35. Given that mandatory statutory obligation it seems to me that it follows - although this would have to be subject of argument in an appropriately framed case - that, as a matter of good administration, when describing the action taken there should be specificity as to the statutory characterisation of the action taken, clarity as to whether that outcome is characterised by the DPC as a legally binding action, and clarity that there is a statutory appeal available. None of that occurred in this case.
Whether the DPC acted lawfully
36. On this issue, in written and oral submissions the applicant argued that it was clear that the applicant's complaint related to work related personal data, whether or not he used the device for personal purposes. This meant, according to the applicant, that it ought to have been clear to the DPC that the investigation should have encompassed a consideration as to whether the HSE complied with its obligations as a data controller in respect of that data.
37. The applicant referred to the DPC document, "Guidance Note: Data Protection in the Workplace: Employer Guidance", which contemplated the potential for work devices to store personal data, for instance in the context of work emails.
38. The applicant argued that the DPC was obliged to investigate breaches of GDPR, and relied on observations by the CJEU in cases such as TR v Land Hessen (Case C-768/21) where inter alia the Court stated:
"32. In particular, under Article 57(1)(f) of the GDPR, each supervisory authority is required on its territory to handle complaints which, in accordance with Article 77(1) of that regulation, any data subject is entitled to lodge where that data subject considers that the processing of personal data relating to him or her infringes that regulation, to investigate, to the extent appropriate, the subject matter of the complaint and inform the complainant of the progress and the outcome of the investigation within a reasonable period. The supervisory authority must deal with such a complaint with all due diligence (see, to that effect, judgment of 7 December 2023, SCHUFA Holding (Discharge from remaining debts), C-26/22 and C-64/22, EU:C:2023:958, paragraph 56 and the case law cited)."
39. The applicant says that the DPC did not respond to his complaint by acting with all due diligence, which ought to have involved inquiries as to whether there was any personal data processed on his work phone. The fact that the applicant believed that the phone had been hacked ought to have been sufficient to trigger those necessary inquiries.
40. The nature of the arguments pursued at hearing is illustrated by the conclusions that the applicant sets out in his written submissions, which were as follows:
"The Respondent:
a. did not make any enquiries to the Notice Party as what work-related personal data was on the phone thereby failing to make any proper enquiries as to whether the Notice Party was a data controller.
b. did not apply their own Guidance Note: Data Protection in the Workplace: Employer Guidance by not enquiring and or investigating as to what data was on the phone for the purposes of establishing whether said data constituted personal data (and then by extension whether the Notice Party was a data controller).
c. did not make any "assessment in a concrete manner" as per VB and failed to investigate the Applicant's complaint with "due diligence" as per TR.
d. dismissed the Applicant's claim in limine.
e. denied the Applicant a statutory entitlement to an investigation as per I.B. v HSE.
f. breached s.101(1)(f) of the Data Protection Act 2018 by failing to properly or adequately "handle" the Applicant's complaint.
g. breached s.101(1)(g) of the Data Protection Act 2018 by failing to properly or adequately "examine the lawfulness of processing" of the subject matter of the Applicant's complaint and the employer/employee relationship and data controller/data subject relationship between the Applicant and the Notice Party."
41. It is quite apparent that with the exception of points (a) and (b) above, the grounds set out above on which the applicant contends that the decision of the DPC should be quashed go considerably and materially beyond the grounds in respect of which he sought and was granted leave to apply for judicial review. Furthermore, at no point did the applicant seek to exercise his entitlement to apply to have his grounds extended.
42. Understandably the DPC objected to any attempt on the part of the applicant to extend the grounds of the challenge without first seeking permission. In that regard, the legal principles are very well established and recently were re-iterated by the Court of Appeal in Hayes and Foley v. The Environmental Protection Agency and Others [2024] IECA 162, where Butler J. stated at para. 61:
"Any High Court proceedings are likely to entail significant costs and it is and remains a concern if additional costs are unnecessarily incurred because the case an applicant seeks to run does not conform with the case that they have pleaded. That concern is heightened in the case of proceedings by way of judicial review because the scope of the case is defined not just by the pleadings themselves but also by the fact that in order to bring such proceedings an applicant has to be granted leave to do so on foot of a preliminary application brought for that purpose."
43. In the first instance therefore, the court in this case will only determine the issues that were pleaded and in respect of which leave to apply for judicial review was granted. I do not consider that it is open to the court or appropriate for the applicant to convert a relatively net issue into a broader survey of the obligations of the DPC concerning the proper handling of enquiries or broader investigatory issues. Still less is it appropriate, as appears to have been suggested in the second and later affidavits sworn by the applicant, to conduct a form of inquiry into whether the DPC should have used the applicant's complaint to launch an investigation into the HSE's broader approach to the processing of personal data that may be stored on devices provided to employees.
44. That then leads to a consideration of what the DPC submitted in response to the issues that properly could be said to form the legitimate content of these proceedings. Here the DPC's starting point is a further uncontroversial proposition that the decision it made should be considered by reference to what the applicant put before it when the complaint was made.
