Showing posts with label damage. Show all posts
Showing posts with label damage. Show all posts

Tuesday, 31 March 2026

Data Breach - Farley and Others v Paymaster (1836) Ltd

Brighton Town Hall
Author Hassocks5489  Licence CCO 1.0  Source Wikimedia Commons























Court of Appeal (Lady Justice King, Lord Justice Warby and Lady Justice Whipple)  Farley and others v Paymaster (1836) Ltd (t/a Equiniti) [2025] EWCA Civ 1117 (22 Aug 2025)

This was an appeal against the order of Mr Justice Nicklin in Farley and Others v Paymaster (1836) Ltd (Trading As Equiniti) [2024] EWHC 383 (KB) (23 Feb 2024), striking out most of the individual claims in a collective action arising from a data breach.  The appeal came before Lady Justice King, Lord Justice Warby and Lady Justice Whipple on 17 and 18 June 2025.  Counsels' arguments were filmed and can be viewed on YouTube at Farley (appellant) v Paymaster (1836) Limited (t/a Equiniti) (respondent) 17 June and ent) 18 June. The Court of Appeal allowed the appeal on 22 Aug 2025 (Farley and Others v Paymaster (1836) Ltd (t/a Equiniti) [2025] EWCA Civ 1117 (22 Aug 2025).  Permission to appeal to the Supreme Court was granted on 17 Dec 2025.  The appeal is listed for 7 and 8 Oct 2026.

Background

The claimants were members of a pension scheme for officers of the Sussex Police administered by the defendant. In August 2019, the defendant administrator sent an annual benefit statement to each member of the scheme. The statement contained an overview of the member's accrued benefits together with his or her name, date of birth, national insurance number and details of his or her salary and pension details. It would have been apparent to anybody reading the statement that the member was or had been a police officer.   The defendant sent some 750 of those statements to wrong addresses. The members affected alleged that this was a misuse of their personal information and an infringement of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA relevance)
OJ L 119, 4.5.2016, pp. 1–88 ("the GDPR"). Those members complained that the infringement had led to injury to their feelings, and in some cases, psychiatric harm from fear of third-party misuse of their personal data. They sued the administrator for compensation for the damage that they had suffered under art 82 (1) of the GDPR.

The Defendant's Application

The defendant applied to strike out the claim for failing to disclose a cause of action, or alternatively summary judgment.  The application came on for hearing before Mr Justice Nickin on 27 and 28 Feb 2023.  The learned judge received written submissions on 18 and 19 May and 1 June 2023.   His lordship allowed the claims of 14 members to proceed as they could show that their statements had been read, but he struck out the remaining claims which numbered over 400.

The Appeal

The members whose claims had been struck out appealed on the ground that the judge had been wrong in law.   In particular, he had been wrong to regard disclosure of the benefit statement to a third party as an essential ingredient of a viable data protection claim. The appellants contended that posting the statement to the wrong address infringed their rights under the data protection legislation. The defendant argued that the compensation claims were factually incredible, insufficient or untenable as a matter of law, or so trivial that they should be dismissed as an abuse of process of the kind identified in Jameel v Dow Jones Inc [2005] EMLR 16, [2005] QB 946, [2005] 2 WLR 1614, [2005] EMLR 353, [2005] EWCA Civ 75.

The Issues

Lord Justice Warby, who delivered the lead judgment, summarized the main issues at para [5]:
The Data Protection Legislation

The learned Lord Justice condensed the data protection legislation in para [28] of his judgment:
"The GDPR is EU legislation with direct effect in all EU member states. It enacts a number of data protection rights and obligations and contains provision for their enforcement. Article 5 identifies six 'principles relating to processing of personal data' with which data controllers must comply. Articles 24, 25 and 32 require data controllers to 'implement appropriate technical and organisational measures' to ensure GDPR compliance. Article 82 confers a right to receive compensation for material or non-material damage suffered as a result of an infringement. The GDPR applied with effect from May 2018. By Part 2 of the [Data Protection Act 2018], Parliament enacted provisions supplemental to the GDPR. Those provisions also came into force in May 2018."
He explained at [29] that these are the legislative instruments that apply to the events with which the Court was concerned because the European Union (Withdrawal) Act 2018 provided for the GDPR to remain part of English law until 23:00 on 31 Dec 2020.

