9 min read

UK data breach litigation and the search for a sustainable claims model

Read more

By Richard Breavington & Astrid Hardy

|

Published 09 October 2026

Overview

In recent days, the Supreme Court has been considering UK data breach litigation in Farley and others v Paymaster (1836) Limited (trading as Equiniti) ("Farley"). The appeal to the UK's highest court has generated interventions from the Information Commissioner (as was) and the activist Open Rights Group. These interventions highlight the potential influence of the case on the direction of claims arising from breaches of UK data protection law.

Richard Breavington, Partner at DAC Beachcroft, comments: "Farley is the latest chapter in a series of battles arising from the search by claimant representatives for an effective long-term method of bringing large numbers of data breach claims. At its core, Farley considers a narrow issue: whether there is a threshold of seriousness required for a successful claim arising out of a personal data breach. However, the judgment from such an authoritative source could have wider implications for data breach claims more generally. In particular, the outcome of Farley could provide a steer as to whether a viable long-term model for UK data breach claims can emerge, as well as addressing open questions about UK/EU regulatory alignment."

The landscape for UK data breach litigation has changed considerably over a relatively short period of time. It has involved arguments about causes of action; disputes about thresholds and recoverable damage; and fights about appropriate procedural allocation. Underlying all of this has been a crucial question: is there a way for claimant law firms to make meaningful money out of data subject litigation? If not, claims will be confined to those few individuals who have the time and strength of feeling to pursue a claim proactively, because, following Johnson v Eastlight Community Homes, low-value data breach claims are likely to be allocated to the Small Claims Track. But if so, then the number of data breaches that occur could encourage significant claimant law firm investment - as seen in some other jurisdictions to date. The key issue for insurers, practitioners and all businesses that hold significant personal data is the extent to which Farley contributes to answering that question.

 

A short history lesson

The landmark 2015 Court of Appeal decision in Vidal-Hall v Google established that claims for distress under the Data Protection Act 1998 could be brought without proof of pecuniary loss in the UK. Article 82 of the General Data Protection Regulation (via the Data Protection Act 2018) expressly incorporated this right to compensation for material and non-material damage into UK legislation. This created expectations in some quarters that data breach claims could become the successor to other declining categories of litigation previously attractive to claimant representatives, such as motor personal injury claims.

However, in practice, claimants and their representatives faced an immediate difficulty. The core allegation in most cyber incident claims is that the controller failed to implement appropriate technical and organisational security measures. Proving these allegations is challenging without access to documents and expert or forensic evidence. The costs of bringing such a claim can therefore spiral at an early stage. Funding for such claims became essential, usually via after-the-event (ATE) insurance.

Claimant firms sought to circumvent these issues by advancing multiple causes of action alongside statutory data protection claims. Claims for misuse of private information (MPI), breach of confidence (BoC) and negligence routinely accompanied UK GDPR allegations. This approach was tactical and a response to specific funding issues. The recoverability of ATE premiums was largely eliminated from low-value claims, yet "publication and privacy proceedings" remained an exception. Successful MPI and breach of confidence claims could unlock the recovery of ATE premiums through being classified as privacy proceedings. The ATE premiums often far exceeded the value of the damages claim itself, creating pressure on defendants to settle actions.

That approach suffered a major setback in Warren v DSG Retail Ltd in 2021. The claim was brought in response to a significant cyber attack suffered by DSG between 2017 and 2018. In Warren, Mr Justice Saini struck out the negligence, MPI and BoC claims advanced by the claimant. The Court found that, where a third-party cyber criminal had attacked the defendant, there was no positive wrongful disclosure by the defendant capable of supporting those causes of action. This closed down the possibility of classifying data breach claims as 'privacy proceedings'. The funding market was substantially affected by Warren and subsequent decisions.

Only a few months later, the Supreme Court delivered a second decisive blow in Lloyd v Google LLC. The Court rejected the proposition that loss of control of personal data was itself compensable damage and also narrowed down considerably the practical viability of the representative action model set out under CPR Part 19 that many hoped would effectively provide an opt-out route for breaches of data protection legislation.

Numerous other cases before the lower courts tended to confirm the existence of a threshold of seriousness that needed to be met for data breach claims to be viable. There was increasing judicial scepticism towards trivial claims, which were considered appropriate for the County Courts, usually on the Small Claims Track (see, for example, Johnson v Eastlight Community Housing Trust and Cleary v Marston (Holdings) Ltd). Interest from claimant law firms dwindled.

The UK position on the recoverability of damages for loss of control remains relatively settled, with the UK courts continuing to take the restrictive view adopted in Lloyd v Google in respect of damages for loss of control. The position is slightly murkier in the EU. Earlier this year, our team untangled the thread of ambiguous decisions issued by the CJEU on this very issue.

 

Farley: the threshold battleground

The issue of whether there is a threshold of seriousness required for a viable data breach claim has been brought to the fore again in Farley. Annual benefit statements for 432 pension members were accidentally sent to outdated addresses by the scheme administrator, Paymaster (Equiniti). The pension members were current and former police officers, and the statements included their names, dates of birth, National Insurance numbers, length of service in the police force, and salary and pension details.

