Skip to content

Supreme Court weighs de minimis threshold for GDPR compensation

Listen to a Summary of This Article

Five Supreme Court justices are considering whether a claimant who proves non-material damage from a data protection infringement may nevertheless be denied compensation because the harm is too slight. The answer could reshape the treatment of low-value and mass data breach claims in England and Wales.

The Supreme Court opens a two-day hearing today on a narrow question with consequences extending well beyond the hundreds of police officers whose pension statements gave rise to the litigation: does data protection law impose a minimum threshold of seriousness before non-material damage becomes compensable?

The appeal in Michael Farley and 431 others v Paymaster (1836) Ltd (trading as Equiniti), UKSC/2025/0185, is being heard by Lord Sales, Lord Leggatt, Lord Burrows, Lord Stephens and Lady Simler. The Information Commissioner and Open Rights Group have intervened.1

The Supreme Court has framed the issue in a single sentence: “Does a threshold of seriousness apply to claims for damages under the General Data Protection Regulation and Data Protection Act 2018?”

That formulation is important. Paymaster’s appeal is confined to the compensation issue. The Supreme Court is not being asked to reconsider the Court of Appeal’s separate conclusion that disclosure of personal data to a third party is not an essential ingredient of an infringement.1

Pension statements sent to old addresses

The dispute arose in August 2019, when Paymaster, which administered the Sussex Police pension scheme, sent more than 750 annual benefit statements to out-of-date residential addresses even though Sussex Police had supplied updated address information.

The statements contained personal information including names, dates of birth, National Insurance numbers, details of police service and salary, and accrued and projected pension benefits. It would also have been apparent to anyone reading a statement that its intended recipient was a police officer.2

Some 102 statements were returned to Paymaster unopened. Others were recovered or forwarded to their intended recipients, but the fate of many remained unknown. Thirty-seven of those affected took up an offer of fraud protection at Paymaster’s expense. The Information Commissioner’s Office was notified but did not take regulatory action.2

Proceedings were originally brought on behalf of 474 current and former officers. The present Supreme Court respondents number 432.

The case they now advance is narrower than the litigation with which the High Court began. Following Lloyd v Google LLC [2021] UKSC 50, [2022] AC 1217, the claimants abandoned any claim to compensation merely for “loss of control” of their information. Nor do they now assert, as a generic proposition, that every missing statement was actually opened.

Their pleaded case is that Paymaster’s unlawful processing caused anxiety, alarm, distress and embarrassment because they did not know what had happened to their statements and feared that the information might have come into the hands of third parties and been misused. Forty-two of the appellants also alleged aggravation of a pre-existing medical condition.3

What the High Court did and did not decide

At first instance, Mr Justice Nicklin struck out most of the claims in Farley v Paymaster (1836) Ltd [2024] EWHC 383 (KB).

His essential conclusion was that, save for 14 claimants whose cases contained evidence capable of supporting the proposition that an envelope had been opened, the officers had no real prospect of establishing that their information had actually been read by a third party. In substance, the remaining cases amounted to what he described as a “near miss”.4

But Nicklin J deliberately declined to decide the question now before the Supreme Court.

He said it was neither necessary nor desirable to reach a concluded view on whether English data protection law imposed a threshold of seriousness. Given the importance of the point, he considered that it should be decided, if necessary, against facts established at trial rather than facts assumed for the purposes of strike-out or summary judgment.5

That distinction matters. The Court of Appeal did not reverse a High Court ruling that Article 82 contained a seriousness threshold. There was no such ruling. The threshold question was left open.

The Court of Appeal draws a different line

The Court of Appeal allowed the officers’ appeal in Farley v Paymaster (1836) Ltd [2025] EWCA Civ 1117.

Lord Justice Warby, giving the judgment of the court with which Lady Justice King and Lady Justice Whipple agreed, rejected the premise that a claimant had to prove that the contents of a statement were actually disclosed to another person before a relevant infringement could be established. Sending the statements to obsolete addresses was itself capable of constituting processing contrary to the GDPR.6

Paymaster nevertheless advanced an alternative argument: even if an infringement could be shown and non-material harm was alleged, compensation should not be available unless that harm crossed a minimum threshold of seriousness.

The Court of Appeal rejected that proposition too.

legal graphic

Damage first, seriousness second

The legal distinction at the heart of the appeal is easily obscured.

Article 82(1) of the GDPR provides that a person who has suffered material or non-material damage as a result of an infringement has a right to receive compensation for the damage suffered. Section 168(1) of the Data Protection Act 2018 expressly provides that “non-material damage” includes distress.7

Because the events occurred in 2019, the applicable instrument is the EU GDPR as it then had direct effect in the United Kingdom, supplemented by the Data Protection Act 2018. References to the post-Brexit UK GDPR are relevant to the interpretive question, but it was not the operative regulation when these statements were misaddressed.8

The European case law draws a distinction between two questions.

First, has the claimant suffered “damage” at all?

Secondly, if damage has been established, may a domestic court nevertheless refuse compensation because it regards that damage as insufficiently serious?

