Selected cases

High Court of Justice · [2020] EWHC 1812 (QB)

Aven & Ors v Orbis Business Intelligence Ltd

For businesses, the lasting lesson is that purpose matters, but so does the quality of your checking process.

High Court of Justice8 July 2020

Plain-English explainers, not legal advice. Use the linked official source for section-level detail, and get advice for your situation.

Get legal help

Start here

Quick read

  • If your business commissions or produces investigation reports, do not assume that a legal dispute, client confidentiality or a public-interest concern gives you a free...
  • Aven & Ors v Orbis Business Intelligence Ltd is a useful UK data protection case for businesses that prepare or commission investigation reports about individuals.

Use this to check

  • A business report can be regulated as personal data processing if it contains information about identifiable people.
  • Legal-purpose and national security arguments do not automatically remove all data protection duties.
  • The court may accept reasonable verification for some intelligence points but still find liability for a more serious allegation.

Decision snapshot

  1. What happened

    • The dispute arose from one memorandum within the well-known Steele Dossier.
    • Orbis Business Intelligence Ltd, an English company providing intelligence and investigative services, had been instructed in 2016 by a Washington DC consultancy to produce intelligence memoranda about possible links between Russia, President Putin and Donald Trump.
    • One memorandum, dated 14 September 2016 and referred to as Memorandum 112, discussed the relationship between Alfa Group and President Putin and named Petr Aven, Mikhail Fridman and German Khan.
    • The memorandum included several allegations, including that significant favours were done in both directions between Putin and Alfa figures, that Aven and Fridman gave informal advice to Putin on foreign policy, that Fridman had recently met Putin directly, that Aven and Fridman had used Oleg Govorun to deliver large amounts of illicit cash to Putin in the...
  2. What the court had to decide

    • The legal issue was whether Orbis’ creation and disclosure of Memorandum 112 breached the Data Protection Act 1998.
    • That required the court to decide what parts of the memorandum were personal data about the claimants, whether the allegation about illicit cash was sensitive personal data alleging criminality, whether exemptions for legal purposes and national security applied, whether the processing was fair and lawful, and whether the data were inaccurate or misleading.
  3. What the court decided

    • The court held that the memorandum did contain personal data about the claimants and that the allegation about delivering illicit cash amounted to sensitive personal data about alleged criminality.
    • It accepted that some exemptions applied, including the legal purposes exemption for the disclosure to the Washington consultancy and exemption from notice requirements for the national security disclosures.
    • The court also found no breach of the first data protection principle.

Practical impact

Practical read

  • If your business commissions or produces investigation reports, do not assume that a legal dispute, client confidentiality or a public-interest concern gives you a free pass on data protection.
  • The court drew a line between broad intelligence points that had been reasonably checked for the purpose they served, and a much more serious allegation of criminal wrongdoing that needed stronger verification.
  • That distinction matters in practice.
  • The more serious, old, specific or damaging the allegation, the more checking is likely to be expected before you store or share it.

Useful next steps

  • A business report can be regulated as personal data processing if it contains information about identifiable people.
  • Legal-purpose and national security arguments do not automatically remove all data protection duties.
  • The court may accept reasonable verification for some intelligence points but still find liability for a more serious allegation.
  • Allegations of criminal conduct are especially risky and may be treated as sensitive personal data.
  • Keep clear records of purpose, verification and disclosure decisions if your business handles investigation reports.

The story

This case was about an intelligence memorandum, not a customer database or marketing list. But the court treated the report as a data protection problem because it contained information about identifiable individuals and had been processed and disclosed by a business.

Orbis prepared Memorandum 112 as part of a wider intelligence exercise. The memorandum referred to three businessmen connected with Alfa Group and made a series of allegations about their relationship with President Putin. After the dossier became public through BuzzFeed, the individuals named in the memorandum brought a claim under the Data Protection Act 1998.

The claim focused on whether the memorandum contained their personal data, whether some of that data were sensitive because they alleged criminality, whether Orbis had processed the data fairly and lawfully, and whether the allegations were accurate or had been checked properly before disclosure.

Practical sense check

  • A report can be personal data if it says things about identifiable people
  • Private intelligence work can still fall within data protection rules
  • Publication by someone else does not erase the original handler’s duties
  • Serious allegations need stronger checking than vague or lower-level claims

What the court decided

The court took a contextual, practical approach to the memorandum. It rejected an overly atomised reading of the report and treated it as a coherent narrative when deciding whether it contained personal data about the claimants. It also held that the allegation about delivering illicit cash amounted to sensitive personal data because it alleged criminality.

On exemptions, the court accepted that the disclosure to the Washington consultancy fell within the legal purposes exemption. It also accepted that the purpose of national security required exemption from the notice requirement for the national security disclosures. But those findings did not end the case.

The court found that the claimants had proved the personal data complained of were inaccurate or misleading as matters of fact. Even so, Orbis avoided breach of the accuracy principle for most of the allegations because it had accurately recorded third-party information and had taken reasonable steps to verify those points in light of the limited purposes of the report. The exception was the illicit cash allegation. For that allegation, the court held that Orbis had not taken reasonable enough steps to verify it.

Why one allegation created liability

The court drew a clear distinction between different kinds of statements in the memorandum. It considered the allegations about favours, foreign policy advice, a recent meeting and political bidding to be broad, factual propositions that were less grave and more credible on their face in the context of the report. For those, the court accepted that Orbis had taken reasonable steps for the purposes in question.

The allegation about using an intermediary to deliver large amounts of illicit cash to Putin in the 1990s was different. The court described it as an allegation of serial criminal wrongdoing over a prolonged period. It was older, more specific and much more serious than the other points. Because of that gravity, the court expected closer attention, more energetic checking and a more enquiring approach.

On the evidence, Orbis had not done enough. The judge was not persuaded that the verification effort for that allegation met the required standard. That failure meant a breach of the fourth data protection principle was established for that allegation, even though other parts of the memorandum survived challenge.

Type of allegationCourt's viewPractical lesson
Broad intelligence pointsReasonable steps accepted in contextContext and purpose matter, but keep records of checks
Serious criminal allegationVerification steps were not enoughHigher-risk allegations need stronger evidence and scrutiny
Sensitive personal dataTreated with added seriousnessEscalate review where criminality is alleged

How to read this for your business

This decision matters if your business gathers, writes, stores or shares allegations about people as part of due diligence, investigations, disputes, fraud reviews, sanctions screening, workplace investigations or political risk work. The court did not say that intelligence businesses cannot handle uncertain information. It did say that purpose and context do not excuse weak checking of serious allegations.

In practice, the standard of checking should rise with the seriousness of the claim, the age of the events, the specificity of the allegation and the likely harm if the information is wrong. If you are handling allegations of bribery, fraud, money laundering or other criminal conduct, you should expect a much more disciplined process than for lower-level background intelligence.

The case also shows the value of documenting why a disclosure was necessary, who received it and what verification was done. If your business cannot later explain those steps, it may struggle to defend the processing even where the overall project had a legitimate purpose.

Practical sense check

  • Identify whether the report contains personal data about living individuals
  • Flag any allegation of criminality as higher-risk material
  • Match the level of verification to the seriousness of the allegation
  • Record the purpose of the report and each disclosure
  • Limit circulation to people who genuinely need the information
  • Keep a note of any challenge to accuracy and how it was handled

Operating checklist

If your business uses investigators or prepares sensitive reports, build a process that can withstand later scrutiny. This case is a reminder that courts look closely at what was actually done, not just at the label attached to the project.

A practical workflow should separate ordinary background intelligence from serious allegations, especially allegations of criminal conduct. It should also make clear who signs off on disclosure and what evidence supports the most damaging statements.

Common questions

Does this case mean investigation reports are always covered by data protection law?

Not always in every form, but this case confirms that where a report contains information relating to identifiable living individuals, it can amount to personal data and the handling of it can be regulated by data protection law.

Did the court say legal or national security purposes remove all data protection duties?

No. The court accepted some exemptions in relation to notice requirements and legal-purpose processing, but it did not accept that those purposes wiped out all accuracy obligations in the circumstances of this case.

Why was one allegation treated differently from the others?

Because the allegation about delivering illicit cash was a much more serious accusation of criminal wrongdoing over a long period. The court said that level of allegation called for closer checking than the broader and less grave points in the memorandum.

What should a business do before sharing allegations about a person?

Be clear about why the information is needed, whether the person is identifiable, what lawful basis applies, how serious the allegation is, what checks have been done, who really needs to receive it and how you will record any challenge to accuracy.

Related topics

How Sprintlaw can help