Guardians of Data
A show where we explore the world of information law and governance; from privacy and AI to cybersecurity and freedom of information.
In each episode we will be speaking with experts and practitioners to unpack the big issues shaping the IG profession.
Guardians of Data
Managing Workplace Data Protection Risks
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
The biggest data protection challenges facing organisations do not stem solely from cyber-attacks or AI deployment; they also arise from employees. Sometimes it’s from an innocent mistake; an email sent to the wrong person, confidential information shared inadvertently or a document uploaded to the wrong system. In other cases, the issues are more serious; employees accessing information they have no business looking at, taking confidential data when they leave, or deliberately misusing personal information.
When those situations arise, employers need to investigate what has happened, decide whether a breach needs to be reported to the ICO and manage employment law issues such as disciplinary action; all the while protect the rights of the individuals whose data is involved, including employees.
And then there's the inevitable employee Data Subject Access Request, or DSAR to deal with. Often made alongside a grievance or before Employment Tribunal proceedings, DSARs can present significant legal and practical challenges for employers trying to balance transparency with confidentiality and legal privilege.
In episode 13 of the Guardians of Data podcast we explore:
- what happens when employees are involved in personal data breaches;
- the legal and practical issues arising when employees misuse personal data;
- how employers should approach workplace investigations involving personal data; and
- how to respond effectively to employee Data Subject Access Requests.
Our guest is Andrew Latham, a partner in the Public Law team at Capsticks, who specialises in data protection and privacy law.
Useful Links
ICO Employment Practices Code: Supplementary Guidance
The Morrisons Vicarious Liability Case
This podcast is sponsored by Phaselaw - a purpose-built solution for document disclosures, like subject access requests and FOI requests. Instead of redacting PDFs one by one, or forcing litigation software to do a job it wasn't designed for, with Phaselaw you get collection, review, and redaction in one workflow. Teams across the World are using it to cut response times from weeks to days.
For Guardians of Data listeners, Phaselaw is offering a two-month free trial; run it on live requests, see what it does to your backlog, decide from there. No card, no commitment.
Hello and welcome to Guardians of Data, the show where we explore the world of information law and information governance, from privacy and AI to cybersecurity and freedom of information. I'm your host, Ibrahim Hassan. Every organization relies on its employees to collect and use personal data fairly and lawfully. But employees can also be at the center of some of the most difficult data protection issues employers face. Sometimes it's an innocent mistake, an email sent to the wrong person, or a document uploaded to the wrong system. But in other cases, the issues are more serious. Employees accessing information they have no business looking at, or deliberately misusing personal data. When these situations arise, employers have to investigate and take action whilst navigating a complex mix of legal obligations. In this episode, I'm joined by Andrew Latham, a partner in the public law team at CapSticks who specializes in data protection and privacy law. Andrew and I explore what happens when employees are involved in personal data breaches, the legal and practical issues when employees misuse personal data, how employers should approach workplace investigations involving personal data, and how to respond effectively to employee data subject access requests. Let's jump in. How are you doing?
Andrew LathamI'm very well, thanks, Ibrahim. Thanks very much for having me and uh great podcast, and really looking forward to talking to you today.
Ibrahim HasanThank you very much, Andrew. And we've known each other for almost 20 years, but I thought we'd start off allowing you to introduce yourself.
Andrew LathamThanks very much. So I work at Capstix. We are a law firm. We work mainly with the healthcare sector, social housing providers, professional regulators, and local government organizations. So we're talking about employment-related issues today. And I suppose invariably, in that scenario, I would be advising an employer rather than an employee. I think that's about 550 people at the moment. And the team that I lead is eight of us that deal almost exclusively with information law issues. So data protection, free information, confidentiality-related issues, misuse of private information, the rise of AI, and other issues that are in that kind of space.
Ibrahim HasanAnd it's a fascinating area to be involved in at the moment, especially with the advancement of technology, particularly AI. And that's really where I want to start. Employees are becoming much more data-focused, data-centric, AI, and technology in general is allowing them to gather and process much more information about employees, about users, about customers. Is it fair to say, Andrew, that employees now sit at the center of almost every data protection issue in an organization?
Andrew LathamI think that's a great observation. We are definitely seeing two sides of a coin with it. So you either in scenarios where we're talking about data about employees and an employer wanting to use that information and make better use of it. But also we're in the scenario where employees themselves are doing things with data either about their colleagues, either legitimately or illegitimately. And in practice, pretty much all of the cases that we get involved with will have a human element to them, one way or the other.
Ibrahim HasanLet's start with the issue of employees involved in data breaches. I want to explore what the employers' options are, starting with inadvertent data breaches. Last year, Capita received a 14 million pound fine following a cyber attack which saw hackers gain access to 6.6 million people's personal information. The attack began when a malicious file was unintentionally downloaded onto an employee's device. Now, of course, as a matter of data protection law, the employer is liable for the breach as a data controller. But often the employer will also have to pick up the bill of any consequential damage and losses suffered by employees. Usually this ends up as part of a civil claim. So the question is, is there scope for an employer in such cases to take legal action against an employee to recover such losses?
Andrew LathamThe answer to this is that it is theoretically possible, but it's very uncommon in practice. And we can think about that in several ways. There's a legal answer, which involves a case from 50 or so years ago called Morris and Ford Motor Company, which is around whether or not it's kind of equitable if an employer has got insurance to go after an employee. But I think the bigger issues are practical ones, which are unless you have an employee that is being paid millions of pounds, the losses that the organization has incurred are not really going to be something that any single employee could be able to pay for. And so that is why most organisations will carry insurance. And I think certainly one of the things that I would encourage organisations to do is to think about what their cyber and data insurance covers and what scale of losses they are provided for as part of that. And also where the parameters of those policies lie. But if you don't have insurance and you think, well, actually that employee has cost me a load of money, can I get that money back from them? It's very, very difficult. I think you'd need to think about taking legal advice on that. And moreover, it might also be bad for business in terms of trying to pursue that individual employee as well. So theoretically possible, but tricky to pursue. There are other things that an employer might want to do, and in particular to think about taking disciplinary action against the employee that's been involved in the incident. So there is that sort of other avenue as well.
Ibrahim HasanThank you for that. We'll come on to disciplinary action because I want to look at that in a little bit more detail. But before we do, you're saying that it's an issue of fairness. The other point which resonates with me is that it's also about reputational damage. If an employer is known for seeking damages from employees for inadvertent breaches, who's going to want to work there?
Andrew LathamThat's exactly right. I don't think it would be a very tricky thing to put on your recruitment website is we're going to come after you if you cause us a problem. So I think it is a real challenge. And also, a lot of organizations now are moving towards a no-blame culture. And there are real questions about where the distribution of responsibility is between the employee and the employer. Because if I was acting for the employee, what I would be saying is I'm just the vessel through which this incident had occurred. Going to your CCing email thing, you know, what policy was there to stop me from sending emails in a CC box? Was there some technical troll controls in place to stop that mistake from happening? And those are the responsibilities of the employer to put in place rather than the employee. So trying to place all of the responsibility onto the employee in those scenarios is really, really tricky, as well as, as you say, causing a kind of reputational risk for the employer. So I think it's something that is worth thinking if you're an employer. The legal test is on having technical and organizational controls in place to keep data safe and secure. And to try to say, well, that everything that goes with that relies on a human to make the right choices, I think is something that an organization would really, really struggle to get home on down the line.
Ibrahim HasanIn your previous answer, you also said that the focus in any legal action, in addition to fairness, would be what measures the employer had in place to avoid the breach happening, or in data protection terms, technical and organizational measures. Is it fair to say that the same measures would have to be considered when deciding whether to take disciplinary action against an employee for an inadvertent data breach?
Andrew LathamYes, I think they would need to be taken into account. The situation where an employee has made a genuine mistake and whether that constitutes misconduct is pretty tricky, particularly if it's something that isn't really set out in any particular policy or guidance that applies to the employee or that they've not really had sort of training on. A lot will turn on the facts. But the question is really whether an employee, I think, can reasonably know that an act might be categorized as gross misconduct and therefore fall within a disciplinary policy. I should say that I'm not an employment lawyer by trade. There are a team of people at CAPSICs that deal with those kinds of questions all day, every day. And I would I would defer to them on what the right answer is in any particular scenario. But uh just as a sort of general observation, the genuine mistake scenario is tricky to prove, I think, as misconduct on the part of the employee.
