Equitable Injunctions for Mistaken Disclosure of Third-Party Personal Data: Data Controller Standing, Return/Deletion Duties, and Public-Domain Carve-Outs
1. Introduction
Grant Thornton [A Firm] and Anor v Scanlan (Approved) [2026] IEHC 167 is a High Court trial judgment (Dignam J) arising from a prolonged and procedurally complex dispute dating back to 2015. The plaintiffs (Grant Thornton and Grant Thornton Corporate Finance Ltd) sought permanent injunctions in respect of a large volume of information accidentally disclosed to the defendant, Ms Gerardine Scanlan, on a CD furnished in response to her data access request. The CD contained (i) her personal data and (ii) a “very significant volume” of information unrelated to her, including third-party personal data and information said to be confidential/proprietary and even legally privileged.
The central issues at trial were:
- whether the accidentally disclosed material had the “quality of confidence” required for equitable protection;
- whether the circumstances of receipt imported a duty of confidence despite the absence of a typical “confider/confidant” relationship;
- whether Ms Scanlan’s conduct (interrogation, copying, retention, and disclosure to third parties) amounted to breach;
- critically, whether the plaintiffs had locus standi to seek relief in respect of third-party personal data (particularly in light of Mahon v Post Publications Limited [2007] 3 IR 338); and
- on the counterclaim, whether damages were recoverable under s. 7 of the Data Protection Act 1988 absent proof of loss.
2. Summary of the Judgment
The Court granted permanent injunctive relief to the plaintiffs for breach of confidence. Dignam J held that:
- the information on the CD, taken as a whole, was private and confidential (subject to specific exceptions for public-domain material);
- a duty of confidence arose once the defendant knew (or ought to have known) the material was confidential—even though it came to her by mistake;
- the defendant breached that duty by continuing to examine (“interrogate”) the material after realising it contained third-party information, by copying it onto USB keys, by failing/refusing to return it promptly, and by disclosing it to at least Mr Scriven and Mr McKeogh;
- the plaintiffs were entitled to seek and obtain relief to protect third-party personal data in their possession (distinguishing Mahon v Post Publications Limited); and
- the injunction had to be drafted proportionately to exclude specified categories of material no longer confidential (birth certificates; documents previously included in legal packs; and certain specified material that had appeared on social media and in an email).
The defendant’s counterclaim for “substantial damages” under s. 7 of the Data Protection Acts for delayed compliance with her data access request was dismissed because she failed to prove actual loss/damage caused by the breach, applying Collins v FBD Insurance plc [2013] IEHC 137 and subsequent authority.
3. Analysis
3.1 Precedents Cited
A. The foundations of breach of confidence in Irish law
The Court’s framework rests primarily on the Irish leading authority House of Spring Gardens Limited & Ors v Point Blank Ltd [1984] IR 611, where Costello J (endorsed by O’Higgins CJ) treated breach of confidence as an equitable intervention enforcing “essentially a moral obligation,” not dependent on contract. Dignam J used it to anchor:
- the non-contractual basis of the duty;
- the importance of identifying confidential character; and
- the good faith limitation on use of confidential material to the purpose for which it was imparted.
B. The classic three-part test and the “quality of confidence”
The judgment relies heavily on English authorities that have long informed Irish confidence law:
- Saltman Engineering Co. Ltd. v Campbell Engineering Co. Ltd. [1948] 65 RPC 203 (Lord Greene MR) for the proposition that information must have the “necessary quality of confidence” and not be public property/knowledge.
- Coco v. A.N. Clark (Engineers) Ltd. [1969] R.P.C. 41 (Megarry J), cited via Attorney General v Guardian Newspapers (No. 2) [1990] 1 AC 109, for the familiar tripartite structure:
- confidential quality,
- circumstances importing obligation of confidence, and
- unauthorised use to the detriment of the confider.
Dignam J treated “public domain” analysis as central, drawing particularly on Attorney General v Guardian Newspapers (No. 2) [1990] 1 AC 109 (“Spycatcher”) for the proposition that confidentiality ceases when information becomes so generally accessible that it cannot be regarded as confidential.
C. Third-party recipients and accidental acquisition
This case turned on the defendant’s position as an unintended recipient. The Court drew from:
- Attorney General v Guardian Newspapers (No. 2) [1990] 1 AC 109 (Lord Goff) for the principle that a duty of confidence can arise where an “obviously confidential document” is picked up by a passer-by—i.e., accidental acquisition can still engage conscience-based obligations once confidentiality is (or should be) appreciated.