Interpretating the GDPR

Lord Justice Warby added at [30] that English courts are bound by principles laid down by the Court of Justice of the European Union ("CJEU") and decisions made by it before 31 Dec 2020 as these are "assimilated EU case law" but not by any principles laid down, or any decisions made, by the CJEU after that date.  English courts "may have regard" to such principles or decisions "so far as it is relevant to any matter before the court". In deciding how to approach the latter class of CJEU decisions, English courts are bound by the law of precedent.

Infringement Issue

His lordship said that the first question to be considered in determining whether the administrator's mistake amounted to an infringement of the GDPR was whether the claimants had set out a reasonable basis for alleging that the defendant had engaged in "processing" their "personal data" within the meaning of the regulation and of the Act.    

He considered the definitions of "personal data" in art 4 (1) of the regulation and s.3 (2) of the Act and described them as "language of extremely broad reach." He added that there had never been any dispute that the information at issue here fell within that language and concluded that clearly it did.  

He turned his attention to the definition of "processing" in art 4 (2) of the regulation and s.3 (4) of the Act. Their definitions, which were very similar, defined "processing" as "any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means" with such illustrative examples as "collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction."  He recalled the CJEU's discussion of art 4 (2) in para [35] of its judgment in Case  C-175/20 “SS” SIA v Valsts ieneumu dienests, EU: C:2022:124, ECLI: EU:C:2022:124, [2022] EUECJ C-175/20:
"It is apparent from the wording of that provision, in particular from the expression 'any operation', that the EU legislature intended to give the concept of 'processing' a broad scope. That interpretation is corroborated by the non-exhaustive nature, expressed by the phrase 'such as', of the operations mentioned in that provision."

Lord Justice Warby noted at [36] that it was common ground that the defendant's operations amounted to "processing."

The learned Lord Justice observed that the defendant might have argued that printing out the statements, stuffing them into envelopes and posting them were manual operations after the processing had been completed, but it did not do so. It actually admitted that those steps did constitute processing.   On the basis of that admission, his lordship ruled that there was no basis for striking out those aspects of the claims.

Compensation Issue

Art 82 GDPR provides:

"(1) Any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller ... for the damage suffered."
(2) Any controller involved in processing shall be liable for the damage caused by processing which infringes this Regulation ..."
Before 31 Dec 2020, s.168 (1) of the Data Protection Act 2018 amplified art 82 (1) of the GDPR (right to compensation for material or non-material damage), by adding that 'non-material damage' included distress.

The claimants had pleaded that each of them experienced "anxiety, alarm, distress and embarrassment" at the prospect or possibility that their personal data may have come into the hands of third parties and been misused or exposed to the risk of misuse. That was expressly pleaded as "non-material damage". Secondly, 42 of them alleged that the infringements aggravated a pre-existing medical condition for which general damages were sought without particularizing such aggravation as material or non-material damage.   The administrator invited the Court of Appeal to dismiss those claims as incredible under CPR Part 24.  His lordship declined the invitation as it would have been a strong thing to reject statements of truth without hearing from the witnesses. He did not consider that the Court would be justified in taking that step.

The defendant's next point was that on the true construction of the GDPR and the Data Protection Act 2018, compensation was not recoverable for emotional responses other than distress. Lord Justice Warby rejected that submission. He said that the governing provision was art 82, which referred to "non-material damage" without limitation. S.168 (1) of the Act added that this term "included distress" but it was plain that that was an illustrative point. S.168 did not purport to define or limit the scope of the term "non-material damage" in art 82. Indeed, it seemed clear that Parliament's aim in enacting s.168 (1) was not to limit the ambit of the right to compensation but rather to confirm its breadth.

