Who Does Personal Data on a Work Device Belong to?
22nd May 2025
Irish High Court rules against data subject in case regarding personal data on work phone
In the case of McShane v Data Protection Commission and Health Service Executive [2025], the Irish High Court ruled that the Controller of personal data on work devices is not the employer. This case highlights a common grey area in data protection law regarding personal use of work equipment and the importance of keeping professional and personal data separate.
Details of the Case
The data subject, Eamon McShane, was given a work phone for use as part of his role as fire prevention officer with the Health Service Executive (HSE). He used this work phone to access his personal email account and a cryptocurrency account. The HSE suffered a data breach and ransomware attack in May 2021, compromising several HSE computers and other devices, including McShane’s work phone. The following month, McShane noticed that his personal email account and cryptocurrency account had both been compromised, and €1,400 worth of cryptocurrency had been stolen.
McShane filed a complaint with his employer relating to this incident and sought compensation for his loss, claiming that his personal data had been unfairly processed. He claimed that work-related personal data on the work phone could identify him, and this meant that the HSE was a data controller, which they rejected. Unsatisfied with the HSE’s response, McShane escalated this to the Irish Data Protection Commission, which refused to investigate his complaint, citing Article 4(7) of the GDPR. This article states that:
“‘controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;” – Source: gdpr-info.eu
The High Court Ruling
The DPC’s rejection of McShane’s complaint was due to HSE’s policy of not using a work device for personal use. Nonetheless, McShane sought further remedy with the Irish High Court, hoping they would compel the DPC to investigate. The High Court upheld the DPC’s decision, and Mr Justice Barry O’Donnell stated that “the DPC clearly engaged in an appropriate and proportionate investigation of his complaint” (source – Irish Times). The DPC’s argument was that McShane should not have used the work phone for personal use, and had he not done so, there would have been no personal data to be breached, and he would not have lost his cryptocurrency. HSE set a clear instruction to employees to not use their work devices for personal use, which McShane disregarded by checking personal emails and his personal cryptocurrency account. Therefore, the HSE was not responsible for protecting this data, due to the unauthorised use of work equipment.
Related Cases
This case relates closely to Meadows v Minister for Justice, Equality and Law Reform [2010] in its application of judicial review principles, particularly the standard of reasonableness in administrative decisions. In Meadows, the Irish Supreme Court held that where fundamental rights are at stake, decisions by public bodies must meet a standard of “proportionality” and not merely avoid being irrational. McShane relied on this test in arguing that the DPC’s refusal to investigate his complaint about personal data on his work phone was unreasonable. However, the Irish High Court found that the DPC had acted within its powers and responded appropriately to the nature of McShane’s complaint, which concerned non-work-related data that the HSE had no knowledge or control over. The Court concluded that the threshold set in Meadows was not met, reinforcing the idea that while the proportionality standard remains a safeguard for rights-based complaints, it must be grounded in a clearly established duty and an identifiable error in process or judgment, which, in this case, was not found.
The court ruling hasn’t exactly made a new law here, but it has clarified the responsibilities of both employee and employer in such a case. It’s important to keep work data and personal data separate for the protection of both parties – personal data would not be compromised by a work-related data breach if there is no personal data stored on work devices.
If you have questions or concerns about data protection and work devices and your rights and responsibilities as an employer, feel free to get in touch with us here at Griffin House Consultancy – see our contact page or call 01673 885533 for a chat.
Author: Mike Martin LLM
Mike is an information governance specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.
Sources