The Common Law Duty of Confidentiality

The Common Law Duty of Confidentiality is a key principle that underpins trust in many professional and personal relationships. It serves as a crucial element in maintaining discretion and privacy across various sectors. Therefore it ensures that sensitive information is not misused or improperly disclosed. In essence, the duty of confidentiality protects individuals and entities from having their confidential matters revealed to unauthorised parties. Over the centuries, this duty has evolved, adapting to the changing needs of society. It remains a core principle: safeguarding private information.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

Contents

What is the Common Law?

Common law is a legal system that derives its authority from judicial decisions rather than from legislative acts. This means that judges’ rulings in previous cases (precedents) serve as a basis for deciding future cases with similar legal issues.

Key characteristics of common law:

  • Precedent-based: Judges are bound by the doctrine of stare decisis. This means they must follow the decisions of higher courts in previous cases.

  • Flexibility: While rooted in precedent, common law is not entirely rigid. Judges can adapt and modify existing law to fit new circumstances or changing societal values.

  • Evolutionary: Common law is a living system that evolves over time through judicial decisions.

  • Used in many countries: Common law is the primary legal system in many countries. These include the United Kingdom, the United States, Canada, Australia, and India.

In contrast to civil law systems, which are based on comprehensive legal codes, common law systems rely on judicial interpretation and precedent to develop and apply the law.

What is Confidentiality?

Confidentiality refers to the obligation to keep information private and secure. It ensures that sensitive information is not disclosed to unauthorised individuals or entities.

In various contexts, confidentiality can have specific meanings:

  • Medical Confidentiality: Doctors and healthcare providers have a duty to protect their patients’ personal medical information.

  • Legal Confidentiality: Attorneys have a duty to maintain confidentiality with their clients.

  • Business Confidentiality: Companies often have policies in place to protect trade secrets, proprietary information, and customer data.

  • Data Privacy: Organisations have a responsibility to protect the personal data of individuals.

The principles of confidentiality are essential for building trust, protecting individuals’ rights, and maintaining the integrity of sensitive information.

Origins of the Duty of Confidentiality

The roots of the duty of confidentiality in common law stretch back to ancient legal traditions, where keeping secrets was considered a moral obligation. As early as the Middle Ages, the courts recognised that certain relationships required a heightened sense of discretion. These early precedents laid the groundwork for what would become a formalised legal doctrine, evolving through judicial decisions and statutory law.

Key Principles of Common Law Confidentiality

At its core, the common law duty of confidentiality revolves around three main principles:

  • the expectation of confidence,
  • the relationship between the parties, and
  • the unauthorised disclosure of information.

The first principle asserts that when private information is shared in a context where confidentiality is expected, a duty arises.

The second focuses on the nature of the relationship, such as those of professionals who inherently owe a duty of trust to their clients or patients.

Lastly, the third principle dictates that disclosing information without consent or lawful excuse constitutes a breach of this duty.

The Scope of Confidentiality Obligations

The duty of confidentiality applies broadly, not just to explicit agreements but also to implied understandings between parties. It extends beyond formal contracts to encompass a wide range of relationships.

Professionals such as doctors, lawyers, and financial advisors are most commonly associated with this duty. However, the obligation also applies to anyone who receives confidential information in a situation where trust is reasonably expected. Thus, it is not only professionals but also employers, contractors, and even friends who may find themselves bound by this duty in certain circumstances.

Exceptions to the Duty of Confidentiality

While the duty of confidentiality applies broadly, it is not absolute. Certain situations necessitate a breach of this duty, such as when disclosure is mandated by law or in the interest of preventing harm. One common exception is when there is a compelling public interest that overrides the need for confidentiality. Additionally, disclosures may be permissible when consent is explicitly given, or when the information is already in the public domain. Understanding these exceptions is crucial for both professionals and individuals to navigate the boundaries of confidentiality responsibly.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

Confidentiality in Professional Relationships

Professional relationships are often the most scrutinised in terms of confidentiality. In law, the attorney-client privilege serves as a cornerstone for ensuring that clients can speak freely with their lawyers without fear of sensitive information being exposed. Similarly, in the medical field, the doctor-patient relationship is underpinned by strict confidentiality obligations, which are vital for maintaining patient trust and encouraging full disclosure of health concerns. In business, confidentiality agreements ensure that trade secrets and proprietary information remain secure.

The Common Law Duty of Confidentiality in Medical Settings

The common law duty of confidentiality for medical professionals is a fundamental ethical and legal obligation to protect patient information. This duty extends to all aspects of patient care, including:

  • Medical records: Doctors, nurses, and other healthcare providers must maintain the confidentiality of patient medical records. This includes electronic records, paper records, and any other information that can be used to identify a patient.

  • Conversations: Any conversations between patients and healthcare providers, whether in person, by phone, or through electronic means, are considered confidential.

  • Third-party disclosures: Healthcare providers must obtain explicit consent before disclosing patient information to third parties, such as insurers, family members, or other healthcare providers.

Breaching the duty of confidentiality can have serious consequences, including:

  • Legal action: Healthcare providers who breach confidentiality may face legal action from patients or regulatory bodies.

  • Loss of trust: Breaches of confidentiality can erode trust between patients and healthcare providers.

  • Reputational damage: A breach of confidentiality can damage the reputation of the healthcare provider and the organisation they work for.

As noted above the common law duty of confidentiality is not absolute. In certain circumstances, such as when there is a risk of harm to the patient or others, healthcare providers may be justified in disclosing confidential information. However, any disclosure must be necessary and proportionate to the risk involved.

To ensure compliance with the common law duty of confidentiality, healthcare organisations should have clear policies and procedures in place for handling patient information. These policies should address issues such as data security, access controls, and the disclosure of information to third parties. They also need to be mindful of the privacy risks arising from sharing data for research purposes or public health monitoring.

Confidentiality for Solicitors and Barristers

The common law duty of confidentiality for solicitors and barristers is a fundamental ethical obligation that requires them to protect the confidential information of their clients. This duty is rooted in the principles of legal privilege and professional ethics.

Key aspects of the duty of confidentiality for solicitors, barristers and those working with them:

  • Client-attorney privilege: This is a fundamental legal principle that protects communications between solicitors and their clients from disclosure to third parties. It ensures that clients can seek legal advice without fear of their communications being revealed.

  • Scope of confidentiality: The duty of confidentiality extends to all information communicated between a solicitor and client, including:

    • Facts and circumstances of the case

    • Legal advice given

    • Documents exchanged

    • Any other information shared in the course of the solicitor-client relationship

  • Exceptions: There are limited exceptions to the duty of confidentiality, such as:

    • Client consent: The client may explicitly consent to the disclosure of confidential information.

    • Legal obligation: Solicitors may be required to disclose confidential information to comply with a court order or other legal obligation.

    • Prevention of crime: In exceptional circumstances, solicitors may be justified in disclosing confidential information to prevent a serious crime.

Breaching Confidentiality

Breaching the duty of confidentiality can have serious consequences including:

  • Disciplinary action: The legal profession has strict disciplinary procedures for breaches of confidentiality.

  • Civil liability: Solicitors may be liable for damages if their breach of confidentiality causes harm to their client.

  • Criminal liability: In some cases, a breach of confidentiality may constitute a criminal offense.

To ensure compliance with the duty of confidentiality, solicitors and barristers must:

  • Implement security measures: Protect client information from unauthorised access or disclosure.

  • Train staff: Educate staff on the importance of confidentiality and the consequences of breaches.

  • Review policies: Regularly review and update policies related to confidentiality.

By upholding the duty of confidentiality, solicitors and barristers can foster trust with their clients and ensure the effective delivery of legal services.

Entering into a contract to process personal data

The Common Law Duty of Confidentiality in Business

The common law duty of confidentiality in business can arise from contractual relationships, fiduciary duties, or implied terms of good faith.

Key aspects of the duty of confidentiality in business:

  • Scope of confidentiality: The duty extends to any information that is considered confidential, including trade secrets, customer data, financial information, and intellectual property.