45. The DPC illustrated that general proposition by reference to the observations of Phelan J. in Hayes v. The Property Services Appeal Board [2023] IEHC 282.
46. In that case, which dealt with an appeal on a point of law arising from a different statutory code, the appellant was concerned with an admissibility decision where the authority declined to carry out an investigation. At first instance, the authority declined to investigate, relying on a particular statutory provision. That decision was appealed to the respondent board, in which the appellant set out his grounds of appeal. The licensee and the authority provided a response, and the respondent board affirmed the decision not to carry out an investigation.
47. The judgment of Phelan J. sets out that when the appeal was argued the appellant elaborated significantly on certain matters that had not been canvassed as part of the underlying process. The court noted:
"41. It is imperative that a complainant sets out fully the basis for his or her concern when presenting the complaint which is then relied upon in making an admissibility decision. As no right of reply is provided for under the scheme of the 2011 Act in response to submissions filed by the other party and the Authority on an appeal against a decision of the Authority, the complainant's case may well stand or fall on the contents of the original complaint."
48. The Court went on to make clear that in the circumstances she considered that she had to determine the question of law on the basis of the material before the Authority and the Board on appeal.
49. While clearly there are differences between the process with which the Hayes case was concerned and the process involved in the current case, I consider that the comments made by Phelan J. are apposite. In my view, the court is required to gauge the lawfulness of the DPC decision from the 23 May 2022 on the basis of the materials that were before it at the time, albeit that in this case there had been some further exchange of information after the initial complaint on 15 December 2021.
50. In the circumstances I consider that the only fair way to analyse the DPC decision of the 23 May 2022 is by reference to the materials that were before it, and specifically by reference to the particular issues that the applicant sought to agitate. It would be entirely oppressive for a body such as the DPC to be required not only to handle a complaint that was made on its own terms but also, for that body to have to speculate as to whether there might be additional matters worthy of investigation hidden, as it were, in the shadows of the actual complaint.
51. As noted above, I do not consider that this approach is controversial. The DPC was asked to handle a complaint that had been expressed in a letter from a firm of solicitors acting for the applicant. That complaint was specific, and the clear gravamen of the complaint was not that his work device contained work related personal data, but that it contained non work related personal data. The complaint as presented in the online form attached a copy of the letter dated the 24 September 2021 that the applicant's solicitors had sent to the HSE. In turn, that letter made clear that the applicant was concerned that there had been a data breach and that his Gmail, Yahoo, Binance and Fitbit accounts had been compromised.
52. On the 10 January 2022, the applicant's solicitor emailed a copy of the HSE response letter of the 17 December 2021 to the DPC. The email also attached a response from the applicant's solicitor to the HSE by email dated the 10 January 2022 which stated that the HSE had failed to confirm the following:
"1. Whether the remit of your investigation included our client's specific complaint that his personal data held on his HSE-issued mobile phone was accessed without his authority; and
2. If so, the findings made in that regard." [emphasis added]
53. I am satisfied that the clear import of that response - particularly having regard to the words emphasised by me above - was that the applicant remained focused on the Gmail, Yahoo, Fitbit and Binance data. The response did not suggest that the applicant was concerned about whether the HSE had looked into the question of whether other "work related personal data" had been accessed improperly.
54. The DPC sent a query to the applicant by email on the 14 April 2022. That email noted that the essence of the complaint was that the "HSE was responsible for a breach of his personal data". The email then referred to the HSE letter from the 17 December 2021 and asked (a) for evidence that the HSE was responsible for the data breach, and (b) how the HSE could be a data controller for "personal data processed in apparent contravention of the HSE ICT Acceptable Use Policy".
55. At that point it was perfectly open to the applicant to correspond with the DPC with a view, if that was the case at the time, to explain that the DPC and HSE had misconstrued his complaint by focusing on the non-work related personal data (despite the fact that these were the only types of data referred to in the initial letter to the HSE) and that the applicant was concerned about the broader issue of legitimately stored personal data on his work phone.
56. Instead, as explained above, the applicant did not clarify what he meant by personal data. Given its importance and the way it has been characterised in the statement of grounds, it is worth setting out the material parts of the applicant's email of the 20 April 2022 in full. Having referred to the email from the DPC of the 14 April 2022 the applicant's solicitor states:
"In short, the position is as follows: -
1. The HSE issued a mobile phone to our client in the course of his employment;
2. The said HSE-issued phone, and in turn our client's personal data on that phone, was accessed without authority or consent by a cyber-criminal during the course of the well-documented HSE data preach (sic) last year;
3. Though we have asked the HSE on a number of occasions for confirmation that our client's personal data was breached, this has not been forthcoming from the HSE contrary to its obligations under the GDPR and Data Protection Acts as data controller;
4. Instead, the HSE has ignored the issues at the core of this complaint and raised an allegation that its internal ICT Acceptable Use Policy was breached by our client. Respectfully, that would be an employment matter and our position is that any alleged breach of that HSE Policy does not allow the HSE to escape its obligations under data protection law as data controller."
57. On my reading of that email when viewed in the context of the correspondence that went before it, it is very difficult to see how that can be seen as some form of clarification that the complaint was intended to concern work related personal data. The applicant complained that there had not been a proper investigation by the HSE into the question of how his data was accessed, and contended that the HSE ICT Acceptable Use Policy was an employment matter that did not affect the HSE obligations. The implication of the last point, as I understand it, was to contend that even if the applicant had used his device without permission to process non-work related personal data, that fact did not prevent the HSE being treated as a controller of that data.
58. Following receipt of the 20 April 2022 email, the DPC made its decision and communicated that to the applicant's solicitors in an email dated the 23 May 2022.
59. In those premises, what were the obligations of the DPC faced with the specific complaint and information before it?
60. In Ryan v. Data Protection Commissioner [2024] IECA 152 the Court of Appeal addressed a refusal by the High Court of an application for a declaration that the DPC had failed to carry out an investigation. The general approach to be adopted by the DPC was described by Binchy J. in the following way starting at para. 79:
"79. The obligation of supervisory authorities such as the respondent to handle complaints with "all due diligence" is well established. It is obvious from the phrase itself that it affords supervisory authorities with a measure of discretion in their handling of complaints, but this is in any event made clear by several provisions of the GDPR, such as recital 141 and article 57, each of which speak of the handling and investigation of a complaint "to the extent appropriate", and also recital 129 which states that measures adopted by supervisory authorities in the exercise of their powers "should be appropriate, necessary and proportionate in view of ensuring compliance with this Regulation, taking into account the circumstances of each individual case, respect the right of every person to be heard before an individual measure which would affect him or her adversely is taken and avoid superfluous costs and excessive inconveniences for persons concerned".
80. In his opinion in the Land Hesse, Advocate General Pikamäe, having emphasised the binding obligation of supervisory authorities to handle complaints lodged by data subjects with the due diligence that "is appropriate to the specific case" (my emphasis), also stated that "several factors militate in favour of an interpretation to the effect that [supervisory authorities] enjoy a margin of assessment in examining those complaints and a degree of latitude and the choice of appropriate means to carry out its tasks". In expressing this opinion, he relied on the opinion of Advocate General Saugmandsgaard Øe in Data Protection Commissioner v. Facebook Ireland Ltd (Case C-311/18)(Schrems II)."
61. Bearing those observations in mind and also bearing in mind that the margin of discretion afforded to the DPC does not extend to its interpretation of legislation, can it be said that the decision is wrong as a matter of law in finding that the HSE was not a data controller when it came to the processing of the non-work related personal data of the applicant? To a large extent there is no apparent dispute on this specific point, otherwise the applicant likely would not have attempted to turn the focus of the case to the work related personal data arguments.
62. In my view, the DPC clearly engaged in an appropriate and proportionate investigation of the individual complaint that had been made. As made clear in Ryan, the point of the handling exercise is to address complaints in a way that is appropriate to the specific case. Here, as I have found, the specific case made to the DPC related to the applicant's complaint that his Gmail, Yahoo, Fitbit and Binance accounts had been compromised, and, albeit without any evidential basis, that this was attributable to the cyberattack conducted on the broader HSE ICT infrastructure. The applicant did not in reality dispute that the use of the work phone to conduct his personal business was not permitted, and in fact at a later stage in the proceedings before this court that was accepted by the applicant. The DPC did not purport to adopt an unorthodox interpretation of the definition of data controller. Instead, against the backdrop of the factual matrix before it, it found that the HSE had not "determined the purposes and means of the processing" of the data relating to the Gmail, Yahoo, Fitbit and Binance accounts accessed by the applicant on his work phone. That finding appears to me to be self-evident, where that use of the phone clearly was not authorised by the HSE.
63. I should also say that the DPC decision was not only based on the proposition that in the circumstances the HSE was not the data controller, but also referred to the fact that it could not be determined whether the applicant's personal accounts were accessed as a result of the cyberattack on the HSE, rather than being compromised by a different route.
64. Hence, I cannot find that the decision was ultra vires the DPC. Likewise, I can find nothing irrational in the decision, whether that is gauged by the Meadows or O'Keeffe type tests. This was a decision that was open to the DPC in light of the nature of the complaint and the definition of "data controller"; I am satisfied that he decision was made on the basis of and consistent with the evidence that was before the deciding officer.
CONCLUSION
65. In all the circumstances, I have not been persuaded that the applicant is entitled to the relief sought. I am satisfied that the applicant made a specific complaint about specific issues and, within the parameters of that complaint and those issues, the DPC decision was lawful and clearly open to it. Accordingly, the application for judicial review will be refused.
66. As this judgment is being delivered electronically, I will invite the parties to seek to reach agreement on the appropriate final orders including orders in respect of costs. In case it is not possible to reach an agreement I will list the matter before me for argument on final orders at 10.30am on Thursday, the 1 May 2025. However, if there is any argument on costs, I direct that the parties exchange written submissions of no more than 1,500 words no later than the 24 April 2025.
BAILII: