23 September 2025

4 min read

Farley v Paymaster 1836 Ltd (trading as Equiniti) (Equiniti): a victory for data breach claimants.

Written by Laura Cunningham

In a landmark judgment the Court of Appeal has overturned a previous High Court ruling which appeared to limit the ability of individuals to bring data breach claims.

Background

In August 2019, more than 450 current and past employees of the Sussex Police Force brought claims against Equiniti, a pension scheme administrator, for a breach of data protection legislation, and misuse of private information after Equiniti sent envelopes containing their annual pension benefit statements to out-of-date addresses. These letters included their name, date of birth, national insurance number, details of the officer’s salary and pension details.

High Court

In the court of first instance, Nicklin J struck out all but 14 claims who could demonstrate that their letter had been opened and read. Of the 14 only two asserted that there was evidence their statement had been read by a third party who was neither a family member nor a colleague.

In respect of the other 460 cases, Nicklin J rejected the claimants’ attempt to rely on the inference that the envelopes had been opened and read by a third party; rather, there must be a solid evidential basis to draw such an inference. Nicklin J stated that “to have a viable claim for the misuse of private information and/or data protection, each claimant must be able to show that s/he has a real prospect of demonstrating that there had been a ‘misuse’”.

Many of the statements had been returned unopened, yet claims were advanced on the basis that personal information had been “put at significant risk of being opened and read by unknown third-party recipients”. Nicklin J rejected this on the grounds that a “near miss” was not sufficient on its own even if it did cause significant distress, as “the general law of torts does not generally allow recovery for the apprehension that a tort might have been committed”.

For a full background on the High Court decision, see our April 2024 article here.

Court of Appeal

Allowing the claimants appeal, the Court of Appeal ruled that printing, placing and posting letters by qualifies as processing, and that it is not “essential for the appellants to allege or prove third-party disclosure” for there to have been infringement of the claimant’s data rights.

The Court of Appeal found that there is no de minimis requirement in data misuse claims, and as such there is no minimum level of damage required to be demonstrated for a claimant to be successful. Lord Justice Warby stated “in principle a claimant can recover compensation for fear of the consequences of an infringement if the alleged fear is objectively well-founded but not if the fear is (for instance) purely hypothetical or speculative”. In other words, the fear of misuse of personal data can amount to non-material damage provided such fear is deemed to be well-founded.

The Court then considered whether the Plaintiffs’ claims constituted an abuse of process, referencing Municipio de Mariana v BHP Group, reading: “[P]roceedings may ... be abusive if, even though they raise an arguable cause of action, they are (objectively) pointless and wasteful, in the sense that the benefits to the claimants from success [are] likely to be extremely modest and the costs to the defendants in defending the claims wholly disproportionate to that benefit”. The Court referred to Sullivan v Bristol Film Studios and concluded that “The mere fact that a claim is small should not automatically result in the court refusing to hear it at all. If I am entitled to recover a debt of £50 .... it would be an affront to justice if my claim were simply struck out.” The “abuse of process” appeal was dismissed.

The Court of Appeal ruled that Nicklin J was incorrect in striking out most of the claims at the early stage, and as such remitted the claims back to the High Court for re-consideration.

Implications

Whilst it is likely to be appealed to the Supreme Court, for now, this ruling means that claimants can continue to bring low value data breach claims with no requirement to demonstrate that such claims meet a ‘threshold of seriousness’.

This judgement should act as a reminder to organisations to remain vigilant and ensure compliance with their data protection obligations to minimise exposure to data breach claims.

If you would like any further information or advice on these issues, please contact Laura Cunningham, Head of Data Protection and Information Law.

*This information is for guidance purposes only and does not constitute, nor should be regarded, as a substitute for taking legal advice that is tailored to your circumstances.

About the author

Laura Cunningham

Partner

Laura Cunningham is a Partner in the Commercial team at Carson McDowell. She is qualified to practice in Northern Ireland, Republic of Ireland and England and Wales. Laura specialises in all aspects of information law including: privacy, confidentiality, data protection, General Data Protection Regulation (GDPR), and freedom of information (FOIA).