Michael Farley & Anor v Paymaster (1836) Limited (trading as Equiniti)
[2025] EWCA Civ 1117
Case details
Case summary
The Court of Appeal allowed the appellants' challenge to the judge's decision to strike out most data protection claims on the basis that proof of disclosure to a third party was an essential element of an actionable infringement. The court held that "processing" under the GDPR/DPA is of broad scope and does not require third‑party disclosure, and that proof of disclosure was not necessary to plead an infringement of Articles 5, 24, 25 or 32 (or Article 82 in relation to compensation). The court rejected the existence of a domestic threshold of seriousness for GDPR non‑material damage, emphasising CJEU authority that no de minimis requirement should be imposed. It held that compensation for fear of misuse is in principle available but only where that fear is objectively well founded; the court remitted the factual assessment of which individual claims meet that test to the High Court. The court also held that the Jameel abuse jurisdiction did not permit wholesale summary dismissal of the class of claims, although individual claims may be abusive on their facts.
Case abstract
Background and parties:
- The appellants are members of a pension scheme administered by the respondent Equiniti. In August 2019 annual benefit statements were mailed in window envelopes to a substantial number of out‑of‑date addresses because the respondent's system used previous addresses in error. Some statements were returned unopened, some were retrieved by intended recipients, and the fate of many remains unknown.
- The respondent accepted a data breach and was notified to the Information Commissioner. The appellants (initially several hundred claimants across a collective claim) sought damages under the GDPR and the Data Protection Act 2018 and, originally, for misuse of private information.
- The Information Commissioner intervened in the appeal.
Nature of the claim / relief sought:
- The claimants sought compensation for non‑material damage (distress, anxiety, alarm and embarrassment) arising from the respondent's alleged breaches of data protection obligations (including Articles 5, 24, 25 and 32 of the GDPR) and for aggravation of pre‑existing medical conditions in some cases.
Procedural posture:
- At first instance Nicklin J struck out all but 14 of the claims on the basis that claimants could not show their statements were opened and read and that, absent such disclosure, there was no "misuse" or actionable processing.
- The appellants appealed. The respondent sought permission in this court to advance alternative grounds for dismissal; permission was granted.
Issues framed:
- Whether the appellants had pleaded a reasonable basis for alleging an infringement of the GDPR/DPA (the "infringement issue");
- Whether the appellants had pleaded a tenable claim for compensation under Article 82 and the DPA, including whether a claim based on fear of third‑party misuse could succeed (the "compensation issue");
- Whether the claims were nonetheless an abuse of process under the Jameel principle (the "Jameel issue").
Court's reasoning and conclusions:
- Processing/infringement: the court held that the definition of "processing" in Article 4(2) GDPR (and the corresponding DPA provisions) is broad and covers the recording, organising, storing, printing and posting of the ABS. The judge was wrong to make proof of third‑party disclosure an essential element of an actionable GDPR infringement.
- Compensation: Article 82 provides a right to compensation for material or non‑material damage; section 168(1) DPA confirms that "non‑material damage" includes distress but does not limit the concept. The Court of Appeal followed CJEU authority that domestic courts may not impose a de minimis or threshold of seriousness for recovery under Article 82. However, the CJEU jurisprudence requires that a claimant relying on fear of misuse must show that the fear was objectively well founded; a purely hypothetical risk is insufficient.
- Application to these claims: the court held that the judge could not properly strike out the claims wholesale. The viability of each claim based on fear must be assessed case by case. The court declined to perform that extensive factual assessment itself and remitted the matter to the High Court to determine which individual claims (if any) disclose a well‑founded fear and are therefore capable of success; consequential psychiatric claims depend on that threshold finding.
- Jameel: the court concluded that the Jameel abuse jurisdiction did not justify bypassing a case‑by‑case factual assessment; the class cannot be characterised as abusive as a whole, though individual claims may be abusive depending on their facts and litigation conduct.
Held
Appellate history
Cited cases
- Prismall v Google UK Ltd & Ors (appeal), [2024] EWCA Civ 1516 negative
- Mueen-Uddin v Secretary of State for the Home Department, [2024] UKSC 21 neutral
- Lloyd v Google LLC, [2021] UKSC 50 negative
- Three Rivers District Council v. Governor and Company of The Bank of England, [2001] UKHL 16 neutral
- Campbell v Mirror Group Newspapers Ltd, [2002] EWCA Civ 1373 positive
- Jameel (Yousef) v Dow Jones & Co Inc, [2005] EWCA Civ 75 neutral
- UI v Österreichische Post AG, Case C-300/21 positive
- Data Protection Commissioner v Facebook Ireland Ltd, Case C-311/18 positive
- VB v Natsionalna agentsia za prihodite, Case C-340/21 positive
- VX v Gemeinde Ummendorf, Case C-456/22 positive
- BL v MediaMarktSaturn Hagen-Iserlohn GmbH, Case C-687/21 positive
- Endemol Shine Finland Oy, Case C-740/22 positive
Legislation cited
- Data Protection Act 2018: Part 2
- Data Protection Act 2018: Section 168(1)
- Data Protection Act 2018: section 3(2) and (3)
- Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019: Regulation SI 2019/419
- European Union (Withdrawal) Act 2018: Section 2
- European Union (Withdrawal) Act 2018: Section 3
- European Union (Withdrawal) Act 2018: Section 6
- General Data Protection Regulation: Regulation N/A – GDPR