03/02/2020 CG v Facebook Ireland Ltd & Anor [2016] NICA 54 (21 December 2016) applicable law test because of the risk that the data subject might be left unprotected and the effectiveness of the Directive would be compromised. [90] We do not accept the latter submission. The decision in Weltimmo built upon the jurisprudence developed by the ECJ in Google Spain and supports the conclusion that the Directive has a particularly broad territorial scope and should not be interpreted restrictively. The evidence indicates that Facebook (UK) Ltd was established for the sole purpose of promoting the sale of advertising space offered by Facebook the effect of which is to make the service offered more profitable. It conducts its activities within the United Kingdom and is responsible for engaging with those within this jurisdiction who seek to use the Facebook service for advertising. It holds relevant data which it processes on behalf of Facebook in respect of advertising customers. There is no direct evidence of its connection with Facebook but there is an irresistible inference in the absence of any further explanation that Facebook (UK) Ltd was established to service Facebook and is part of the wider Facebook group of companies. [91] We are satisfied, therefore, that Facebook (UK) Ltd plainly engages in the effective and real exercise of activity through stable arrangements in the United Kingdom and having regard to the importance of those activities to Facebook’'s economic enterprise the processing of data by Facebook was carried out in the context of the activities of that establishment. Facebook is, therefore, a data controller for the purposes of section 5 of the 1998 Act. [92] The only remaining issue is whether Regulation 19 of the 2002 Regulations which exempts an ISS which consists of the storage of information provided by a recipient of the service operates to relieve Facebook of liability for damages under the 1998 Act in the absence of actual knowledge of unlawfulness or facts and circumstances from which it would have been apparent that the activity or information was unlawful. It was common case that the claim under the 1998 Act would not add to damages payable in respect of misuse of information. This issue arises, therefore, in respect of the entitlement to damages for the postings and comments on the McCloskey profile page and any postings and comments on the RS page prior to 26 November 2013. [93] In support of the submission that the e-Commerce Directive did not limit the entitlement to damages under the 1998 Act Mr Tomlinson pointed first to the fact that Article 1(5) of the eCommerce Directive which defined its objective and scope stated that it would not apply to questions relating to information society services covered by Directives 95/46/EC and 97/66/EC. These are the Directives dealing with data protection. [94] This is mirrored by Regulation 3 of the 2002 Regulations which provides that nothing in the Regulation shall apply in respect of questions relating to information society services covered by the Data Protection Directive and the Telecommunications Data Protection Directive and Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector. Mr Tomlinson also relies upon recital 14 of the e-Commerce Directive which records that the aforesaid Directives already establish the Community legal framework in the field of personal data. [95] We accept all of that but the starting point has to be the matter covered by the e-Commerce Directive which is the exemption for information society services from the liability to pay damages in certain circumstances. The provisions do not interfere with any of the principles in relation to the processing of personal data, the protection of individuals with regard to the processing of personal data or the free movement of such data. The provisions do, however, provide a tailored solution for the liability of information society services in the particular circumstances outlined in the eCommerce Directive. We do not consider that this is a question relating to information society services covered by the earlier Data Protection Directives and accordingly do not accept that the scope of the exemption from damages is affected by those Directives. Regulation 3 of the 2002 regulations must be read accordingly. Conclusion [96] We find that Facebook are liable to the respondent in damages for misuse of private information for the period from 26 November 2013 until 4/5 December 2013 in respect of the first www.bailii.org/nie/cases/NICA/2016/54.html 20/21

Select target paragraph3