Selected cases

Court of Appeal of England and Wales · [2024] EWCA Civ 1516

Andrew Prismall v Google UK Limited & Anor

Andrew Prismall v Google UK Limited & Anor [2024] EWCA Civ 1516 is a major UK privacy case about patient data and the limits of...

Court of Appeal of England and Wales11 Dec 2024

Plain-English explainers, not legal advice. Use the linked official source for section-level detail, and get advice for your situation.

Get legal help

Start here

Quick read

  • Do not treat this case as permission to take broad rights over sensitive data.
  • Andrew Prismall v Google UK Limited & Anor [2024] EWCA Civ 1516 is a major UK privacy case about patient data and the limits of representative actions.

Use this to check

  • Patient-identifiable medical information will normally attract a reasonable expectation of privacy.
  • That starting point does not mean every person in a very large class automatically has the same misuse of private information claim.
  • A representative action can fail if the weakest notional claimant in the class does not have a realistic prospect of success.

Decision snapshot

  1. What happened

    • Andrew Prismall brought a representative action against Google UK Limited and DeepMind Technologies Limited on behalf of a class said to include about 1.6 million people.
    • The claim arose from the transfer by the Royal Free London NHS Foundation Trust of patient-identifiable medical records in October 2015, followed by a continuing live data feed until 29 September 2017.
    • The records related to patients who had attended Royal Free hospitals or had blood tests processed by Royal Free laboratories between 29 September 2010 and 29 September 2015.
    • Google and DeepMind used the data for developing Streams, an app intended to identify and treat patients suffering from Acute Kidney Injury.
  2. What the court had to decide

    • The central issue was whether a representative action for misuse of private information could proceed on behalf of about 1.6 million people under CPR 19.8.
    • To do that, the representative claimant and all class members needed the same interest, and the parties accepted that each class member had to have a realistic prospect of success.
  3. What the court decided

    • The Court of Appeal dismissed Mr Prismall’s appeal and upheld the order granting reverse summary judgment and striking out the representative claim.
    • It held that, although patient-identifiable information in medical notes will normally attract a reasonable expectation of privacy, that is only the starting point.
    • The court must still consider all the circumstances, including whether equivalent information is already in the public domain and whether the seriousness threshold is crossed.

Practical impact

Practical read

  • Do not treat this case as permission to take broad rights over sensitive data.
  • The court upheld the strike out because of the way the claim was framed as a representative action, not because patient data lost its protected status.
  • The practical lesson is to control purpose and scope from the start.
  • If identifiable data is received for one project, avoid letting contracts, internal practice or later expansion quietly widen the use into research, testing or future commercial capability building without clear justification.

Useful next steps

  • Patient-identifiable medical information will normally attract a reasonable expectation of privacy.
  • That starting point does not mean every person in a very large class automatically has the same misuse of private information claim.
  • A representative action can fail if the weakest notional claimant in the class does not have a realistic prospect of success.
  • The court did not decide that the underlying data transfer and use were lawful across the board, and it recognised that valid individual claims might still exist.
  • Businesses handling sensitive data should control purpose, scope, contracts and project expansion, especially where identifiable health data is used for development or future commercial capability building.

The story

This dispute came out of a large transfer of patient-identifiable medical records from the Royal Free London NHS Foundation Trust to Google and DeepMind. The transfer started with a one-off transfer in October 2015 and then continued through a live data feed until 29 September 2017.

The data related to patients who had attended hospitals in the Royal Free Trust or had blood tests processed by Royal Free laboratories between 29 September 2010 and 29 September 2015. The class was said to include about 1.6 million people.

Google and DeepMind used the data in connection with Streams, an app intended to help identify and treat patients suffering from Acute Kidney Injury. But the case was not limited to direct patient care. The court recorded that Google and DeepMind also had a contractual entitlement to use the data for purposes wider than direct patient care and to develop and prove capabilities that could enhance future commercial prospects.

That wider commercial and development angle mattered. Mr Prismall said the defendants wrongfully obtained, stored and used patient-identifiable records on terms that went beyond direct care and beyond the Streams project itself.

Practical sense check

  • The data was patient-identifiable medical information
  • The transfer covered a very large proposed class
  • The alleged uses included storage, research and development, and broader capability building
  • The claim sought damages for loss of control only
  • The case was brought as a representative action rather than as individual claims

What the claim was actually about

The claim did not challenge every use of the data. In particular, it did not concern the use of patient data on Streams in treating patients from February 2017.

Instead, the pleaded case focused on four alleged wrongs. These were obtaining patient-identifiable medical records under an agreement said to be wider than direct patient care and the Streams project, storing the records before Streams became operational, using the records in research and development of Streams, and using the records to develop general capabilities for future commercial prospects.

That distinction is important for businesses. The case was not simply about whether a useful clinical tool existed. It was about what rights were taken over identifiable data, what happened before live deployment, and whether broader development and commercial uses sat outside the narrow purpose that patients might reasonably expect.

Key points

  • Obtaining the records on broad contractual terms
  • Storing the records before operational use
  • Using the records in research and development
  • Using the records to build wider capabilities for future commercial benefit

What the court had to decide

The appeal was mainly about whether this privacy claim could be run as a representative action under CPR 19.8. To use that route, the representative claimant and the people represented must have the same interest.

The parties accepted that, following Lloyd v Google, each member of the class had to have a realistic prospect of succeeding. That meant the court had to test the claim by looking at the weakest notional claimant in the class, described as the lowest common denominator or irreducible minimum scenario.

So the question was not simply whether medical information is private in general. It was whether every person in this very broad class could show the same legally viable misuse of private information claim without individual differences undermining the case.

Practical sense check

  • Did every class member have a realistic prospect of success?
  • Did the whole class have the same interest for CPR 19.8 purposes?
  • Was all patient-related information automatically private for this tort?
  • Did prior publication by a patient affect the privacy analysis?
  • Could loss of control damages be pursued on this class-wide basis?

What the court decided

The Court of Appeal dismissed the appeal. It upheld the order granting reverse summary judgment and striking out the representative claim.

The court accepted the importance of confidentiality in health data and said patient-identifiable information in medical notes will normally attract a reasonable expectation of privacy. But it rejected the broader argument that every item of patient-related information generated in the healthcare relationship will always satisfy the first stage of the tort.

The court said misuse of private information depends on all the circumstances. A relevant factor is the extent to which the information is already in the public domain. If a patient has themselves published equivalent information, that can affect whether there is still a reasonable expectation of privacy in that information for the purposes of the tort.

The court also accepted that there is a minimum threshold of seriousness. Not every disclosure of medical information will automatically be enough. The fact that information appears in a medical record does not, by itself, guarantee that every claimant in a huge class has the same viable claim.

On the facts of this representative action, that was fatal. Because some people in the proposed class could not realistically show the same viable misuse claim, the same interest requirement was not met.

Direct care and the limits of the ruling

One argument on appeal was that the judge had adopted too wide a definition of direct care. The Court of Appeal did not need to settle the exact limits of direct care to decide the appeal.

It noted that the judge had rejected the submission that all of Google and DeepMind’s use was covered by direct care. The judge had found that some, but by no means all, of the alleged wrongful use came within direct care.

For business readers, the practical point is simple. A project can include some uses that look close to service delivery or care, while other uses look more like testing, development, capability building or future commercial exploitation. Those categories should not be blurred together in contracts or governance documents.

Amendments and procedure

Mr Prismall also argued that he should have been allowed to amend the class definition. The Court of Appeal rejected that argument.

The proposed amendments tried to tighten the class by referring to patient-identifiable medical records and to records containing features such as attendance, medical issue, diagnosis, tests or treatment. But the court said that did not solve the main problem. A person could still have published equivalent information themselves, which would undermine the claim that every class member had the same viable privacy case.

The court treated the refusal to allow amendment as a case management decision made for good reasons. It also noted that a narrower route focused only on some parts of the class was not pursued on appeal.

This matters because privacy class actions often rise or fall on procedure as much as substance. A claimant may have a serious complaint, but if the class is too broad and individual circumstances matter, the representative route can fail.

How businesses should read it

The most important business point is that a failed representative claim is not a clean bill of health. The court did not say the underlying data use was lawful across the board. It said this particular class-wide claim could not be proved in the same way for every person in the class.

If your business receives or uses sensitive personal data, especially health data, focus on purpose, necessity and scope. The judgment records allegations about broad contractual rights, storage before operational use, research and development, and capability building for future commercial prospects. Those are exactly the kinds of facts that can create legal and reputational risk.

Businesses often focus heavily on cyber security and access controls. Those still matter, but this case shows that privacy risk also comes from purpose creep. The question is not only whether data was kept safe. It is also whether the organisation was entitled to receive it, store it, test with it and use it for wider development goals.

Practical sense check

  • Map every purpose for which identifiable data is received and used
  • Separate direct care or core service delivery from product development and experimentation
  • Check whether contracts grant wider rights than your approvals, notices or governance assume
  • Record why identifiable data is necessary instead of de-identified, synthetic or more limited data
  • Review whether a project has expanded beyond its original purpose
  • Limit access to identifiable data on a strict need-to-know basis
  • Keep a clear audit trail for testing, development and capability-building uses

Documents and conduct that can create risk

This case is a reminder that privacy disputes are often built from documents as much as from technical systems. The court referred to an information sharing agreement, a memorandum of understanding, ethics approval material, regulatory investigation and later correspondence about the project’s scope.

For businesses, that means risk can appear in ordinary project paperwork. A contract that quietly allows broader use than the public-facing purpose statement, or a collaboration document that points to future commercial capability building, can become central in a later dispute.

Good governance is not just about having a privacy policy. It is about making sure the contract, the project plan, the testing plan, the approvals and the actual data use all say the same thing.

Risk points

  • Information sharing agreements
  • Statements of project purpose
  • Testing and safety documentation
  • Research or ethics approval applications
  • Memoranda of understanding and collaboration documents
  • Internal records showing when live operational use began
  • Records explaining why identifiable data was needed

Key points for privacy disputes

If your business faces a privacy complaint, this case shows that the shape of the claim matters. A claimant may struggle to run a representative action where privacy depends on individual circumstances, including what information was involved, how sensitive it was, whether it was already public, and what effect the use had.

But that procedural difficulty should not be confused with low substantive risk. The court accepted that valid individual claims might still exist. In practice, a business can still face individual litigation, regulatory attention, contractual disputes and reputational damage even if a mass representative claim fails.

That is why the safest reading of this case is cautious. It is not a licence to stretch data use. It is a warning that sensitive-data projects need disciplined purpose control from the outset.

Common questions

Why did the representative claim fail?

It failed because the court said the whole class did not have the same viable claim. In a representative action under CPR 19.8, every class member must have the same interest. The parties accepted that each person in the class had to have a realistic prospect of success. The court therefore tested the claim by looking at the weakest notional claimant, called the lowest common denominator. Because some people in the class might not have a reasonable expectation of privacy in the same way, the claim could not proceed for everyone together.

Did the court say the data transfer and use were lawful?

No. The court was careful not to decide that broader question. It said this judgment was not about whether there were valid claims that could be brought by patients whose records were transferred. The submissions proceeded on the basis that, subject to limitation issues, such claims might be brought and might succeed.

Did the court accept that medical information is private?

Yes, as a starting point. The court said patient-identifiable information in medical notes will normally attract a reasonable expectation of privacy and stressed the importance of confidentiality in health data. But it rejected the idea that every item of patient-related information generated in the healthcare relationship will always satisfy the tort without looking at the circumstances.

Why did public disclosure by a patient matter?

Because misuse of private information depends on all the circumstances, including whether the information is already in the public domain. The court accepted that if a patient had themselves published equivalent information, that could affect whether there was still a reasonable expectation of privacy in that information for the purposes of the tort.

What should businesses handling sensitive data take from this case?

The main lesson is procedural and operational. Procedurally, large privacy claims are harder to run where individual circumstances differ. Operationally, businesses should not rely on that difficulty as protection. If you use identifiable health data, keep purposes narrow, document necessity, separate direct care from wider development work, and make sure contracts do not quietly authorise broader uses than your governance expects.

Related topics

How Sprintlaw can help