Horsfield Menzies : Blog vs Behaviour – SAM BUTLER, HORSFIELD MENZIES’ SENSITIVITY SPONSOR

Every serious organisation needs somebody to explain data protection.

Horsfield Menzies had Sam Butler.

Of course it fucking did.

On Data Protection Day, Butler published “Understanding GDPR”, a brisk tour through lawfulness, fairness, transparency, purpose limitation, data minimisation, confidentiality and accountability. Employers, he explained, are “stewards of sensitive employee information” and carry significant responsibilities when collecting, using and sharing personal data.

It is difficult to read that now without mentally issuing him a badge.

SAM BUTLER
SENSITIVITY SPONSOR
HORSFIELD DATA HANDLING DEPARTMENT

Please keep your medical information inside the marked area at all times.

The article is not especially complicated. That is part of its charm. Sam takes GDPR, removes most of the pain, and gives employers the rules in language anybody can understand: know why you have somebody’s information, do not collect more than you need, tell people what you are doing with it, protect sensitive material, be careful when third parties become involved and have proper procedures when somebody exercises their data rights.

Then comes the important bit.

Accountability.

Employers must be able to demonstrate compliance.

Excellent advice.

Unfortunately for Sam, Horsfield Menzies later supplied me with the practical workshop.


Sam Explains Sensitive Information

Butler begins from a sensible premise. Employers hold large quantities of information about people, including recruitment records, payroll data, disciplinary material and other personal information that employees necessarily surrender because employment relationships require it. Some of that material is particularly sensitive, which is why the law imposes higher standards around its handling.

Health information obviously sits towards the interesting end of that discussion.

My mental health was not some incidental curiosity in the Cepac proceedings. Disability was central to the claim, relevant to my ability to participate in litigation and repeatedly connected to requests concerning hearings and adjustments. Medical evidence entered the process because the proceedings required me to explain things about myself that I would otherwise have had no reason to hand to Horsfield Menzies.

That is where Data Protection Day Sam becomes considerably funnier.

The record that eventually caused me to complain about Butler included the handling and use of disability-related medical material and contact involving my medical centre. I objected, among other things, to what I regarded as medical information being pushed beyond the purpose for which it had been supplied, alongside enquiries concerning medical appointment availability which then appeared in opposition to my request for a postponement.

Brochure Sam is standing at the front of the seminar explaining the careful stewardship of sensitive information.

File Sam has wandered off with a torch.


Purpose Limitation Meets Curiosity

Purpose limitation is one of Butler’s chosen GDPR principles. Personal data, he explains, should be collected for specified, explicit and legitimate purposes.

Again, perfectly sensible.

Suppose a disabled litigant supplies medical material because he needs to evidence illness, explain participation difficulties or support a request concerning a hearing. There is an obvious question about how far that material should then travel and what further enquiries it should inspire.

That was part of what bothered me.

The article is aimed at employers rather than opposing solicitors in litigation, so the legal contexts are not identical. Fine. But Sam was not publishing obscure technical exemptions. He was preaching basic disciplines around sensitive information: purpose, necessity, transparency and accountability. Those principles become more interesting, not less, when the person writing about them later becomes the subject of a complaint concerning somebody’s medical information.

Then there is data minimisation.

Employers, Sam says, should process only what is necessary for the intended purpose.

Minimal.

Necessary.

Proportionate.

Lovely.

The Cepac litigation did not generally strike me as a project suffering from excessive minimalism. Medical circumstances became contested territory while Horsfield Menzies accumulated correspondence, complaints, previous litigation, behaviour, blogs and social-media material until a judicially described simple claim had swollen towards two thousand pages.

Some lawyers treat data minimisation as a principle.

Sam appeared to regard it more as a fucking aspiration.


Horsfield Menzies’ Very Own Data Troll

This is where Data Troll stops feeling like an insult and starts sounding like a job title.

I picture Sam underneath the Horsfield Menzies bridge, surrounded by bundles, whispering “lawfulness, fairness and transparency” while rummaging around to see whether the disabled claimant can get a GP appointment before Thursday.

The joke works because Butler wrote the checklist himself.

Purpose limitation. Data minimisation. Integrity and confidentiality. Accountability. Third-party access. DSARs.

It increasingly reads like somebody gave him a preview of future TCAP headings.

None of this means that medical information entering litigation becomes untouchable. Of course it does not. The point is the almost comic distance between the restraint implicit in Butler’s article and the appetite for information I experienced once Horsfield Menzies was on the other side of the case.

Sam’s online character is careful and custodial. He wants employers to understand that data belongs to real people, that sensitive information deserves heightened attention and that organisations need systems capable of demonstrating responsible handling.

Very wholesome.

Then you open the Cepac folder.


Fairness, Transparency And The Complaint

Fairness and transparency sit right at the beginning of Butler’s GDPR sermon. People should understand how their information is being used and organisations should be able to explain what they are doing.

So when I became concerned about medical information and contact involving my medical centre, I did something terribly old-fashioned.

I complained privately.

On 23 March 2025, a detailed complaint about Butler went directly to Angus Menzies, Simon Horsfield and Daniel Rubin. It raised the medical-information issues alongside disputed litigation statements, costs pressure and correspondence I considered obstructive. Whatever those men thought of the allegations, they had them.

That was an opportunity.

Investigate. Ask Butler what happened. Check the correspondence. Explain the purpose and basis of the disputed conduct. Reject the complaint with reasons if the firm believed I had misunderstood everything. Uphold something if something required upholding.

Butler’s own seventh GDPR principle supplies the word.

Accountability.

What followed did not feel much like Sam Butler’s Data Protection Day.

There was no meaningful or constructive investigation outcome communicated to me. What I received from Rubin was, if memory serves, little more than a brief flat denial rather than substantive engagement with what had actually been raised.

The Sensitivity Sponsor had attracted a complaint.

Management put the shutters down.

Happy Data Protection Day.


Third Parties, Sam? Tell Me More

One part of Butler’s article now reads with particularly good comic timing.

Managing Third-Party Access.

Sam explains that organisations remain responsible when personal information is shared with third-party processors. Due diligence matters. Contracts matter. Knowing who has information, why they have it and what they are doing with it matters.

The technical example in his article concerns outsourcing arrangements such as payroll and IT support. My complaint concerned a different setting altogether, but that distinction does little to rescue the optics.

The reason the medical issue became so intrusive from my perspective was precisely that it escaped the comfortable boundary of documents already sitting between parties in litigation. Contact involving my medical centre entered the story.

Suddenly Data Protection Day Sam looks less like an author and more like foreshadowing.

The solicitor warning employers about careful handling of sensitive information and third-party involvement later becomes the solicitor I am complaining about because of conduct involving sensitive health information and a fucking medical centre.

If I scripted Blog vs Behaviour this neatly, it would be accused of lacking subtlety.

Sam keeps doing it for me.

He writes about equality.

He writes about sickness absence.

Now we discover he does GDPR.

At this rate, I am waiting for “A Practical Guide To Not Becoming Your Own Firm’s Search Result”.

I would read that one immediately.


The DSAR Department Is Open

Butler also has useful advice about data subject access requests. Organisations should establish clear procedures, meet the relevant deadlines, redact third-party information where appropriate and seek legal advice when things become complicated.

Luckily, Horsfield Menzies knows some lawyers.

Its own data-protection practice advertises assistance with compliance, audits of current data handling, DSAR responses, breaches, ICO engagement and training. If a company is unsure whether its information-handling practices are sufficiently robust, Horsfield Menzies can apparently investigate the matter and recommend improvements.

Perhaps they should mystery-shop the service internally.

I know a candidate.

This is the recurring difficulty Horsfield Menzies has created for itself with Blog vs Behaviour. The firm publishes so much material explaining what responsible organisations should do that TCAP rarely needs to invent a standard against which to assess them. Their own lawyers write it, upload it, optimise it and leave it waiting for the documentary record to arrive.

Sam has been especially generous.

Every new article gives me another laminated card to hold beside the file.

The firm can hardly complain that the comparison is unfair when its own people chose the fucking criteria.


Build Trust

Towards the end of Butler’s article comes the reward for doing all of this properly.

Employers can minimise risk, avoid costly penalties and “build trust with employees”.

Trust is the bit that matters.

Data protection becomes painfully technical very quickly. Lawful bases, special-category conditions, controllers, processors, exemptions and competing rights can turn a human problem into several pages of alphabet soup.

Underneath it all sits something simpler.

If somebody gives you sensitive information, particularly information about their health, they need to trust what will happen to it.

Once that trust goes, everything changes. A request that might otherwise look routine feels intrusive. An enquiry feels like intelligence gathering. Another piece of medical evidence feels less like assistance to the process and more like ammunition being handed to somebody already pointing in your direction.

That was increasingly how I experienced Horsfield Menzies.

From the firm’s side, every action could presumably be divided into legal purpose, litigation necessity and procedural justification. From mine, I had disclosed highly personal information because disability made it relevant and then watched medical circumstances become another contested part of an increasingly hostile case.

Contact involving the medical centre followed. The complaint came afterwards. What I did not receive was the kind of careful accountability exercise Sam recommends when writing for everybody else.

Trust did not merely decline.

It packed a bag.


Data Protection Day, Horsfield Menzies Style

The temptation with Butler is to become angry.

That would waste this article.

His GDPR piece is funny now.

Not intentionally. Sam presumably wrote it because Data Protection Day had arrived, employers needed reminding of their obligations and somebody at Horsfield Menzies thought a topical article might generate useful traffic.

History has improved it.

Here is Sam Butler solemnly reminding employers that they are “stewards of sensitive employee information”. Purpose limitation follows. Then data minimisation. Transparency is over there, with accountability bringing up the rear.

It is less an article now than a guided tour of the principles against which I later complained about its author.

That is what makes Blog vs Behaviour such an irritating format for Horsfield Menzies. I do not need to stand outside the building shouting that everyone inside is terrible.

Their own website is more useful.

The lawyers explain the standard.

I bring the file.

Readers can enjoy the fucking distance between them.


The Sensitivity Sponsor

So I think Horsfield Menzies should embrace this rather than fight it.

Make Sam the official Sensitivity Sponsor.

Give him a lanyard. Maybe a tasteful sash.

Every Data Protection Day, he can walk around the Manchester office reminding colleagues to minimise, specify, justify and protect. Anyone approaching a medical record has to get Sam’s little rubber stamp first.

APPROVED BY THE HORSFIELD DATA TROLL.

Daniel Rubin can supervise from a comfortable fucking distance.

If somebody complains, Angus and Simon can host an accountability workshop.

There might even be biscuits.

Underneath the joke remains the reason this article exists. Butler publicly taught organisations about careful stewardship of sensitive information, transparency, purpose limitation, minimisation and accountability. I later complained about his conduct concerning disability-related medical information and contact involving my medical centre, and I did not receive what I regarded as a meaningful investigation outcome.

That contrast belongs in the record.

No need to shout about it.

Sam already supplied the presentation.

I merely changed the slides.

Happy Data Protection Day, Sensitivity Sponsor.

Try not to touch anything sensitive on the way out.

Lee Thompson – Founder, The Cummins Accountability Project


Sources

Scroll to Top