- Imerman v Tchenquiz & Ors [2011] 2 WLR 592 (Lord Neuberger) for the scope of the duty upon an unauthorised recipient: restraining threats to look at, copy, distribute, communicate, utilise; and enabling orders for return/destruction to prevent the information being “out there”. Dignam J treated this as broadly applicable beyond the matrimonial context.
D. Public/private mixtures and reconstruction from public sources
In assessing mixed confidentiality, the Court used authorities recognising that:
- information partly public and partly private may still be protectable, with the recipient required to take care to use only truly public material: Seager v. Copydex Ltd. [1967] 1 W.L.R. 923 and discussion of Coco v. A.N. Clark (Engineers) Ltd. [1969] R.P.C. 41 (novelty/confidentiality may arise from compilation/skill even if components are public).
E. Standing and the attempted reliance on Mahon
The defendant’s central resistance—plaintiffs could not enforce confidence over third-party data—was argued by reference to Mahon v Post Publications Limited [2007] 3 IR 338. Dignam J distinguished it as a case involving a public tribunal, unilateral confidentiality designations, press freedom, and prior restraint, rather than a private actor holding inherently confidential information under a duty of confidence.
F. Data protection damages: proof of loss required
On the counterclaim, the Court applied the settled line that s. 7 Data Protection Act 1988 damages are not “actionable per se,” requiring proof of damage and causation:
3.2 Legal Reasoning
A. Confidential quality: practical, category-based assessment
The Court rejected the suggestion that confidentiality required a document-by-document adjudication across “thousands” of data subjects. Instead, it evaluated categories and exemplars (progress reports, VAT computations, deeds of appointment, receivers’ fees, invoices, BER certs, borrower names/security addresses, and various internal spreadsheets). This is significant in data-breach litigation: confidentiality is assessed realistically, acknowledging volume and operational constraints.
While holding the dataset “as a whole” confidential, Dignam J identified necessary carve-outs:
- birth certificates (public record),
- documents already published in legal packs for land sales (thus no longer confidential), and
- specific items already placed online (Facebook/Twitter screenshots and a specified emailed attachment), where confidentiality was lost otherwise than through the defendant’s agency (and the plaintiffs did not prove she posted them).
The Court thereby treated “confidentiality” as both (i) a general attribute of the dataset and (ii) a variable property that can be lost for particular items once genuinely in the public domain.
B. Duty of confidence: triggered by knowledge after receipt
Even if the defendant did not know the CD’s contents upon receipt, the duty crystallised once she realised (very shortly after opening it) that it contained “very serious private information” of others. The Court found her subsequent stance and correspondence inconsistent with any claim of ignorance: she escalated the issue, emphasised its gravity, and described her own “interrogation” of the data.
C. Breach: interrogation, retention, copying, and disclosures
The Court treated several acts as wrongful once confidentiality was appreciated:
- continued examination (“interrogation”) after realising third-party confidentiality, distinguishing initial access necessary to discover the problem;
- retention/failure to return promptly, even if not framed as an explicit “refusal”; the correspondence supported a position of withholding pending her own “full and final interrogation” and a desire to contact “victims” directly;
- copying onto USB keys: copying before knowledge was not treated as a breach, but the failure to return/destroy copies after knowledge was;
- disclosure to third parties: admissions as to Mr Scriven and (on the facts) the Court did not accept that Mr McKeogh saw only the defendant’s data given the intertwined nature of the dataset and the defendant’s own account of using a USB key on his laptop.
Notably, the Court did not find the defendant responsible for the “Due Dilliger” online posts or for contacting Kevin Brophy, because those third parties were not proved in evidence (and plaintiffs expressly did not pursue attribution for online publication).
D. “No fire” and necessity for injunctions
The defendant’s argument that there was “no fire” (no urgency/need for injunctive relief) was rejected. The Court placed weight on:
- the defendant’s consent to interlocutory injunctions (the point should have been taken then); and
- the plaintiffs’ repeated requests for return met with non-return and refusal to give confirmations/undertakings.
The “fire” was the continuing possession and risk: confidential material remained outside plaintiffs’ control, with at least one USB key still missing even years later.
