Case details
Summary
Anonymity in civil proceedings is a strictly necessary derogation from open justice. A large data-protection claim does not create a general entitlement to anonymity. Claimants must establish, by clear and cogent evidence, why anonymity is necessary for each individual or a properly identified sub-group, and the order must go no further than proportionately required. Generic assertions of security risks, distress, hostile actors or the sensitivity of armed-forces service are insufficient. Targeted protective or case-management orders may remain available where particular risks or confidential information are demonstrated.
Factual background
The claimants, numbering 2,502, brought a data-breach claim against a company which processed personal data for the Ministry of Defence. They applied for an order under CPR r 39.2(4), with consequential restrictions under CPR rr 5.4C and 5.4D, preserving the confidentiality of their identities and identifying details.
The application relied on the alleged sensitivity of the claimants’ personal data, their current or former association with HM Crown Forces, and asserted risks of further harm, hostile exploitation and blackmail. The defendant remained formally neutral but challenged whether the strict necessity and evidential thresholds were met. The central issue was whether wide, class-based anonymity had been justified.
Held
- Application dismissed. The claimants had not established that anonymity was necessary to secure the proper administration of justice or protect their legitimate interests. Costs were summarily assessed, but the amount was not stated in the judgment.
- Open justice is the starting point. Any derogation must be exceptional, strictly necessary, and no wider than required. The burden lies on the applicant and must be discharged by clear and cogent evidence. These principles apply with equal force to data-protection claims.
- A cohort application does not remove the need for individualised evidence. Claimants must identify relevant sub-groups, where appropriate, and explain why the necessary threshold is met for the particular people concerned. Generalised evidence concerning 2,502 claimants was inadequate.
- Assertions that naming the claimants would expose them to serious or grave harm, or that their armed-forces roles were inherently private or risky, did not establish engagement of Convention rights or satisfy the evidential test. The court would not infer risk merely from current or former service in the armed forces.
- The argument that publication would aggravate the distress caused by a data breach would, in substance, make anonymity available in data-breach claims generally. That would unjustifiably curtail open justice.
- Speculation about hostile nation states, hackers, the resale of data, wider circulation or blackmail could not substitute for evidence identifying risks to particular claimants. The absence of specific evidence about individuals said to have especially sensitive roles was material.
- The court retained power to make targeted protective or case-management orders where particular risks or confidential information were demonstrated. Future applicants should also consider giving advance notice to the media, including through the Press Association’s Injunction Application Alert Service.
The court’s approach to earlier authorities
This feature is available to zoomLaw Pro members.
Key cases cited
This feature is available to zoomLaw Pro members.
Cases citing this case
This feature is available to zoomLaw Pro members.