Ibrahim HasanI agree. And once again, as we've said, technical and organizational measures, did they receive appropriate training? Did they know what the safeguards were? All those things would come into place. Of course, there's a big difference, Andrew, between making a mistake and deliberately accessing or using personal data without authority. We've seen a lot of examples of that recently. The tragic Nottingham attacks come to mind where health workers were accused of accessing the medical records of the victims. We've had the boy who was attacked by the crocodile at the zoo. Again, number of employees were accused of accessing his medical records. Of course, there are potential criminal offences here. I'm thinking section 170 of the Data Protection Act, a big problem which successive information commissioners have highlighted with that criminal offense, is that there's no custodial sentence. Some argue there's no deterrent. But these cases often also end up with civil claims for damages against an employer. So what would your advice be to employers? First of all, to avoid liability in such cases, and then secondly, in terms of recourse back to the employee?
Andrew LathamWell, the starting point here, I think, is to talk about two different kinds of liability that can attach in civil claims. So firstly, we have what's called direct liability. And that is, does the organization have sufficient uh measures in place to keep the data safe and secure on a kind of day-to-day basis? And in a scenario where data is exposed, then that might be a kind of direct liability issue. Someone will say, well, the measures that you had in place to stop this thing from happening in the first place were not sufficient. And that would be the first sort of way in which, if I were acting for an individual, I would be trying to articulate the claim. The second kind of liability is what's called vicarious liability. And that is where an employee has gone and done something and in the course of their work or while they've been at work. And the question is: should the employer be responsible for that employee's activities? And the test here came up in Morrison's case a few years ago. And that does leave the door open a little to vicarious liability for data breaches. But the the sort of legal test that you'd be thinking about is was what the employee doing so closely connected with their acts of as an employee that the employer may be fairly regarded as responsible because it's the employee doing things in the course of their employment. So was it the employee doing something which was kind of a misguided attempt to do their job, in which case the organization might be vicariously liable for the activities of that employee? Or was the employee going off on a frolic of their own and pursuing like a vendetta against a particular person? And in those scenarios, the court would be pretty slow to attach vicarious liability to the employer absent direct liability on the employer. But there's two cases, I think, that were kind of illustrative of these scenarios. First is a case involving the local authority in Lewton, where they had an employee who was pursuing a kind of vendetta against a sort of acquaintance. And in that case, they started looking up the records on the social work system that they had access to. And the court said that it was unfair to say that the council should be responsible for the employee going rogue and looking at those records on their system. That was something that they just had the opportunity to do at work. It wasn't part of their job at all. And therefore the council shouldn't be vicariously liable for the actions of that rogue employee. And that was pleaded as a vicarious liability issue where a member of the public calls up Weatherspoons and says, I'm a relative of one of your employees. Please can you pass on the details because I need to get in touch with them. And in that scenario, Weatherspoons was found to be directly liable in terms of the measures that they had in place to stop that breach from happening. The employee gave out information to the family member and or the the ex, and they harassed the individual. And the pub company was found to be vicariously liable for the employee doing their job, albeit it was something that then caused a harm to the individual.
Ibrahim HasanSo just to summarize, Andrew, when it comes to liability of employers for employees' data breaches, you've got direct liability, which I'm summarizing what you've said, that really depends on the back to the technical and organizational measures that the employer has in place to avoid the data breach. And then you've got vicarious liability where the employer is normally responsible, no matter what measures they've put in place, in relation to the actions of their employee, unless, of course, the employees doing something which is totally outside the course of their employment, what's known as a frolic of their own. Is that a fair summary?
Andrew LathamThat is a brilliant summary.
Ibrahim HasanWe've talked about what actions employers can take against employees in terms of disciplinary action. We've talked about civil claims. Are there any other remedies available when an employee goes rogue and starts misusing information?
