R (The Pensions Regulator) v Workchain Ltd [2019] EWCA Crim 1422
- Summary
- Citing
- Cited By
R (The Pensions Regulator) v Workchain Ltd [2019] EWCA Crim 1422 concerned an appeal by a recruitment company against a fine of £200,000 imposed following a conviction for unauthorised access to computer material contrary to section 1 of the Computer Misuse Act 1990. The Court of Appeal (Lord Justice Hickinbottom, Mr Justice Edis and HHJ Marson QC sitting) allowed the appeal and reduced the fine to £100,000.
Workchain Limited pleaded guilty at the magistrates’ court to unlawfully accessing the NEST online pension system in order to opt out employees from the workplace pension scheme to which it was required by the Pensions Act 2008 to enrol them. Seven individuals (the two directors and shareholders Philip Tong and Adam Hinkley, financial controllers Hannah Armson and Lisa Neal, and branch managers Martin West, Robert Tomlinson and Andrew Thorpe) also pleaded guilty. All eight defendants were committed to the Crown Court at Derby for sentence.
The facts showed that Workchain’s staging date for automatic enrolment under the 2008 Act was 1 May 2014. The Act required employers to enrol eligible workers into a pension scheme without consulting them, with both employer and employee making contributions. Workers could opt out within one month of enrolment, avoiding any obligation to contribute. NEST, the statutory workplace pension scheme, required each worker to opt out personally using a unique NEST ID number; employers were not permitted access to employee data. This was a design feature intended to prevent employers pressuring workers to opt out and to save the employer contributions which would otherwise be payable.
From an early stage, Tong, Hinkley and Armson were determined to opt out Workchain’s employees. On 28 April 2014 Armson sent branch managers a list of temps due to be enrolled with NEST’s telephone number. Tomlinson immediately instructed his recruiting staff to “phone NEST and opt out on behalf of the temp by pretending to be that temp,” warning that failure to do so would affect their margins as the company’s contributions came off margins. On 6 May 2014, five calls were made to NEST by Tomlinson and a consultant, falsely purporting to be temps requesting NEST IDs. Those IDs were then used to opt out workers via the NEST online service. The Derby and Nottingham branches continued this practice. By 11 June 2014, 102 out of 155 enrolled workers (66 per cent) had opted out, compared with the usual opt-out rate of eight per cent. Of the 102 opt-outs, 90 were carried out online, and 67 of those originated from Workchain’s IP address. From early June 2014, once the workers employed in May had been dealt with, Workchain complied fully with the scheme in respect of all new employees.
Tong, Hinkley and Workchain initially submitted a basis of plea asserting low culpability and claiming they had not instructed unlawful steps but had merely failed to supervise staff. Judge Shant QC adjourned sentence for a Newton hearing. At that hearing, however, they accepted the prosecution case that Workchain through its directors had instructed managers and staff to do whatever was necessary to secure opt-outs. A revised basis of plea acknowledged responsibility on a joint enterprise basis and for creating “an atmosphere whereby these activities took place,” though it maintained that Tong and Hinkley were unaware of the impersonation calls. The prosecution and the court accepted this revised basis.
Judge Shant correctly found culpability to be high. She accepted the agreed immediate loss figure of approximately £3,000, but stated that the prosecution’s estimate of £35,000 to £50,000 over time had not been agreed and the defence put it lower. The judge considered that the real harm was not financial but damage to public confidence in the workplace pension system and the credibility of the security in data held. She referred to the approach in the Sentencing Council’s Environmental Offences guideline, as applied in R v Thames Water Utilities Limited [2015] EWCA Crim 960, that financial orders must have a real economic impact to bring home to management and shareholders the need to improve regulatory compliance. Evidence showed shareholder funds of up to £1.5 million in 2016–17 and regular profits before tax of £600,000 to £800,000 per year. The judge found the company remained in good financial health and could bear a substantial penalty. She also took into account that Workchain had been previously compliant and had been in full compliance since the investigation began in 2015. She sentenced Tong and Hinkley each to four months’ imprisonment suspended for two years, 200 hours community service and £11,250 costs; Armson and Neal each to two months suspended for two years and £1,500 costs; and West, Tomlinson and Thorpe each to a two-year community order and £500 costs. None appealed. Workchain was fined £200,000, plus costs of £60,930 and the victim surcharge. Workchain appealed against the fine with the leave of Sir Alistair MacDuff.
On appeal, Mr Kevin Hegarty QC advanced five grounds. First, that the judge failed to have regard to the Sentencing Guideline on Corporate Offenders: Fraud, Bribery and Money Laundering. Lord Justice Hickinbottom rejected this ground. He held that the focus of section 1 of the 1990 Act was unauthorised access to programmes or data and did not require proof of dishonesty or any particular intent. Financial loss was a relevant category of harm but unauthorised access also caused loss of confidence in the integrity of the computer system, which was a crucial head of harm in this case, particularly given the statutory scheme expressly prohibited employers accessing employee pension data. The fraud guideline’s assessment of harm by reference only to financial sums and a culpability multiplier was not sufficiently analogous.
The second ground was that the judge had failed to give credit for Workchain’s guilty plea. The parties agreed that, having pleaded guilty at the first appearance but accepted high culpability only at the Newton hearing, a discount of 20 per cent was appropriate. Lord Justice Hickinbottom held that the judge had erred in not giving such credit and allowed the appeal on that basis alone.
The third ground was the failure to credit the spontaneous cessation of offending from early June 2014 and subsequent compliance. The fourth was the failure to calculate or state the basis of loss on which the sentence was based. The fifth concerned totality. Lord Justice Hickinbottom did not deal with these grounds separately but considered them in his overall assessment.
The court emphasised that in the absence of a guideline harm required assessment of actual and potential financial gain and loss, the number of victims, and the impact on victims. In addition, harm included damage to the computer system itself and public confidence in it and similar systems in the financial world. In terms of culpability, reasons for and circumstances of the access and the degree of persistence were relevant, as was breach of a position of trust. Previous convictions and poor regulatory record could aggravate. Any sentence had to be proportionate, taking into account the financial circumstances of the offender.
Applying those principles, Lord Justice Hickinbottom accepted that the financial loss to employees was relatively small in the event and the potential loss was limited because of the temporary nature of the workforce; within about eighteen months only two of the 102 workers remained. The offending took place over a few weeks and thereafter new workers were automatically enrolled as required. The aggregate loss was in the low thousands, though for lower-paid workers the amounts were not insignificant. The company’s savings were also relatively small but gave it a direct financial advantage and potential commercial advantage. Nevertheless, as the Pensions Regulator’s evidence explained, the manipulation of the online system inevitably damaged or risked damaging trust in such systems, confidence in security of personal data and confidence in the security of pension funds. Workchain’s culpability was clearly high: it unlawfully attempted to persuade workers to opt out and, having failed, pretended to be workers to access unauthorised data to defeat automatic enrolment. The conduct was successful, as shown by the opt-out rate. The offending was clearly serious and warranted a substantial sentence, as reflected in the suspended custodial sentences imposed on Tong, Hinkley, Armson and Neal.
However, Lord Justice Hickinbottom held that it was important to bear in mind that Workchain’s sole directors and shareholders had been convicted of the same offence and sentenced to imprisonment (suspended). The need to send a message to directors and shareholders was therefore not a weighty factor in this particular case, and the burden of any fine would in practice largely fall on those same two individuals. The court also took into account the company’s unblemished record save for this offence and its general compliance with regulatory schemes. Despite the seriousness of the offence, the fine imposed was manifestly excessive. Taking into account all the circumstances, a fine of £125,000 would have been appropriate after trial. With a 20 per cent discount for the guilty plea, a fine of £100,000 was appropriate. The court allowed the appeal and substituted a fine of £100,000, leaving all other orders undisturbed.
In short, a fine of £200,000 for unauthorised computer access to opt out employees from a pension scheme was reduced on appeal to £100,000 to reflect a 20 per cent guilty-plea discount and the overall circumstances, including the burden on the two shareholder-directors who had themselves received suspended sentences.