Data Kraken v Torry Harris: what a displaced software supplier's High Court claim teaches contractors
A small Oxford consultancy is suing a Bristol systems integrator in the High Court over what it says was the copying of its software to replace it as a supplier to a mobile network. The case, Data Kraken Consultancy Ltd v Torry Harris Business Solutions (Europe) Ltd, is listed under number IL-2026-000011 in the Intellectual Property List and has yet to be decided. The pleadings already contain more useful lessons for software contractors than most judgments.
Data Kraken licensed its DK Solution data-warehousing software to Three Ireland from January 2020 to December 2023 for use with the operator's prepaid brand, 48 Mobile. As the contract approached expiry, Torry Harris built a replacement. Data Kraken says it discovered, through unusual email alerts in July 2023, what it believed was a replica of its system running on its own code. It alleges that Torry Harris misused confidential information, including source code, to build the replacement and take its place as the main supplier. Torry Harris denies wrongdoing, says its system was developed independently, argues that Three Ireland owned the relevant database rights, and questions whether the English court has jurisdiction.
Five lessons
Evane Alexandre of Gerrish Legal, writing for the contractor press on 2 September, draws five practical points from the dispute for any contractor whose business is the software they write.
The first is access. A permitted-purpose clause, stating what a client and its other suppliers may use the software and its data for, is only as good as the controls that enforce it: role-based permissions and audit logs that show who accessed what, and when. Data Kraken's case rests in part on alerts that told it something was happening. Most contractors' systems would have told them nothing.
The second is the distinction between rights in the software and rights in the data. Ownership, permitted use, purpose and duration need separate treatment for each, because the client's argument that it owns the database is precisely the argument Torry Harris is running.
The third is exit. A contract that says nothing about what happens when the client moves on leaves the outgoing supplier with no right to transition assistance, no obligation on anyone to return or delete code, and no restriction on reverse engineering. The point at which a supplier has least leverage is after the replacement project has started; the terms have to be agreed before signature.
The fourth is the supply chain. The client's other suppliers, integrators and consultants will have access to the system. The confidentiality obligations in the contract need to flow down to them, and the contractor needs to know who they are.
The fifth is geography. Software hosted, accessed, copied or developed abroad raises questions of which court and which law applies. Torry Harris's jurisdictional argument shows why.
Why it matters here
The contractor who builds a system for a client and licenses it, rather than assigning the rights, is running a software business, and the IR35 tests reward that: a company that owns its product and carries the commercial risk of it is a business in a way that a day-rate engagement is not. The price of that position is that the product has to be protected like one. Data Kraken's claim, whatever its outcome, is the cost of finding out too late what the contract should have said.