Andrew LathamAn employer can report it to the police and the ICO. So either you could say it's a computer misuse act issue, or you could say that it is potentially fraud, or you could say that it is the Section 170 DPA offense, as you've described. Unfortunately, the number of prosecutions for those kinds of issues are pretty limited. And I think that is possibly a reason that we get these kinds of scenario that you have described where people are looking at records that they really shouldn't be looking at. There's sort of a lack of appreciation of consequences, or perhaps a lack of fear that there are any consequences, because they are very uncommon in terms of someone being prosecuted for looking at records that they really shouldn't be looking at.
Ibrahim HasanI agree, but you mentioned the Computer Misuse Act. That does carry a custodial sentence. But as you say, the number of prosecutions are so low that people tend to think that they can get away with it. Although recently there have been prosecutions involving both Section 170 and Computer Misuse Act. I'm thinking about the people working for garages and also insurance companies giving details on accidents.
Andrew LathamYeah, and I you're right. There is a slight spike in it at the moment. I suppose the cynical bit of me might say, well, is that just a very tip of an iceberg in terms of the number of incidents that are occurring? And as you uh very well described earlier on, any tragedy that happens, unfortunately, is then made worse through people that should be trusted to look after information, looking at records that they shouldn't be looking at. And uh it's also true of of other sectors as well. Uh there have been various police forces where this has been an issue. There have been instances of HMRC, and so it's one of those things where I think if I were an employer, how do I get the culture right in my organization where people don't do that? There is something which is around training people, but in the NHS there's mandatory training on information governance, and yet we see these scenarios happening nonetheless. So maybe training isn't a sort of an effective solution in and of itself. Role-based access, I think, is something where there is a lot that can be said for that, but necessarily lots of public sector organizations have quite open uh systems to enable information to be able to be looked at in an emergency by someone that really needs to see it. But you could say, well, could we think about sort of break glass type controls or monitoring and other ways of seeing what people are up to, auditing. But there isn't a single solution to this as a problem. There's a theory which, or an expression which I quite like, which is you want ideally to get to a situation where it's easy for people to do the right thing and it's impossible for people to do the wrong thing. And the more measures that you can put in place to achieve that, the better. And I guess for information governance professionals that might be listening to this podcast or or other people that are working in this kind of space, I think that is something to bear in mind and to talk to the organization that you're working with to say, well, what are we doing here to try to kind of constantly iterate and improve our processes to stop accidents from happening and to stop malicious behavior as well. And the more that can be done in those regards, the better.
Ibrahim HasanAbsolutely. Training and awareness, changing the culture of the organization alongside the technical and organizational measures that you've just mentioned, I think could go a long way. But in the end, people are people. Perhaps we seeing and learning about things that previously, prior to social media and the internet, we wouldn't know and maybe wouldn't care about, we're becoming more used to prying. And I think that attitude is permeating into organizations as well.
Andrew LathamYeah, it's human behavior. People are tempted by looking at things that they shouldn't be looking at. So it is a real challenge that it's only getting more complicated.
Ibrahim HasanInteresting. Once we discover there's a data breach, Andrew, organizations would inevitably want to launch an investigation, find out what's happened. Employers often need access to emails, teams' messages, electronic records. There's a data trail. Of course, when doing so, there's a need to balance a thorough investigation with the legal requirement to respect the privacy of employees. What practical advice would you give HR teams before launching an employee misconduct investigation? I appreciate you're not an employment lawyer, but from a data protection perspective.
Andrew LathamI think one of the things that HR teams can do is if they've got an internal information governance team to view these kinds of activities as a team sport, to take appropriate advice to help them with pursuing an investigation in a manner which is proportionate and which is getting the right kind of information and done in a way which is appropriate. So performing an investigation, thinking about what data you're going to need over the course of that investigation and why you're going to need it, what your legal basis is, and it's definitely Definitely not going to be consent, but to be clear with people about how their information is going to be used in the course of that investigation, what their internal facing privacy notices say about making use of information when it's possible to, for instance, do trawls of employees' inboxes or Teams messages and things like that. And ideally, you'd have a policy that says that an employer has a pretty wide degree of discretion to do that, that has been actively communicated to the employees themselves, so that there's then a good degree of latitude for the employer to take the right steps in a timely way in relation to the investigation. I think the other thing before going into an investigation, of course, is to have a plan and to think carefully about what the output of that investigation is supposed to be. You know, it's an investigation to find facts, and sometimes where organizations lose sight of that in the process, then they find themselves in difficulty down the line.
Ibrahim HasanI agree. It is supposed to be an investigation into the facts, what's gone wrong, who was involved. As part of that, Andrew, sometimes, and as we've seen increasingly, even with government ministers, people communicate with each other using private channels, their own WhatsApp messages, their own devices. What's your advice in relation to accessing those messages where they are relevant to the investigation?
Andrew LathamIf it's on a work device, the employer, I think, can pretty easily say, well, this is our within our control. It's on our systems. So if you've got a work phone that's got WhatsApp on it, then that's the employer's device. And in those scenarios, I think it would be a reasonable management instruction for the employer to say, that's ours, give it to us now because we need to use it. And possibly they've also got technology that allows them to look at those things remotely. If it's on a personal device, that is where it gets a little bit more tricky. And in those scenarios, it's easier for an employee to refuse to allow access to something which is on a personal device, whether there's then consequences for that employee because of a failure to cooperate with the investigation is a second set of issues. But in terms of the employee saying, Well, you know, that's my personal phone and you no one's going to be looking at it, I think that's something that uh many employees would be understandably saying in those kinds of scenarios.
Ibrahim HasanAnd I suppose employers need to think very carefully about their policy on use of work devices or disclosure and management of work information, even if employees are doing it on their personal devices. That policy, that procedure is important and may have a lot to say in terms of the employer's rights to look at those devices and those messages.
Andrew LathamThat's right. And even if not that, if it then comes to light that someone is doing work on a personal device and they really shouldn't be, then obviously that then could become a disciplinary issue for the employee concerned themselves. So this rise of the blurring of the line between what is work and what is not work, which has been one of the other phenomena of the last few years, I think is something which itself generates some really interesting data protection and privacy questions about where work stops and personal life starts, and the way in which people communicate with one another is a big part of that.
Ibrahim HasanAnd once we have an investigation, grievance, potential tribunal claims, we know, Andrew, that the employer is going to be faced with subject access requests. They've become almost routine in these kinds of situations. And now, of course, they're powered by AI. Now, some of these subject access requests can be said to be just fishing expeditions or a replacement for pre-action disclosure. Can employees refuse subject access requests on the grounds of motive that all they're doing is asking for information with a view to pursuing a tribunal claim?
Andrew LathamIt's very difficult. Motive in the first instance is quite tricky for an employer to prove if it's not been referenced by the employee, and it's potentially opening a bit of a can of worms in terms of attributing a motive to someone where actually what they will say they're doing is simply exercising their rights in a reasonable and legitimate way. Where motive becomes more of an issue and where some of the case law ends up is at the back end of a process of bringing a legal claim for non-compliance with a subject access request. And in those kinds of scenarios where the court has got a discretion about what else to award in relation to a subject access request, where an employer or an organization more generally has been alleged not to have complied with the request properly, then the motive of the person that's making the request is something that might sway the court's discretion one way or the other in terms of what else to order the organization to do in response to a request where the organization has been found not to have complied with it properly. The other scenario, I suppose, where you could say one motive is important is if it's something that is manifestly unfounded. And the ICO's guidance on this talks about someone that is maliciously pursuing a subject access request. Sadly, we do get scenarios where someone might be making a SAR with a view to trying to harass a colleague or something like that. And in those kind of scenarios, you might say, well, the motive is a relevant factor there, but obviously that is a very small minority of cases as compared to the majority where an employee is, as you say, using subject access requests as a way of seeking disclosure readily as part of the process. I think there has been a case where a failure to comply with a subject access request has been found to be an issue in terms of whether or not an employee was dismissed fairly. And the employee said, Well, actually, I needed the information from the subject access request to properly respond to a case that was being brought against me. It wasn't provided, and therefore I have been unfairly dismissed. And so there is this kind of interaction as well between the subject access right, which is a freestanding right, and the HR process, where the failure to comply with the SAR might be something that the employee ends up bringing as an issue in and of itself.
Ibrahim HasanYou mentioned manifestly unfounded and excessive, one of the reasons for refusing a subject access request, or indeed any request by a data subject under the UK GDPR. I agree that it's a difficult one to claim, particularly where now an employer might say, well, the motive is to harass the organization and to ask for lots of information which may be relevant, but that's from the employer's perspective. For the employee, it may well be relevant in terms of what they're pursuing, their grievance, et cetera. So I think I'm with you there that manifest the unfounded is is a difficult one. One of the other tactics of employees when making subject access requests is they'll ask for everything relating to, for example, a disciplinary investigation. Now, we know that there are no specific exemptions for disciplinary investigations in the UK GDPR, or should I say, the Data Protection Act 2018, Schedule 2 to 4, to be precise. But is there another exemption that an employer can use to withhold information about disciplinary investigations, particularly where they feel that it will prejudice the investigation?
Andrew LathamI think there's various things that an employer could do in that kind of scenario. There are exemptions that might apply to some information. And in particular, things like mixed data might be an issue. And an employer could say, well, there's a difference between disclosing information in the course of the HR process so as to be fair to the employee, where it's in that kind of controlled context, and disclosure in a subject access request, particularly whereas early doors in a process and maybe the other witnesses don't particularly know how that information might be handled, or there's a as yet untested allegation that concerns something like bullying or harassment, then issues of mixed data might be particularly important in those kinds of scenario. And also, invariably, in an employment-related SARS scenario, it will typically take place within a team or within a structure where individuals know one another. And so it's very difficult to sort of anonymize data in that kind of scenario. And it's worth organizations thinking about what is reasonable for the uh employee who's making the request to see how do their rights to know balance with the rights of other employees to have their privacy taken into account by their employer. So mixed data is a really big issue. There is, I think it's still on the ICO's website, and it's something that I go back to all the time. It's the Employment Practices Code supplementary guidance from the 1998 Act. And I think it's probably the best bit of ICO guidance that ever got put out. And it was a list of non-statutory factors to think about in dealing with employment-related subject access requests and where the balance on mixed data issues might lie. Obviously, it's a context-specific kind of decision, but it was a really good bullet-pointed list of things like the nature of the information, the hierarchy between the employees concerned, whether the information is something that someone might dispute, and all of these kind of different factors. And it was something that I thought was a really useful resource. So, yeah, mixed data is the is the big one. Privilege, uh, it's worth saying that the test for privilege is something that can be quite contested.
Ibrahim HasanSo by privilege, do you mean um legal professional privilege?
Andrew LathamLegal professional privilege, exactly correct. So, yeah, the test for legal professional privilege is something that can be quite contested. There's two main kinds of privilege. So there's information which is being created for the sole or dominant purpose of litigation at a time when litigation is in contemplation. And internal HR processes are not litigation. So it's very hard to say that litigation privilege applies to those kinds of scenarios. And then there is advice privilege, which is take material that's been generated to take advice from a lawyer or that's been produced by a lawyer in response to request for advice or giving advice. And again, the parameters around what is legal advice, particularly in circumstances where you know someone that is not a lawyer may have recounted advice that's been given by a lawyer, is something that ends up in court occasionally as disputes about where the the boundary line on what privilege is or isn't is. And those can be quite kind of hotly contested. It's worth saying that simply writing legal privilege on something doesn't make it privileged, and similarly writing confidential doesn't give it any sort of special degree of protection in terms of data protection exemptions. I guess the other sort of main exemption that employers might want to think about is prejudice to management planning. And uh it's quite a nebulous exemption, and I don't think there's any case law that's really kind of considered what the parameters of what management planning is or isn't. But in scenarios where there is an HR process that's ongoing, it might be something that an employer could consider as an exemption to apply. And obviously, there though is quite kind of context-specific. So I wouldn't recommend just kind of applying it across the board if you've got a SAR that touched on employment issues.
Ibrahim HasanThat's great advice. I'm glad you've mentioned the ICO's document in relation to the employment practices code, the supplementary guidance, because I've been looking for that for a while. I couldn't find it on the website. So if you could kindly share the link to that, I'll send you the link and you can put it in the show notes. Excellent. Thank you very much for that. Andrew, we mentioned subject access requests are becoming weaponized, particularly with the assistance of AI. Any advice?
Andrew LathamIt's a massive challenge. Almost every single subject access request that we get asked to advise on at the moment has the hallmarks of being AI generated or assisted with when they're made by employees. And so I think one of the things that I would start with is just remembering that simply because it's been produced by AI, that doesn't mean that it's right. And one of the things that we see within subject access requests that are AI generated is references to various purported legal rights that are not actually subject access rights in and of themselves. So you'll get references to requests for metadata, and you'll get requests for documents, and you'll get requests for litigation holds and things like that. And I think it's important for organizations to bear in mind that what their responsibilities are for dealing with subject access requests, primarily set out in Article 12 and Article 15 of the UK GDPR. And you know, the obligations on them are to do a reasonable and proportionate search for personal data, to provide a copy of that data based on the reasonable and proportionate search, and to make sure that the other sort of rights that are set out in Article 15 have been covered off in the response. And I think if organizations get bogged down in trying to deal with the request in the terms in which it's been made by the employee, then they will find that it's very, very tricky to kind of respond in full. It is possible, of course, for employers now to ask individuals to clarify their requests and to stop the clock as part of that. And one of the things that's specifically referenced in the legislation is where organizations process a large amount of information about an individual. And in the employment scenario, that is potentially quite common. So I think asking individuals to clarify their request is a tool that employers can use. It's worth saying, though, that of course you can't really negotiate with an AI. You know, it's it's not something where the machine is going to say, well, yes, that's a perfectly reasonable answer. And so it might be worth thinking if you're an employer. Can you talk to the employee? Can you say, well, trying to help you? We're very happy to try and give effect to your rights. But what is it you're actually looking for? Invariably, employees say they want everything. They don't want everything. They don't want 50 telephone directories worth of emails saying, can you come to this meeting? What they want is yet a very specific piece of information that they think exists about something particular to do with their employment. So I think if you can try to get out of the doom loop of dealing with things through back and forth correspondence where it's all in writing and it's all being fed into a machine, then that's something that might help in the long run. But the other things that are worth saying, yeah, good information hygiene, you know, are you deleting things that you don't really need anymore? Are you looking in sensible places to respond to subject access requests? Are you pulling material to deal with it? And do people know how to respond to it? Have you got training in the right places within an organization? Are the other things that I think an employer can think about doing if they're faced with a difficult Tsar?
Ibrahim HasanFor me, one of the difficulties of this increased weaponization of subject access requests using AI is that the AI speaks with such confidence in relation to the law. And if people haven't checked the sources, they end up repeating that same confidence and feeling as though they're being hard done by or they're being duped in some way.
Andrew LathamYeah, it is really, really tricky. And exactly as you say, the algorithm is designed to be attractive to the person that is using the AI tool, and they will want it to be right. They'll go along with what it is that's saying, because though there is a challenge now about people not having the resources to represent themselves. And if you've got something that is ferociously backing your corner and it's an algorithm, it's an AI tool, and it's there all the time, it's free to use and it's being helpful, then you'll go along with what it is that it's saying. So I I think it it's really understandable that employees are using AI tools, whether it's helpful to them in the long run is the second question.
Ibrahim HasanI read a wonderful quote on LinkedIn. AI is wonderful and 100% accurate in relation to things I know nothing about, but only 40% accurate in relation to things I know something about.
Andrew LathamI like that. I like that a lot.
Ibrahim HasanJust finally, Andrew, we've talked a lot about data protection issues relating to human employees. But the big trend in 2026 is organizations using AI agents to do work previously done by humans. Now, if you believe the marketing hype, AI agents are more productive, don't need annual leave, and never ask for a pay rise. What legal issues do you envisage going forward with the deployment of these new quote-unquote workers?
Andrew LathamI think one of the challenges that we have as lawyers is that law is almost always reactive and it's always almost always a step behind technology. And so we're in a situation now where a lot of these new innovations are coming on stream very, very quickly, and the legal framework that we have got to operate within isn't well suited to those kinds of new tools as and when they're arising. So, from a lawyer's perspective, it's a very interesting time to be working on these issues, and there'll be a long tail, I think, of legal issues that come out after the technology has been deployed in the first place. So, what I think we will almost certainly start to see is people saying the technology that you've used has got some kind of bias in it, that it has hallucinated some kind of information about me. And the organization might struggle to explain how a tool that it has used has actually made a decision. Does it have any records? Does it have any reports? Does the black box explain why it's made a particular decision about this individual doesn't pass the thresholds that we're looking for as part of recruitment? And importantly also, is whatever that material decision that's been made, is it something that is replicable? Could you explain why it's reached the decision that it has? So I think for employers that are thinking of using these kinds of technology, starting point question is what problem are you trying to solve? And does it do the thing that you're that you're trying to achieve? There are then the kind of core data protection considerations, so you know, doing due diligence on suppliers, making sure that if you're buying in some technology and the organization that you're working with is a data processor, that you have got the right contractual terms in place with them, that you understand where the data is, that it's not being used for purposes that are disconnected with your use of it, and that it's not being kept for longer than it needs to. Further consideration is where it is. And I think particularly now we're getting these long chains of cloud-based tools. If you get a data breach that is somewhere down the chain, would you ever become aware of it? You know, is something that is quite challenging now, which is that the way in which employers are structuring their businesses, and particularly using a lot of these new kinds of tools, means that I think it is increasingly important to make sure that there is a decent bit of due diligence that's been done and uh a decent data protection impact assessment as part of it. The other consideration, of course, is how you're bringing the employees with you. And there are lots of scenarios that are kind of coming up at the moment where there's been a very strong reaction to the deployment of AI-related tools that are replacing workers and the kind of actors' guild, screenwriters' guilds in America are very, very spot on the idea of that members being replaced by AI-related tools. And I think that will start to permeate across as well. So if you're an employer thinking of deploying one of these tools to either monitor an employee or replace an employee, then you need to be very careful about ensuring that you're approaching it in a way which is cognizant of the person that is involved in those kinds of handlings of data as well.
Ibrahim HasanAnd I suppose that's where consultation with the unions and the usual employment protocols would have to be complied with.
Andrew LathamYeah, exactly. And and none of that changes simply because you're using a why bit of new technology. All of the rules still apply. And as we'll see, I think probably in a few years' time, it may be that there are some new rules that get put in place to grapple with new bits of technology, but whether those are going to remain a step behind, I think will be the question for the late 2020s and into the 2030s. So as I say, I think it's a really interesting time to be working in this sort of space with uh some interesting data protection angles that go with it.
Ibrahim HasanAbsolutely. Andrew, it's been a fantastic conversation and one to which no doubt will return, as you say, the technology is advancing all the time. But in the meantime, where can people carry on the conversation with you, learn a bit more about your work?
Andrew LathamYou can find me on LinkedIn. If you look for Andrew Latham, then I will be delighted to connect with you on LinkedIn. If you go to www.capsticks.com, then you can find our profile on how to get in touch with us and sign up for events that we're running. And we'd be delighted to connect with people and have you along.
Ibrahim HasanAndrew, thank you very much for your time and best of luck in the future.
Andrew LathamBrilliant. Thank you so much for having me, uh Ibrahim. It's been a real pleasure talking to you and thanks for such a great podcast.
Ibrahim HasanThat's all for this episode of Guardians of Data. My thanks again to Andrew Latham for a really insightful discussion on employee data protection. We've covered why employers need to think carefully before blaming individuals for inadvertent data breaches and why strong technical and organizational measures, clear policies, training, and the right workplace culture are so important. We also looked at the risks when employees deliberately misuse personal data and the practical steps organizations can take when investigating misconduct while still respecting employee privacy. Andrew also shared some really useful thoughts on subject access requests, particularly how they are increasingly being shaped by AI, and why employers should focus on their actual legal obligations rather than being distracted by overbroad or inaccurate demands. Finally, we looked ahead to the growing use of AI agents in the workplace and the need for proper due diligence, impact assessments, transparency, and consultation before deploying new technology. If you found this discussion useful, please subscribe, share the episode with colleagues, and join us next time on Guardians of Data.