E. Standing to protect third-party personal data: the key clarification
The judgment’s most consequential reasoning is the Court’s rejection of the proposition that only the data subject may restrain misuse of third-party personal data mistakenly disclosed. Dignam J held that because the plaintiffs held that data under a duty of confidence (a point the defendant herself emphasised), they were entitled to seek equitable relief to protect it.
In distinguishing Mahon v Post Publications Limited [2007] 3 IR 338, the Court reasoned that:
- Mahon was about a tribunal’s unilateral attempt to impose sweeping confidentiality, implicating freedom of expression and prior restraint;
- here, the information was confidential by nature and held under obligations of confidence; and
- practical effectiveness matters: requiring thousands of data subjects to sue individually could render privacy protection illusory in urgent scenarios.
The Court also identified an internal inconsistency in the defendant’s case: she invoked “control” as a reason plaintiffs could not protect data subjects, while simultaneously asserting a right herself to retain and interrogate those data without the data subjects’ permission.
F. Remedy: proportionate injunction drafting and the public-domain boundary
Having found breach, the Court granted:
- a permanent restraint on dissemination/communication/use,
- delivery up of documents/records containing confidential information, and
- destruction/erasure/deletion of any confidential information in the defendant’s possession, as the Court may specify.
Crucially, the first restraint was narrowed to exclude (i) birth certificates, (ii) documents already included in legal packs up to the order date, and (iii) specified online-leaked materials. This reflects an insistence that confidence relief must not operate as a disproportionate restraint covering information that is no longer confidential.
3.3 Impact
A. Data-breach response: equity as an immediate control mechanism
The decision confirms that where a firm accidentally discloses mixed datasets (including third-party personal data), equitable breach of confidence can provide swift, robust tools—return/delivery up and deletion—independent of a statutory data protection claim. This is practically important where:
- the recipient is uncooperative,
- the data is voluminous, and
- the firm must rapidly contain a breach to discharge its obligations to third parties.
B. Standing: controllers/custodians can act to protect data subjects
By distinguishing Mahon and recognising plaintiffs’ entitlement to restrain misuse of third-party personal data they hold under duties of confidence, the judgment reduces a potentially severe “enforcement gap” that would otherwise arise if only individual data subjects could sue.
C. Public domain carve-outs: injunctions must be carefully scoped
The case is a reminder that “confidential information” in injunctions must be drafted with real attention to:
- public records,
- prior publication (e.g., sale legal packs), and
- proven online dissemination not attributable to the defendant.
This promotes proportionality and mitigates the risk of contempt disputes over material that is, in truth, already generally accessible.
D. Data protection damages: litigation discipline on proof of loss
The dismissal of the counterclaim underscores that (under the pre-GDPR statutory regime applied here) delay/breach alone does not sound in damages under s. 7 without cogent proof of loss and causation. Plaintiffs defending such counterclaims will likely rely on this reaffirmation of Collins v FBD Insurance plc [2013] IEHC 137.
4. Complex Concepts Simplified
- “Quality of confidence”: the information must truly be confidential—i.e., not already so widely accessible that it is effectively public.
- “Public domain”: not merely “someone else might have it,” but information so generally accessible (e.g., published online or in public sale packs) that it cannot sensibly be treated as secret.
- Duty of confidence without contract: even absent an agreement, equity can bind a recipient who knows (or should know) the information is confidential—especially where it arrived by mistake.
- Delivery up / destruction: court orders requiring the recipient to hand back physical/electronic copies and to delete confidential files so the information is no longer “out there.”
- Locus standi: the right to bring a claim. Here, the plaintiffs were held entitled to seek orders even for third-party data they held under duties of confidence.
- Section 7 Data Protection Act 1988 damages: treated as negligence-based; damages require proof of actual loss caused by the breach, not breach alone.
5. Conclusion
Grant Thornton [A Firm] and Anor v Scanlan (Approved) [2026] IEHC 167 reinforces and applies core equitable confidence principles to a modern data-breach fact pattern: accidental disclosure does not neutralise confidentiality; once the recipient appreciates the nature of the material, conscience-based duties arise to stop examining, to refrain from disclosure, and to return/delete.
The judgment’s lasting significance lies in two linked clarifications: (i) a custodian of third-party personal data can invoke equity to restrain misuse by an unintended recipient, and (ii) such injunctions must be proportionately drafted to exclude material that is demonstrably in the public domain. On the counterclaim, the judgment confirms the strict requirement of proof of loss for s. 7 damages under the 1988 Act regime.