GDPR

All eyes on the Supreme Court: does a 'threshold of seriousness' apply to claims in respect of a data breach?

Published on 5 October 2026

A ruling of no threshold requirement could increase the volume of claims organisations face following data incidents, even where the harm caused is minimal

Virtual map of the world

At a glance

  • Last year, the Court of Appeal ruled that claims for damages for breaches of the GDPR are not subject to a minimum seriousness threshold.

  • The Supreme Court is set to hear argument on the issue on 7 and 8 October 2026.

  • If no seriousness threshold applies, this could spur more data breach claims, though individual claimants must still show their fear of harm is objectively well-founded.

In 2019, Equiniti, a pensions scheme administrator, mistakenly sent pension benefit statements for over 750 police officers to out-of-date residential addresses. The statements contained personal data, as well as details of each member's accrued benefits under the pension scheme. Over 400 affected members brought claims for damages under the General Data Protection Regulation (GDPR) in respect of the distress they allegedly suffered as a result, in Farley and others v Paymaster (1836) Limited (trading as Equiniti).

High Court decision

In the High Court, the majority of the individual police officers' claims were struck out on the basis that those claimants could not prove that the envelope containing the annual benefit statement had in fact been opened by a third party. The judge accordingly found that there had been no "processing" of the address data for the purposes of the GDPR claims.

Fourteen claims were permitted to continue, on the basis that those claimants had a reasonable prospect of proving that the envelope had in fact been opened.

Court of Appeal decision

The claimants subject to strike out appealed to the Court of Appeal in 2025. In a decision that was broadly unfavourable to data controllers, the Court of Appeal held that:

  • a claim can be brought on the basis that personal data was mistakenly sent to a third party; proving the correspondence was actually opened is not a necessary element of "processing" of data;
  • compensation is in principle available for an individual's "fear of the consequences" of a breach, provided that fear is "objectively well-founded" rather than "purely hypothetical or speculative"; and
  • there is no de minimis "threshold of seriousness" below which a claim under GDPR for non-material damage (such as distress rather than financial loss) cannot be pursued.

The Court of Appeal declined to depart from recent Court of Justice of the EU (CJEU) case law establishing that no minimum threshold of seriousness applies in respect of the regime for the protection of personal data. It noted that the EU GDPR had direct effect in the UK in 2019 (at the time of the events), and that departing from the relevant case law now would undermine legal certainty.

It suggested that the position would likely be the same under the UK GDPR, given that it uses the same language as the relevant provisions of the GDPR. However, although the wording may match, its constitutional foundations differ: the UK GDPR is now underpinned by Convention rights within the meaning of the Human Rights Act 1998. There may therefore still be room to argue that the UK GDPR position should diverge from the EU GDPR approach, and align more closely with the privacy law standard under the UK's Human Rights Act.

Supreme Court appeal

Equiniti was granted permission to appeal the Court of Appeal's judgment to the Supreme Court on a single issue: whether a minimum threshold of seriousness applies in England and Wales to damages claims brought under the GDPR and the Data Protection Act 2018. 

The Supreme Court is due to hear argument on this issue on 7 and 8 October 2026. At the heart of the debate is whether the Supreme Court should, like the Court of Appeal, see no reason to depart from post-Brexit CJEU case law, or whether it should instead follow English and Commonwealth authorities.

The Information Commissioner and the Open Rights Group have been permitted to intervene, and have made submissions which are supportive of the argument that there is no threshold of seriousness, including on wider policy grounds. 

Osborne Clarke comment

If the Supreme Court upholds the Court of Appeal's ruling that no minimum threshold of seriousness applies to data protection claims, this is likely to result in a significant increase in relatively low-value data protection compensation claims against data controllers, compounded by the growing prevalence of AI-generated claims and letters before action. 

Claimants will still need to prove to the court that their fear of harmful consequences of a data breach is objectively justifiable in order to claim damages, whatever the outcome of the Supreme Court hearing. This may be challenging in the context of fairly trivial breaches. 

The requirement for an individualised assessment will also continue to underpin the proportionality and risk considerations made by lawyers and funders who are considering the merits of pursuing claims on a collective and no-win no-fee basis.

* This article is current as of the date of its publication and does not necessarily reflect the present state of the law or relevant regulation.

Interested in hearing more from Osborne Clarke?