In UI v Österreichische Post AG (Case C-300/21) [2023] 1 WLR 3702, the Court of Justice of the European Union held that an infringement of the GDPR alone is insufficient. Damage must actually have been suffered and there must be a causal link between the infringement and that damage. But it also held that Article 82 precludes a domestic rule or practice requiring non-material damage to reach a specified degree of seriousness before compensation is available.9

That approach was subsequently repeated in cases including VB v Natsionalna agentsia za prihodite (Case C-340/21) [2024] 1 WLR 2559 and BL v MediaMarktSaturn Hagen-Iserlohn GmbH (Case C-687/21) [2024] 1 WLR 2597.10

The distinction is fundamental. The absence of a seriousness threshold does not mean that every infringement generates damages. It means that once a claimant proves something which legally qualifies as damage, the court cannot necessarily impose a second hurdle requiring that damage to be grave enough to count.

Warby LJ put the point with particular care. He observed that “fleeting or transient subjective reactions” might not qualify as non-material damage in the first place. The CJEU authorities, he said, did not establish that every negative emotional reaction to an infringement was compensable. They established that a claimant who proves harm falling within the concept of non-material damage does not then have to show that it reaches an additional level of gravity.11

That may be the most important distinction in the entire case.

Fear of misuse must still be well founded

The Court of Appeal also imposed a significant evidential discipline on claims based upon fear of what might happen to personal data.

In VB, the CJEU held that fear of future misuse can itself constitute non-material damage, but the national court must determine whether that fear is well founded in the particular circumstances. In BL, the court made the corresponding point that a purely hypothetical risk of future misuse cannot generate compensation.10

Warby LJ treated that as importing an objective standard of reasonableness.

A claimant relying upon fear therefore cannot succeed merely by saying that the breach caused worry. Each officer must ultimately establish a reasonable factual basis for fearing both that the statement had been or might be opened and read, and that the information might then be misused in the way feared.12

That is likely to matter greatly if the litigation returns to the facts of the individual claims. Warby LJ noted that the overwhelming majority of people who receive correspondence plainly marked private and confidential but addressed to somebody else would be expected to return, retain or discard it rather than open it. Nearly six years after the incident, the Court of Appeal also had no evidence before it of actual misuse of the information.13

Removing a formal seriousness threshold therefore does not remove the claimant’s burden of pleading and proving compensable harm.

The costs problem has not disappeared

The litigation also exposes a procedural problem familiar in modern data claims: the relationship between very modest individual damages and very substantial collective litigation costs.

Nicklin J recorded that claimant costs had reached just short of £2 million by the High Court hearing. The claimants’ estimated budget for a trial of lead cases was £2.549 million and Paymaster’s £2.7 million. By contrast, counsel for the claimants estimated the value of a typical individual claim without personal injury at about £1,250 to £1,500.14

The Court of Appeal did not dismiss that disparity as irrelevant. Warby LJ described the costs figures as “certainly very large” and accepted that arguments about proportionality were serious. But he held that modest claims should ordinarily be dealt with by finding a proportionate procedure rather than creating a substantive rule which extinguishes them.15

That leaves defendants with several filters even if Paymaster loses in the Supreme Court. They can dispute whether an infringement occurred, whether legally cognisable damage was suffered, whether it was caused by the infringement, whether a claimed fear was objectively well founded and whether the claimant can prove the pleaded facts. In an appropriate case they may also invoke the court’s jurisdiction to prevent proceedings which are objectively pointless or wasteful under Jameel v Dow Jones & Co Inc [2005] EWCA Civ 75, [2005] QB 946.

What they would not have, on the Court of Appeal’s analysis, is a free-standing rule allowing an otherwise valid claim to fail simply because the proved damage was considered too small.

A post-Brexit problem hiding inside a privacy case

The appeal carries a second and more constitutional question.

The CJEU authorities on which the Court of Appeal relied were decided after the end of the Brexit implementation period. English courts are not bound by those later decisions. Paymaster therefore argued that the domestic courts should take a different course.

Its case drew support from domestic authority including Lloyd v Google and from the fact that a seriousness threshold unquestionably exists in the separate tort of misuse of private information. Why, it asked in substance, should closely related privacy regimes treat trivial harm differently?

Warby LJ rejected the analogy. The Supreme Court had already made clear in Lloyd that two legal regimes protecting the same broad value do not necessarily have to protect it in the same manner or provide identical remedies. Data protection is a statutory regime with its own language and structure.16

The more difficult point concerned what weight should be given to Luxembourg after Brexit.

Warby LJ accepted that the United Kingdom was free, as a matter of political choice and legislation, to take a different course. But he held that a judicial departure from settled CJEU interpretation would require sufficiently compelling legal reasons. Of particular significance was Parliament’s decision, in the domestic successor regime, to retain language in the UK GDPR identical in the respects material to the case. Divergent judicial interpretations of the same wording, he observed, tend to undermine legal certainty.17

The importance of that question extends beyond privacy law.

In an Oxford lecture in April, Lord Sales examined the constitutional place of assimilated law and expressly identified Farley as an example of the difficulty confronting domestic courts when post-Brexit CJEU decisions interpret legislation from which continuing UK law derives. He noted that the Court of Appeal had followed a consistent line of post-completion CJEU authority and that Parliament had retained materially identical language in the domestic successor legislation.18

Lord Sales also emphasised the wider difficulty. English courts cannot simply assume that domestic law must continue moving in lockstep with Luxembourg after Brexit. Equally, the European origins and purposes of assimilated legislation do not vanish merely because the constitutional framework has changed.

His lecture cannot properly be treated as an indication of the result in an appeal on which he now sits. But it demonstrates why Farley is more than a dispute about compensation for misdirected pension statements.

Mass claims in the background

The practical significance can already be seen elsewhere in the High Court.

In Spurgeon and others v Capita plc [2026] EWHC 241 (KB), 3,973 individual claimants are seeking damages following a cyber attack, including for alleged mental distress. Master Dagnall’s judgment refers to Farley in considering both the substantive claims and the procedures appropriate to large multiple-claimant data litigation.19

A ruling for Paymaster would give defendants in such litigation another substantive weapon: a claimant might establish infringement, causation and some non-material harm yet still fail because the court regarded that harm as insufficiently serious.

If the Supreme Court upholds the Court of Appeal, modest claims will remain possible, but not automatic. The battleground will move instead to the anterior questions: what counts as damage, whether it was actually suffered, whether the breach caused it and, in claims based upon apprehension of future misuse, whether that apprehension had an objectively reasonable foundation.

The distinction is subtle, but commercially significant.

The line the Supreme Court must draw

The case therefore presents a more precise question than whether trivial data breaches should attract compensation.

No party needs the Supreme Court to establish that an infringement alone is insufficient. Article 82 already requires damage resulting from the infringement. Nor does the Court of Appeal’s judgment relieve claimants of the need to prove their case.

The disputed proposition comes one stage later.

If a claimant proves an infringement, proves that it caused harm and proves that the harm falls within the legal concept of material or non-material damage, may an English court nevertheless say: the damage is real, but it is too slight for the law to compensate?

That is the additional threshold Paymaster asks the Supreme Court to recognise.

The hearing is listed to conclude on Thursday 8 October. Judgment will follow at a later date. Whatever the result, the court’s reasoning is likely to matter not only to the economics of low-value data litigation but also to a wider post-Brexit question which English courts will repeatedly encounter: when Parliament retains European legislative language, how far should subsequent European interpretation continue to influence what that language means here?


Authorities

  1. Michael Farley and 431 others v Paymaster (1836) Ltd (trading as Equiniti), UKSC/2025/0185, Supreme Court case summary and issue on appeal.
  2. Farley v Paymaster (1836) Ltd [2024] EWHC 383 (KB), [2]–[12]; Farley v Paymaster (1836) Ltd [2025] EWCA Civ 1117, [1]–[12].
  3. Farley [2025] EWCA Civ 1117, [41]–[43].
  4. Farley [2024] EWHC 383 (KB), [143]–[158].
  5. Farley [2024] EWHC 383 (KB), [159].
  6. Farley [2025] EWCA Civ 1117, [28]–[40].
  7. Regulation (EU) 2016/679, art 82(1); Data Protection Act 2018, s 168(1).
  8. Farley [2025] EWCA Civ 1117, [28]–[29], [41]–[42].
  9. UI v Österreichische Post AG (C-300/21) [2023] 1 WLR 3702, [32]–[33], [42], [44]–[51]; Farley [2025] EWCA Civ 1117, [54]–[56].
  10. VB v Natsionalna agentsia za prihodite (C-340/21) [2024] 1 WLR 2559; BL v MediaMarktSaturn Hagen-Iserlohn GmbH (C-687/21) [2024] 1 WLR 2597; Farley [2025] EWCA Civ 1117, [57]–[60], [73]–[75].
  11. Farley [2025] EWCA Civ 1117, [70]–[72], [95].
  12. Farley [2025] EWCA Civ 1117, [75]–[85], particularly [78] and [81].
  13. Farley [2025] EWCA Civ 1117, [82]–[84].
  14. Farley [2024] EWHC 383 (KB), [9]–[12].
  15. Farley [2025] EWCA Civ 1117, [96]–[104]. See also Mueen-Uddin v Secretary of State for the Home Department [2024] UKSC 21, [2024] 3 WLR 244, [81].
  16. Lloyd v Google LLC [2021] UKSC 50, [2022] AC 1217, [124]; Farley [2025] EWCA Civ 1117, [68]–[69].
  17. Farley [2025] EWCA Civ 1117, [61]–[76], particularly [67].
  18. Lord Sales, “The concept, status and constitutional place of assimilated law in the post-Brexit legal order”, Assimilated Law Conference, Oxford, 13 April 2026, pp 18–21.
  19. Spurgeon and others v Capita plc [2026] EWHC 241 (KB).