Part 03 · Foundations
Data protection and the judgments
Employment Tribunal judgments are public, but they are full of personal data. How I have approached holding, analysing and publishing from 134,000 of them.
Employment Tribunal judgments are published so that anyone can see how the tribunal reaches its decisions. They are also full of personal information about claimants, managers and witnesses, much of it sensitive. Holding a complete copy of the register, analysing it and publishing what the analysis finds is processing of personal data, and the fact that the tribunal has already published the judgments does not take it outside data protection law. This article sets out how I have approached that.
Public, but still personal data
The register is published under the Open Government Licence, but the licence expressly excludes personal data. It deals with reuse as a matter of copyright, not data protection.
Discrimination claims turn on protected characteristics, so judgments routinely record a claimant’s disability and its effects, their religion, sexual orientation or ethnic origin, and the medical evidence about how the treatment affected them. Across 134,000 judgments, that is special category data on a large scale, and a systematic project with published results is not a purely personal activity. Open justice is a strong reason why processing the judgments is lawful and fair, but it has to be applied through the legislation rather than around it.
The basis for processing
I rely on legitimate interests (Article 6(1)(f) UK GDPR). Understanding how the tribunal decides cases, and making that available to practitioners and to claimants who represent themselves, is consistent with the purpose for which judgments are published. The analysis cannot be done without the judgments, the people named in them can reasonably expect them to be read, cited and analysed, and nothing in the project leads to a decision about any individual.
For special category data, the condition is research in the public interest (Article 9(2)(j), with paragraph 4 of Schedule 1 to the Data Protection Act 2018), subject to the research safeguards in Chapter 8A of the UK GDPR as amended by the Data (Use and Access) Act 2025: the processing must not be likely to cause substantial damage or distress, and must not be used to take measures or decisions about particular individuals. Neither is a feature of this project. Articles that discuss individual cases are published for journalistic and academic purposes, within the exemption for the special purposes in paragraph 26 of Schedule 2 to the 2018 Act.
Safeguards
Four features of the project keep the processing proportionate.
- The judgments stay on one computer. The models that analyse them run on the same machine, and the collection is not held in cloud storage.
- The collection follows the register. Judgments are occasionally withdrawn, or replaced with anonymised versions following a privacy order. Anything withdrawn from the register is deleted from the collection and from every index and dataset built on it, and anything replaced is downloaded again. That check is being built into the update run, and the handful of judgments withdrawn since the collection was made are being removed.
- Figures are checked. Every extracted figure is verified against the text of the judgment, doubtful results are set aside, and corrections are invited.
- The processing has been assessed. Large-scale processing of special category data requires a data protection impact assessment, and one has been carried out.
Publishing from the data
The awards viewer, described later in the series, lists each injury to feelings award with the case name, the protected characteristic, the band and amount, and a short note of the tribunal’s reasons. I have kept the case names. Decisions are identified by them in the register, the law reports and the commercial databases, and a practitioner needs the name to find and check the decision.
The risk lies in the compilation rather than any single entry: a list that places a name beside a protected characteristic and the effect the treatment had. Three measures address it, and they follow the practice of the established free-law services. The viewer is excluded from search engines, so a search for a claimant’s name online will not lead to it, although it can be searched from within the page. The reasons are confined to the legal factors that set the level of the award, such as the duration of the conduct, the severity of its effect and the consequences for the claimant’s work, rather than details of medical conditions or personal circumstances. And the viewer follows the register: a judgment removed or anonymised on GOV.UK is removed or anonymised in the viewer at the next update.
Telling people
Where personal data is obtained from a source other than the individual, the controller must normally tell each person concerned. With many thousands of people named across the register, that would be disproportionate, and Article 14(5)(b) allows the information to be made publicly available instead. The site’s privacy notice does that: what is held, why, for how long, and how anyone named in a judgment can ask for a correction or removal.
Doing this yourself
- Treat the collection as personal data from the start, and write down your lawful basis and Article 9 condition before you begin.
- Keep the processing local where you can, and check that working folders are not synchronised to cloud storage.
- Build removals into your updates. A collection that is never refreshed drifts away from the register and keeps judgments the tribunal has withdrawn.
- Think separately about what you hold and what you publish. The case for analysing the judgments is not automatically a case for republishing everything in them.
Next: how the AI comparison will be run, and why the method is published first.