  • Confidentiality agreements: Businesses often require employees, contractors, and business partners to sign confidentiality agreements that outline the specific obligations to protect sensitive information.

  • Reasonable steps: Businesses must take reasonable steps to protect confidential information from unauthorised access, disclosure, or misuse.

  • Exceptions: There may be limited exceptions to the duty of confidentiality, such as when disclosure is required by law or to prevent harm.

Breaching the duty of confidentiality can have serious consequences for businesses, including:

  • Legal action: Businesses may face legal action from customers, employees, or business partners who have suffered harm due to a breach of confidentiality.

  • Financial loss: Breaches can lead to financial losses, such as lost revenue, damage to reputation, and increased costs associated with legal proceedings.

  • Regulatory penalties: Businesses may be subject to fines or other penalties if they violate data protection laws or other regulations related to confidentiality.

To ensure compliance with the common law duty of confidentiality, businesses should:

  • Implement security measures: Protect confidential information from unauthorised access, disclosure, or misuse.

  • Train employees: Educate employees about the importance of confidentiality and the consequences of breaches.

  • Review policies: Regularly review and update policies related to confidentiality.

  • Conduct due diligence: When dealing with third-party suppliers or partners, conduct due diligence to ensure they have adequate confidentiality measures in place.

By understanding and complying with the common law duty of confidentiality, businesses can protect their sensitive information, maintain trust with stakeholders, and mitigate the risks associated with breaches.

The Interaction Between Confidentiality and Privacy Laws

The common law duty confidentiality overlaps with privacy laws, such as the GDPR and Data Protection Act. While confidentiality arises from the trust inherent in relationships, privacy laws typically focus on the individual’s right to control personal information. Although both serve to protect private information, privacy laws can sometimes override confidentiality obligations, particularly when regulatory frameworks impose stricter standards for the handling of personal data. The interplay between these two legal concepts often requires careful consideration, especially in professional and corporate settings.

Key Case Law

Several cases have shaped the legal landscape of confidentiality.

One notable case is Attorney General v. Guardian Newspapers Ltd (No 2). This case was based on whether an author could publish works that contained information relevant to the national interest, where sharing it could cause harm to those interests. The outcome hinged on the extent to which the information concerned was already in the public domain.

Another case is Campbell v. MGN Ltd, which considered how far a reasonable expectation of privacy could restrict journalistic freedom of expression. It was noted that a duty of confidence arises wherever the defendant knows or ought to know that the claimant can reasonably expect their privacy to be protected

These cases, along with others, illustrate how courts have interpreted and applied the duty of confidentiality in diverse contexts, often balancing competing interests between privacy and public accountability.

The Role of the Public Interest in Confidentiality

The public interest often plays a pivotal role in determining whether a breach of confidentiality is justified. In cases where maintaining confidentiality could shield wrongdoing or pose a threat to public safety, courts may find that the public’s right to know outweighs the duty of confidentiality.

Whistleblowing, for example, is a scenario where the public interest may override confidentiality obligations, allowing individuals to disclose information about corporate or governmental misconduct without fear of legal repercussions. However, the threshold for such disclosures is high, and the courts typically assess them on a case-by-case basis.

Consequences of Breaching Confidentiality

The ramifications of breaching confidentiality can be severe, both legally and professionally. Legal consequences may include injunctions, damages, or other remedies, depending on the severity of the breach. In addition to these legal penalties, individuals or organisations that violate confidentiality often suffer reputational damage, which can erode trust and result in the loss of clients or business opportunities. For professionals, breaching confidentiality can lead to disciplinary action from regulatory bodies, including suspension or revocation of licenses, further compounding the damage caused by the initial breach.

The common law duty of confidentiality is a fundamental aspect of legal and professional practices, safeguarding the trust placed in sensitive relationships. While exceptions exist, the core principles remain focused on protecting private information, ensuring that it is disclosed only when absolutely necessary or permitted by law.

Note: like all articles on this site this content is for information and is not a substitute for professional legal advice based on your own circumstances.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial