The UK Supreme Court has finished hearing a case that will decide whether people can claim compensation for a minor data protection breach. Its ruling, now awaited, will shape how much legal exposure UK organisations carry after even small incidents.
What happened
On 7 and 8 October 2026 the Supreme Court heard the appeal in Michael Farley and 431 others v Paymaster (1836) Limited (trading as Equiniti). The question before five justices, Lord Sales, Lord Leggatt, Lord Burrows, Lord Stephens and Lady Simler, is narrow but significant: must a compensation claim under the GDPR and the Data Protection Act 2018 pass a threshold of seriousness?
The facts go back to 2019. Paymaster, trading as Equiniti, administered a pension scheme for Sussex Police. Annual benefit statements were posted to old addresses even though the force had supplied current ones. Osborne Clarke puts the number of statements misdirected at more than 750. Each one carried a date of birth, a National Insurance number, years of police service, pay and both earned and projected pension entitlements.
A total of 432 current and former officers brought a collective action. They want damages for distress and, for some, psychiatric harm, caused by worry that third parties would misuse their data. Judgment is awaited.
The detail
The route to the Supreme Court explains why the case matters. In the High Court, Mr Justice Nicklin found that none of the officers had a tenable case that their statements had actually been read. He let fourteen claims continue, where there was an arguable case that envelopes had been opened, and struck out the rest.
The Court of Appeal reversed him. Warby LJ, with King and Whipple LJJ agreeing, gave the judgment, reported as [2025] EWCA Civ 1117. Three points came out of it. First, sending personal data to the wrong place can be an infringement of the GDPR without proof that anyone opened the letter. Second, compensation is available in principle for fear of what might follow a breach, as long as that fear is, in the court’s words, “objectively well-founded” and not merely speculative. Third, there is no minimum level of seriousness below which a claim for non-material damage, such as distress, cannot be brought.
Equiniti was given permission to appeal on 17 December 2025, on that compensation point only. The infringement finding is not under challenge.
The Court of Appeal followed Court of Justice of the EU case law, which says there is no seriousness threshold under the GDPR. It reasoned that the EU GDPR applied directly in the UK in 2019, when the letters went out. Osborne Clarke notes that the argument may not be settled for the UK GDPR, which now rests on Human Rights Act foundations. That leaves room for the Supreme Court either to stay with the European approach or to follow English and Commonwealth authorities instead.
The Information Commission (formerly the ICO) and Open Rights Group were allowed to intervene. Both made submissions supporting the view that there is no threshold.

Why it matters for UK organisations
Most incidents I see are not dramatic. They are a misaddressed email, a wrong attachment or a mail merge sent to stale addresses. These are exactly the events the Farley case is about. If the Supreme Court keeps the Court of Appeal’s position, every one of them could carry litigation risk, however small the harm to each person.
The economics are the point. Individual awards for distress in low-level cases are modest. Multiply a modest award by hundreds or thousands of data subjects, add legal costs and the time spent handling claims, and a minor slip becomes a material liability. Lawyers commenting on the case, Osborne Clarke among them, expect a no-threshold ruling to bring a significant increase in low-value claims. They expect that increase to grow further as AI tools make it cheaper to produce letters before action and claim forms in bulk.
A ruling in Equiniti’s favour would not mean a free pass. Regulatory enforcement does not depend on the threshold question, and claimants would still be able to sue over breaches serious enough to clear whatever bar the court sets. Either way, a definitive answer will feed into how insurers price cyber and data liability cover, how litigation funders choose which group actions to back, and how boards weigh the cost of minor incidents.
The case is also a reminder that outsourcing does not remove the risk of claims. Paymaster was the scheme administrator, not the police force, and it is the administrator that faces the claims.
Expert view
From a governance point of view, I would not wait for the judgment before acting. Whichever way the court goes, the Court of Appeal has already confirmed two things that change how incidents should be assessed: misdirection can be an infringement without proof of disclosure, and well-founded fear can be compensable. Those findings were not appealed.
In my experience, organisations put serious money into ransomware defences and then lose personal data through routine processes nobody has looked at for years. Here, the controller had sent updated addresses; the failure came afterwards. That is a data quality and supplier assurance problem, not a sophisticated attack.
It is also worth noting where the burden still sits for claimants. Even with no threshold, each claimant must show that their fear was objectively reasonable. A well-documented incident response, showing quick containment, recovery of letters where possible, and a clear, honest risk assessment shared with those affected, is the best evidence an organisation can have when that question is tested.
What to do now
- Treat low-level incidents as potential claims. Log misdirected post and email properly, with a documented risk assessment, even where they fall below the threshold for reporting to the regulator.
- Fix data accuracy at source. Check how address and contact changes flow between your systems and your suppliers’. Stale records caused this case.
- Review processor contracts. Make sure data protection clauses, indemnities and liability caps reflect the risk of group claims, and that suppliers can show their own controls.
- Tighten outbound controls. Use recipient checks for email, address validation for bulk mailings and peer review for large mail merges. Restricting who can send bulk communications supports the Cyber Essentials principles of secure configuration and user access control.
- Prepare your communications. Have templates ready that explain clearly what happened and what risk remains, and offer proportionate support such as fraud monitoring where it is justified.
- Brief your insurer and board. Confirm whether your cyber or professional indemnity policy responds to low-value group actions, and flag the pending judgment as a known risk.
Bottom line
The Supreme Court will decide whether trivial data breaches can support compensation claims, and until it rules the Court of Appeal’s no-threshold position stands. Organisations should assume that small, everyday errors carry real legal risk, and invest in the dull controls that stop personal data going to the wrong place in the first place.
Sources
- UK Supreme Court: Michael Farley and 431 others v Paymaster (1836) Limited (trading as Equiniti)
- Local Government Lawyer: Supreme Court hears appeal over data breach claims and threshold of seriousness
- Computer Weekly: UK Supreme Court to decide whether to block ‘trivial’ data protection claims
- Osborne Clarke: All eyes on the UK Supreme Court: does a ‘threshold of seriousness’ apply to claims in respect of a data breach?