The High Court chose to strike out those claims where the letters had been returned unopened or where there was no proof that the letters had been opened and read by someone other than the claimant. Mr Justice Nicklin considered that there was no claim for damages in the event of an apprehension that a wrong had occurred. Fourteen claims were allowed to proceed where there was evidence that the envelope containing the benefit statement had been opened and read. In most cases, it had been opened and read by a family member who still resided at the old address, and there was no suggestion of further unauthorised use of the information. Although the judge considered that the remaining claims appeared to be "very far from being serious cases", they were not struck out because there was a real prospect of demonstrating that the envelope had been opened and read by a third party.

The Court of Appeal reinstated the claims that had been struck out, finding that the judge had erred in law because there was a reasonable basis for alleging a pleaded infringement of the GDPR. However, the Court of Appeal also held that the defendant, Equiniti, was entitled to argue that the appellants' fears of third-party misuse were not 'well-founded' and hence could not qualify as 'non-material damage' (which is recoverable as compensation).

Equiniti appealed to the Supreme Court.

 

Scaling up data breach claims

With Lloyd v Google curtailing opt-out representative actions as a route for mass data breach claims, the claimant market has adapted, shifting towards book-built group claims, sometimes involving numerous claimants following major cyber incidents. A limited number of litigation routes are potentially open to claimant representatives pursuing mass data breach claims.

  • One such example is the route taken in Farley, structured as a multi-claimant (opt-in) group claim that allows for individual assessment of the claims. This is an alternative to the representative claims pursued in Lloyd and Prismall, avoiding the issues concerning 'same damage' and the 'lowest common denominator' argument that sought to reduce the damage suffered by the class down to the bare minimum.

The High Court's decision in Spurgeon & Ors v Capita plc earlier this year suggests that courts may be reluctant to dismantle these types of claims through procedural challenges alone. Master Dagnall refused an application to strike out the proceedings as an abuse of process, despite allegations concerning the uniformity of claimant evidence. The defendants had argued that the claims were pleaded on the basis of assertions that did not accurately reflect their clients' instructions.

However, AXA v CIR demonstrates the importance of test cases in similar circumstances and the limited ability of follow-on claims to escape findings made in lead litigation. The Supreme Court's decision could have particular significance for the pipeline of claims presently waiting behind Farley.

  • The omnibus claim form has also been highlighted as a potential alternative route. Although no significant data breach claim has reportedly been pursued on this basis, the courts' permissive approach to the use of 'omnibus' claim forms has increased their popularity in volume claims.
  • Looking to the future, the Law Commission is currently considering the introduction of a consumer class actions regime, which may yet provide a further platform for data breach claims. Although the consultation is at a preliminary stage, observers will be interested in how consumer law is ultimately defined. A narrow approach would focus on breaches of consumer law legislation, but a broad approach could include harms suffered by claimants in digital environments. A debate could arise as to whether collective data protection litigation should be covered by such a regime or whether an equivalent mechanism for data breach claims should be considered.
  • The outcome of the Law Commission's work could prompt renewed consideration of whether data breach litigation can be brought on an opt-out basis under a collective action mechanism other than representative actions under CPR Part 19. There is an ongoing referral to the CJEU from the Netherlands in SDBN v Amazon on whether a true opt-out class action for a data breach is permissible under Article 80(1) of the GDPR, given the need for the data subject to mandate the exercise of their rights under Article 82; this is relevant given that opt-out actions bring in affected persons to the class without prior approval. The CJEU is also being asked to provide a preliminary ruling in Protectra GmbH v sprd.net AG on whether Article 82 compensation claims can be assigned to a for-profit vehicle (a debt collection agency). Article 80 sets out the circumstances in which data subjects may mandate the exercise of their rights under Article 82 to not-for-profit bodies, organisations, or associations.

Although these decisions, when issued, would not be binding on the UK courts, they are awaited with interest.

Ultimately, the broader point is that claimant appetite to pursue claims for data breaches has not disappeared. The prospect of Small Claims Track allocation has instead driven innovation in claimant litigation strategy. Faced with limited costs recovery, claimant firms have increasingly explored omnibus claim forms, claimant aggregation and other group-based models (like the lead claimant model) designed to improve the economics of low-value claims. A related trend is the growing use of personal injury allegations alongside claims for distress. By pleading recognised psychiatric injury or other personal injury, claimants may increase both the value of their claims and their apparent complexity, supporting arguments that expert evidence is required and that proceedings should be allocated beyond the Small Claims Track.

 

Looking ahead

Richard Breavington comments: "The question to be answered in Farley is whether a seriousness threshold exists. However, the more significant issue is whether courts in the UK are willing to facilitate a route to trial for large numbers of low-value data breach claims outside the small claims track. Farley might or might not be directly relevant to this, but practitioners will be scrutinising the judgment with this in mind."

The future of data breach claims in the UK does not lie in an ever-increasing number of cyber incidents generating large numbers of standalone claims. Increased regulatory scrutiny, including from the Information Commissioner's Office, will not necessarily of itself create a fertile claims environment. It will lie in claimants and their representatives finding a viable mechanism capable of turning data loss into financial gain. Whether Farley assists in that search may prove to be the most significant aspect of the Supreme Court's decision.

Authors