UK: Paradise Paper Chase: When Is A Leak A Crime?

Last Updated: 6 December 2017
Article by Clive Ince and Morgan Wolfe

Over 13 million files, many of them containing confidential and sensitive client information, were leaked from offshore legal service providers and corporate registries in 19 jurisdictions including the Caribbean, Jersey, Guernsey and the Isle of Man. More than half of the documents came from law firm Appleby. As a result, sometimes complex financial structures used by well-known figures and companies, including the Queen (through the Duchy of Lancaster), Lewis Hamilton, Arsenal and Everton football clubs and Apple and Nike, were exposed to scrutiny and widespread comment.

The files were obtained by German newspaper Süddeutsche Zeitung and reported by the International Network of Investigative Journalists (ICIJ). The ICIJ is represented in the UK by the Guardian and BBC's Panorama, which recently ran this as a  two-part story/exposé. Süddeutsche Zeitung was also the publication initially contacted by an anonymous source with encrypted internal documents from the legal firm Mossack Fonseca in last year's Panama Papers.)

Most media sources have referred to the leak as just that, but others prefer to describe it as a hack. In a statement published on the firm's website, Appleby claims it was the victim of "a serious criminal act by an intruder who deployed the tactics of a professional hacker".

The terms leak and hack are not mutually exclusive. According to the Oxford English Dictionary the former is "an improper or deliberate disclosure of information (e.g. for political purposes)" while the latter is "the practice of gaining unauthorised access to a computer, network, etc., esp. remotely".

Predictably there has been much speculation in recent weeks about the potential wrongdoing of those who create and utilise tax mitigation structures. But what of the potential liability of the leakers/hackers themselves? Here we consider, hypothetically, how leaking confidential data such as that contained in the Panama and Paradise Papers might be treated under current (and future) cyber crime laws in the UK.

According to the Crown Prosecution Service (CPS) hacking is "the unauthorised use of, or access into, computers or networks by exploiting identified security vulnerabilities".  Hacking is classed as 'cyber-dependent crime' which can be committed "only through the use of Information and Communications Technology (ICT) devices, where the devices are both the tool for committing, and the target of, the crime".

In the UK, the Data Protection Act 1998 regulates how personal information is used by organisations, businesses and the government and identifies eight 'data protection principles'. Under section 55(1) it is an offence to knowingly or recklessly obtain, disclose or procure the disclosure of personal data without the consent of the data controller. Appleby has made clear that it did not consent to disclosure. If, as it appears, the leaker(s) acted deliberately (or recklessly) what sanctions would they face under domestic (UK) law?

Companies as well as individuals can be found guilty of a section 55 offence and where this was committed with the "consent or connivance" of a company's directors, both the company and its individual directors could face punishment.

A defence to a section 55 offence may be available (only to individuals, not companies) where the accused believed his actions were necessary to prevent a crime or that it was in the public interest that the information be disclosed. If it is established that some of the parties to the recently-disclosed tax schemes were acting criminally or unlawfully, then such defences might become potentially available.

Leakers/hackers could also find themselves in the crosshairs of the Computer Misuse Act 1990 (CMA), the UK's main legislation on cyber attacks. The term 'computer' is not defined in the act but Lord Hoffman in DPP v McKeown and DPP v Jones defined computer as 'a device for storing, processing and retrieving information'. Both a smartphone and tablet would meet this definition and therefore could play a role in a CMA offence.

Section 1 deals with unauthorised access to computer material, or 'access without right'. The Act distinguishes between (i) unauthorised access and (ii) permitted access for unauthorised purposes. Where a user has permission to access a system, but uses the data for a purpose that is not authorised, he may be guilty of the second limb of the offence.

One common scenario is where an employee is permitted to access certain files but not to share them externally. In this respect, an employee guilty of misuse might avoid sanction under the CMA, but still face substantial fines under the DPA. The external hacker might avoid conviction under the DPA by pleading a public interest defence, but this is not possible under the CMA which carries a maximum prison term of one year, a fine of up to £500,000 or both.

In 2016 there were 19 DPA prosecutions, the vast majority being under section 55. The fines imposed ranged from £150 to £7,500. There were also 262 convictions under the CMA between 1990 and 2013.

As well as the defences mentioned above, whistle-blower protection is available under the Public Interest Disclosure Act 1998 and covers certain disclosures of wrongdoing made by employees, contractors, agency staff, police officers and NHS workers. Section 10 of the Contempt of Court Act 1981 provides protection for journalists and their sources unless disclosure is held to be necessary in the interests of justice, national security or the prevention of crime.

We have considered the above issues from an English law perspective and for this law to apply there would need to be a sufficient connection between the perpetrators, their actions and this jurisdiction. This has not yet been entirely established in relation to the Paradise Papers.

In the Panama Papers' exposé the source/hacker John Doe set several conditions before handing over the documents to Süddeutsche Zeitung's Bastian Obermayer and Frederik Obermaier.  These included anonymity, communicating only over encrypted files and "no meeting ever". Obermayer has said that the source acted because he thought that the law firm Mossack Fonseca was behaving unethically. Obermayer also commented he believed the source was at serious risk "because there are so many people involved who are not only powerful, but who also don't hold back to use that power."

Are such leaks or hacks to be regarded as a force for good or as a proliferating and disturbing extension of criminality? There is no unassailable answer to this question. The law will play its part eventually but often how these headline-grabbing events are judged by the "court of public opinion" will depend more on personal politics and moral values than on detached legal analysis.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

To print this article, all you need is to be registered on

Click to Login as an existing user or Register so you can print this article.

In association with
Related Topics
Related Articles
Related Video
Up-coming Events Search
Font Size:
Mondaq on Twitter
Register for Access and our Free Biweekly Alert for
This service is completely free. Access 250,000 archived articles from 100+ countries and get a personalised email twice a week covering developments (and yes, our lawyers like to think you’ve read our Disclaimer).
Email Address
Company Name
Confirm Password
Mondaq Topics -- Select your Interests
 Law Performance
 Law Practice
 Media & IT
 Real Estate
 Wealth Mgt
Asia Pacific
European Union
Latin America
Middle East
United States
Worldwide Updates
Registration (you must scroll down to set your data preferences)

Mondaq Ltd requires you to register and provide information that personally identifies you, including your content preferences, for three primary purposes (full details of Mondaq’s use of your personal data can be found in our Privacy and Cookies Notice):

  • To allow you to personalize the Mondaq websites you are visiting to show content ("Content") relevant to your interests.
  • To enable features such as password reminder, news alerts, email a colleague, and linking from Mondaq (and its affiliate sites) to your website.
  • To produce demographic feedback for our content providers ("Contributors") who contribute Content for free for your use.

Mondaq hopes that our registered users will support us in maintaining our free to view business model by consenting to our use of your personal data as described below.

Mondaq has a "free to view" business model. Our services are paid for by Contributors in exchange for Mondaq providing them with access to information about who accesses their content. Once personal data is transferred to our Contributors they become a data controller of this personal data. They use it to measure the response that their articles are receiving, as a form of market research. They may also use it to provide Mondaq users with information about their products and services.

Details of each Contributor to which your personal data will be transferred is clearly stated within the Content that you access. For full details of how this Contributor will use your personal data, you should review the Contributor’s own Privacy Notice.

Please indicate your preference below:

Yes, I am happy to support Mondaq in maintaining its free to view business model by agreeing to allow Mondaq to share my personal data with Contributors whose Content I access
No, I do not want Mondaq to share my personal data with Contributors

Also please let us know whether you are happy to receive communications promoting products and services offered by Mondaq:

Yes, I am happy to received promotional communications from Mondaq
No, please do not send me promotional communications from Mondaq
Terms & Conditions (the Website) is owned and managed by Mondaq Ltd (Mondaq). Mondaq grants you a non-exclusive, revocable licence to access the Website and associated services, such as the Mondaq News Alerts (Services), subject to and in consideration of your compliance with the following terms and conditions of use (Terms). Your use of the Website and/or Services constitutes your agreement to the Terms. Mondaq may terminate your use of the Website and Services if you are in breach of these Terms or if Mondaq decides to terminate the licence granted hereunder for any reason whatsoever.

Use of

To Use you must be: eighteen (18) years old or over; legally capable of entering into binding contracts; and not in any way prohibited by the applicable law to enter into these Terms in the jurisdiction which you are currently located.

You may use the Website as an unregistered user, however, you are required to register as a user if you wish to read the full text of the Content or to receive the Services.

You may not modify, publish, transmit, transfer or sell, reproduce, create derivative works from, distribute, perform, link, display, or in any way exploit any of the Content, in whole or in part, except as expressly permitted in these Terms or with the prior written consent of Mondaq. You may not use electronic or other means to extract details or information from the Content. Nor shall you extract information about users or Contributors in order to offer them any services or products.

In your use of the Website and/or Services you shall: comply with all applicable laws, regulations, directives and legislations which apply to your Use of the Website and/or Services in whatever country you are physically located including without limitation any and all consumer law, export control laws and regulations; provide to us true, correct and accurate information and promptly inform us in the event that any information that you have provided to us changes or becomes inaccurate; notify Mondaq immediately of any circumstances where you have reason to believe that any Intellectual Property Rights or any other rights of any third party may have been infringed; co-operate with reasonable security or other checks or requests for information made by Mondaq from time to time; and at all times be fully liable for the breach of any of these Terms by a third party using your login details to access the Website and/or Services

however, you shall not: do anything likely to impair, interfere with or damage or cause harm or distress to any persons, or the network; do anything that will infringe any Intellectual Property Rights or other rights of Mondaq or any third party; or use the Website, Services and/or Content otherwise than in accordance with these Terms; use any trade marks or service marks of Mondaq or the Contributors, or do anything which may be seen to take unfair advantage of the reputation and goodwill of Mondaq or the Contributors, or the Website, Services and/or Content.

Mondaq reserves the right, in its sole discretion, to take any action that it deems necessary and appropriate in the event it considers that there is a breach or threatened breach of the Terms.

Mondaq’s Rights and Obligations

Unless otherwise expressly set out to the contrary, nothing in these Terms shall serve to transfer from Mondaq to you, any Intellectual Property Rights owned by and/or licensed to Mondaq and all rights, title and interest in and to such Intellectual Property Rights will remain exclusively with Mondaq and/or its licensors.

Mondaq shall use its reasonable endeavours to make the Website and Services available to you at all times, but we cannot guarantee an uninterrupted and fault free service.

Mondaq reserves the right to make changes to the services and/or the Website or part thereof, from time to time, and we may add, remove, modify and/or vary any elements of features and functionalities of the Website or the services.

Mondaq also reserves the right from time to time to monitor your Use of the Website and/or services.


The Content is general information only. It is not intended to constitute legal advice or seek to be the complete and comprehensive statement of the law, nor is it intended to address your specific requirements or provide advice on which reliance should be placed. Mondaq and/or its Contributors and other suppliers make no representations about the suitability of the information contained in the Content for any purpose. All Content provided "as is" without warranty of any kind. Mondaq and/or its Contributors and other suppliers hereby exclude and disclaim all representations, warranties or guarantees with regard to the Content, including all implied warranties and conditions of merchantability, fitness for a particular purpose, title and non-infringement. To the maximum extent permitted by law, Mondaq expressly excludes all representations, warranties, obligations, and liabilities arising out of or in connection with all Content. In no event shall Mondaq and/or its respective suppliers be liable for any special, indirect or consequential damages or any damages whatsoever resulting from loss of use, data or profits, whether in an action of contract, negligence or other tortious action, arising out of or in connection with the use of the Content or performance of Mondaq’s Services.


Mondaq may alter or amend these Terms by amending them on the Website. By continuing to Use the Services and/or the Website after such amendment, you will be deemed to have accepted any amendment to these Terms.

These Terms shall be governed by and construed in accordance with the laws of England and Wales and you irrevocably submit to the exclusive jurisdiction of the courts of England and Wales to settle any dispute which may arise out of or in connection with these Terms. If you live outside the United Kingdom, English law shall apply only to the extent that English law shall not deprive you of any legal protection accorded in accordance with the law of the place where you are habitually resident ("Local Law"). In the event English law deprives you of any legal protection which is accorded to you under Local Law, then these terms shall be governed by Local Law and any dispute or claim arising out of or in connection with these Terms shall be subject to the non-exclusive jurisdiction of the courts where you are habitually resident.

You may print and keep a copy of these Terms, which form the entire agreement between you and Mondaq and supersede any other communications or advertising in respect of the Service and/or the Website.

No delay in exercising or non-exercise by you and/or Mondaq of any of its rights under or in connection with these Terms shall operate as a waiver or release of each of your or Mondaq’s right. Rather, any such waiver or release must be specifically granted in writing signed by the party granting it.

If any part of these Terms is held unenforceable, that part shall be enforced to the maximum extent permissible so as to give effect to the intent of the parties, and the Terms shall continue in full force and effect.

Mondaq shall not incur any liability to you on account of any loss or damage resulting from any delay or failure to perform all or any part of these Terms if such delay or failure is caused, in whole or in part, by events, occurrences, or causes beyond the control of Mondaq. Such events, occurrences or causes will include, without limitation, acts of God, strikes, lockouts, server and network failure, riots, acts of war, earthquakes, fire and explosions.

By clicking Register you state you have read and agree to our Terms and Conditions