
Veronica Chu
4/27/23
A Decathlon member's personal data was allegedly leaked, resulting in the member becoming the victim of a fraud scam. The member subsequently filed a lawsuit seeking damages. In the first-instance judgment, the court held that Decathlon was only liable for 10% of the claimed damages.
Decathlon allegedly suffered a membership data breach in April 2022. A member claimed that, following the incident, the member received phone calls from fraudsters pretending to be Decathlon employees, requesting the member to cancel an installment payment arrangement. As a result, the member was defrauded of more than NTD 500,000 and filed a lawsuit against Decathlon seeking compensation for the losses.
Decathlon argued that the personal data had not been leaked from its systems. The company also stated that it had taken appropriate response measures after the incident and had warned its members to be vigilant against fraud.
After reviewing the case, the court found that the timing of the member's fraud coincided with the timing of the alleged personal data breach. The court held that Decathlon's mere denial, without supporting evidence, was insufficient. The court further found that Decathlon had failed to implement appropriate security measures as required under Article 27, Paragraph 1 of the Personal Data Protection Act, and was therefore negligent.
However, the court also found that the member was contributorily negligent. The plaintiff was a lawyer and should have possessed a sufficient ability to identify and verify the authenticity of the phone calls. Nevertheless, after receiving the fraudulent calls, the plaintiff transferred substantial sums of money to the fraudsters over a period of seven hours. The court considered this to constitute contributory negligence.
Accordingly, the court ruled that Decathlon was only required to compensate the member for one-tenth of the claimed damages. The judgment may still be appealed.
Under Article 29 of the Personal Data Protection Act, where a non-government agency violates the Act, causing personal data to be unlawfully collected, processed, used, or otherwise infringing upon the rights of a data subject, it shall be liable for damages. However, no liability shall arise if the agency can prove that it was not intentional or negligent.
Accordingly, who bears the burden of proving whether the personal data was leaked by the business that collected and used the data? In this case, the court held that the defendant could not rely solely on a simple denial as its defense. In addition, the business must provide evidence demonstrating that it had adopted appropriate security measures in accordance with the Personal Data Protection Act in order to avoid liability.
The court also took into account the plaintiff's knowledge, profession, and social background in determining whether the plaintiff was contributorily negligent, and adjusted the allocation of liability between the parties accordingly.
News Source: