Background
Eamon McShane, an HSE fire prevention officer, used an HSE-issued smartphone for work and personal purposes. After discovering in 2021 that personal accounts including Gmail, Yahoo, Fitbit and Binance had been accessed, and that cryptocurrency worth approximately €1,400 had been stolen, he complained to the HSE and then to the Data Protection Commission. The DPC closed the complaint, finding no basis to regard the HSE as controller of personal data that McShane had stored on the phone without the HSE’s apparent knowledge or agreement.
McShane sought judicial review, arguing that the complaint also encompassed work-related personal data for which the HSE was a controller. The High Court refused relief, holding that the complaint actually presented to the DPC concerned his non-work accounts and that the DPC had handled that complaint appropriately and proportionately. McShane appealed.
The Court’s Holding
The Court of Appeal dismissed the appeal. It held that the complaint’s scope had to be determined from the materials submitted to the DPC. Those materials identified the compromised personal accounts, while the HSE’s response recorded that the reported breach concerned McShane’s personal Yahoo account. McShane did not correct that account before the DPC decided the complaint; he first raised work-related personal data after the decision.
Because the complaint concerned non-work personal data, and McShane did not contend on appeal that the HSE controlled that data, the DPC was entitled to conclude that the HSE was not its controller under Article 4(7) GDPR. The DPC had no obligation to look behind the complaint and investigate unasserted matters: complainants must formulate their own complaints, expanding the case would be procedurally unfair to the HSE, and leave for judicial review had not been granted on that broader ground. The court provisionally awarded the DPC its appeal costs.
Key Takeaways
- The legality of a regulator’s decision is assessed against the complaint and materials actually placed before it.
- A data protection authority is not required to reformulate or expand a complaint to encompass possible infringements that the complainant did not allege.
- A distinction exists between work-related personal data controlled by an employer and an employee’s non-work data stored on an employer-issued device without the employer’s knowledge or agreement.
Why It Matters
The decision underscores the importance of defining a data protection complaint precisely at the outset. A complainant cannot ordinarily challenge the DPC for failing to investigate a materially broader case introduced only after the regulator has made its decision.
It also confirms that ownership or provision of a device does not, without more, make an employer the GDPR controller of every item of personal data stored or accessed on that device.