable prospect
of success that the notice party was a data controller that processed the applicant’s
personal data and that the respondent, therefore, should have handled and examined
that aspect of his complaint…”
16. The appellant’s statement of grounds, under the heading “Legal Grounds”, stated: –
“Interpretation/definition of “data controller” under the General Data Protection
Regulation (EU 2016/679)
(a) The respondent erred in law by not defining the Notice Party as a “data
controller” that processed the Plaintiff's “personal data” and further acted
ultra vires by dismissing the Applicant’s complaint on foot of same,
(b) The Notice Party provided the Applicant with a mobile phone in connection
with his work and said phone was to be used on the instruction and
-8-
authorisation of the Notice Party. Notwithstanding any personal use of the
phone by the Applicant, the mobile phone contained “work related” personal
data belonging to the Applicant that was processed in connection with his
employment, in connection with the discharge of his duties and as part of his
employee/employer relationship with the Notice Party.”
17. The respondent’s statement of opposition contained a preliminary objection that, as
there was a statutory right of appeal available to the appellant, he was not entitled to
maintain judicial review proceedings.
18. In respect of the complaint that the appellant made to the respondent, the statement
of opposition specifically pleaded at para. 9 (iii) that: –
“Had the Applicant not used the work phone provided to him by the HSE (the
“Phone”) for his personal use, the Non-Work Data would not have been on or
accessible through the Phone.”
19. Further, the following is stated, repeatedly, in the statement of opposition: –
“The Work Data was not the subject of the Complaint”.
Judgment of the High Court: –
20. In his judgment the learned trial judge dismissed the respondent’s preliminary
objection that the appellant was not entitled to challenge the respondent’s decision as he
had not exercised his right of a statutory appeal. It should be noted that there was no cross-
appeal in relation to this.
-9-
21. The trial judge made clear that he would only determine the issues “that were
pleaded and in respect of which leave to apply for judicial review was granted”. He
continued: -
"43. … I do not consider that it is open to the court or appropriate for the applicant
to convert a relatively net issue into a broader survey of the obligations of the DPC
concerning the proper handling of enquiries or broader investigatory issues. Still
less it is appropriate, as appears to have been suggested in the second and later
affidavits sworn by the applicant, to conduct the form of enquiry into whether the
DPC should have used the applicant’s complaint to launch an investigation into the
HSE's broader approach to the processing of personal data that may be stored on
devices provided to employees.”
22. The trial judge focused on the complaint that was made as set out in the letter of 24
September 2021. The trial judge stated: –
“50. In the circumstances I consider that the only fair way to analyse the DPC
decision of the 23 May 2022 is by reference to the materials that were before it, and
specifically by reference to the particular issues that the applicant sought to agitate.
It would be entirely oppressive for a body such as the DPC to be required not only to
handle a complaint was made on its own terms but also, for that body to have to
speculate as to whether there might be additional matters worthy of investigation
hidden, as it were, in the shadows of the actual complaint.”
23. The trial judge considered the correspondence between the appellant and the
respondent. The trial judge stated: –
- 10 -
“51. – – – That complaint was specific, and the clear gravamen of the complaint was
not that this work device contained work-related personal data, but that it contained
non-work-related personal data. The complaint as presented in the online form
attached a copy of the letter dated 24 September 2021 that the applicant’s solicitors
had sent to the HSE. In turn, that letter made clear the applicant was concerned that
there had been a data breach and that his Gmail, Yahoo, Binance and Fitbit
accounts had been compromised.”
24. Having identified the specific complaint and information before the respondent the
learned trial judge considered its obligations. He referred to the following passage from
the decision of this court in Ryan v. Data Protection Commission [2024] IECA 152 where
Binchy J. stated: -
“79. The obligation of supervisory authorities such as the respondent to handle
complaints with “all due diligence” is well established. It is obvious from the phrase
itself that it affords supervisory authorities a measure of discretion in their handling
of complaints, but this is in any event made clear by several provisions of the GDPR,
such as recital 141 and article 57, each of which speak of the handling and
investigation of a complaint “to the extent appropriate”,…
“80. In his own opinion in the Land Hesse, Advocate General Pikamäe, having
emphasised the binding obligation of supervisory authorities to handle complaints
lodged by data subjects with the due diligence that “is appropriate to the specific
case” (my emphasis), also stated that “several factors militate in favour of an
interpretation to the effect that [supervisory authorities] enjoy a margin of assessment
in examining those complaints and a degree of latitude and the choice of the
appropriate means to carry out its tasks.” …”
- 11 -
The trial judge concluded: –
“62. In my view, the DPC clearly engaged in an appropriate and proportionate
investigation of the individual complaint that had been made. As made clear in
Ryan, the point of the handling exercise is to address complaints in a way that is
appropriate to the specific case. Here, as I have found, the specific case made to the
DPC related to the applicant’s complaint that his Gmail, Yahoo, Fitbit and Binance
accounts had been compromised, and, albeit without any evidential basis, that this
was attributable to the cyber-attack conducted on the broader HSE ICT
infrastructure. The applicant did not in reality dispute that the use of the work phone
to conduct his personal business was not permitted, and in fact is a later stage in the
proceedings before this court that was accepted by the applicant…”
25. The trial judge thus dismissed the appellant's application for judicial review.
Notice of appeal: –
26. The notice of appeal set out some 10 grounds of appeal. Ground number 10
essentially summarised the basis of the appellant’s challenge to the judgment of the court
below: –
“The trial judge erred in law and fact in finding:
(a) the Appellant’s complaint to the Respondent was limited to only
investigating ‘non-work’ data on the phone.
(b) the parameters of the Appellant’s complaint was limited to only what was
specified in the wording of the complaint (and said parameters were too
- 12 -
limited or too focused to allow the Respondent to deny the Notice Party
was a data controller).
(c) the Respondent had no duty or power to look behind the wording of the
complaint.
(d) there was no ‘work related’ personal data on the HSE work phone.
(e) the Notice Party was not a “data controller” for any of the personal data
on the HSE work phone.
(f) the Respondent was correct in finding that the Notice Party was not a
“data controller” for any of the personal data on the HSE work phone.
(g) The Applicant was not a data subject for any data on the HSE work
phone.”
Consideration of appeal: –
27. From the submissions made by the appellant it does not appear to be disputed that the
HSE was not a “Data Controller” for the purposes of non-work-related data on the
appellant's mobile phone but was a “Data Controller” for the purposes of work-related
personal data. This raises the question as to whether the terms of the complaint made by
the appellant included work-related personal data.
28. The trial judge was clearly of the view that in analysing the impugned decision it was
necessary to examine the terms of the complaint made by the appellant. It is very difficult
to see how one would take issue with such a fundamental proposition.
- 13 -
29. At paragraphs 8-10 above I set out the relevant correspondence that passed between
the appellant and the HSE, which correspondence was submitted to the respondent to via
the “online” complaints form.
30. The complaint to the HSE was initiated by letter dated 24 September 2021. At para.
9 above I set out the relevant paragraphs. It is clear from the terms of this letter that the
complaint related to the appellant’s personal accounts not related to his work. On several
occasions the appellant refers to “this personal data breach”.
31. In my view the response of the HSE by letter dated 17 December 2021, set out at
para. 10 above, puts the matter beyond dispute. It states that the appellant informed the
HSE manager that the breach “related to his personal Yahoo account which he states he
accessed on his HSE provided mobile phone.” If this, in the view of the appellant, was not
a correct representation of his complaint one would have thought, at the least, there would
be a response to the HSE to that effect. There was no such response. The issue of work-
related personal data was only raised by an email from the appellant dated 27 May 2022, in
response to the decision of the respondent which had been communicated by email a
number of days previously, on 23 May 2022.
32. Given the contents of the letter of complaint and the lack of any response to the letter
from the HSE of 17 December 2021, I find it difficult to see how the trial judge could
reach any other conclusion other than the complaint related to the appellant’s personal non-
work related data. That being the case it is very clear, and the appellant did not submit
otherwise, that the HSE was not a “Data Controller” for the purposes of Article 4(7) of
the GDPR Regulation.
33. In the course of submissions to this court the appellant broadened his attack on the
impugned decision by suggesting that his complaint had not been adequately investigated.
- 14 -
It was submitted that the respondent was under some form of duty to, as it were, look
behind the complaint. Had the respondent done so, it was submitted that it would have led
the complaint to be broadened to include work related data.
34. There are three fundamental problems with this submission. Firstly, as indicated
earlier, it is for the appellant to formulate his own complaint. It is not for the respondent to
investigate matters that were not the subject of the complaint. Secondly, were the
submission of the appellant to be accepted by the respondent there would be an obvious
unfairness to the HSE in that it would be required to defend a complaint that was never
made. This would be a clear breach of procedural fairness. Thirdly, leave was not granted
on this ground.
35. By reason of the foregoing I am satisfied that the appellant has identified no infirmity
in the decision of the High Court. I therefore dismiss the appeal.
36. As for costs, the provisional view of the court is that, as the respondent has been
“entirely successful” in resisting the appeal, that it is entitled to its costs. Should the
appellant dispute this he may do so by informing the Court of Appeal office within 10 days
of the date of delivery of this judgment. The appeal will then be listed, at a convenient
time, in early October 2026 to consider the costs issue.
37. As this judgment is being delivered electronically both Hyland and Collins JJ. have
authorised me to record their agreement with it.