Despite such authorities as Case C‑300/2 UI v Österreichische Post AG [2023] WLR(D) 221, EU: C:2023:370, [2023] EUECJ C-300/21, ECLI:EU:C:2023:370, Case C‑340/21 VB v Natsionalna agentsia za prihodite EU: C:2023:986, ECLI:EU:C:2023:986, [2024] WLR(D) 17, [2023] EUECJ C-340/21, Case C-456/22 VX v Gemeinde Ummendorf EU: C:2023:988, ECLI:EU:C:2023:988, [2023] EUECJ C-456/22 and Case C‑687/21 BL v MediaMarktSaturn Hagen-Iserlohn GmbH, [2024] 1 WLR 2597, [2024] EUECJ C-687/21, ECLI:EU:C:2024:72, EU: C:2024:72, [2024] WLR(D) 53 to the contrary, the defendant administrator contended that there was a threshold of seriousness which the claimants had not cleared. It argued that the courts of the United Kingdom are no longer bound by decisions of the CJEU handed down after 23:00 on 31 Dec 2020, that they were bound by Lloyd v Google LLC  [2022] 2 All ER 209, [2022] HRLR 1, [2022] 1 All ER (Comm) 1107, [2022] AC 1217, [2021] 3 WLR 1268, [2022] EMLR 6, [2021] UKSC 50 and Prismall v Google UK Ltd [2024] EWCA Civ 1516, [2025] 2 WLR 1224 and that they should not follow the CJEU because its reasoning was flawed and that a threshold of seriousness would eliminate trivial claims and achieve coherence in the law.

Lord Justice Warby did not accept those arguments.  He reviewed the authorities on which the defendant relied and concluded that they did not support the contention that there was a threshold of seriousness for data protection claims in English law.  As for whether the English courts should take a different course from the CJEU, he accepted that it was an option for Parliament.  A judicial decision to do so would require compelling legal reasons.  He remarked at para [67] of his judgment:
"...... the GDPR is an international legal instrument which had direct effect in this jurisdiction at the material time. Further, its domestic successor, the UK GDPR, is post-Brexit legislation in which Parliament decided to adopt the identical language, so far as material to this case. Self-evidently, divergent interpretations of the same legislative text tend to undermine legal certainty. It seems to me that, other things being equal, it makes good legal sense for the court to interpret and apply the GDPR in conformity with settled CJEU jurisprudence."
He analysed the CJEU decisions mentioned above but could see no sufficiently weighty reason for departing on this appeal from the settled CJEU jurisprudence on the threshold of seriousness issue.

However, he said that it was clear from those cases that a claimant could recover compensation for fear of the consequences of an infringement, provided the alleged fear was objectively well-founded.

The Jameel Issue

The defendant relied on the Jameel principle in the strikeout application.   It was summarized by the Court of Appeal in para [175] of their judgment in Municipio de Mariana v BHP Group (UK) Ltd [2022] EWCA Civ 951, [2022] 1 WLR 4691, [2023] 1 All ER 611, [2022] WLR(D) 300, [2022] WLR 4691:
"[P]roceedings may ... be abusive if, even though they raise an arguable cause of action, they are (objectively) pointless and wasteful, in the sense that the benefits to the claimants from success [are] likely to be extremely modest and the costs to the defendants in defending the claims wholly disproportionate to that benefit" (citing Jameel (Yousef) v Dow Jones Co Inc [2005] EWCA Civ 75, [2005] QB 946)

The Supreme Court considered the principle further in Mueen-Uddin v Home Secretary  [2024] UKSC 21, [2024] EMLR 13, [2024] 3 WLR 244, CLW/24/23/1, [2024] 3 All ER 985, [2024] WLR(D) 283.

The administrator relied on the principle in its strikeout and summary judgment application, but Mr Justice Nicklin did not accept it.  It cross-appealed to the Court of Appeal with limited success.  Lord Justice Warby said at para [6 (3)] of his judgment:

"The Jameel jurisdiction does not provide a reason to bypass that process. These claims as a class cannot be categorised as Jameel abuse although the question of whether any individual case is abusive will remain for consideration."

The fact that a claim was small did not mean that it was abusive.  Lord Justice Warby quoted Lord Justice Lewison in Sullivan v Bristol Film Studios [2012] EWCA Civ 570, [2012] EMLR 27 at [29]:

"The mere fact that a claim is small should not automatically result in the court refusing to hear it at all. If I am entitled to recover a debt of £50 .... it would be an affront to justice if my claim were simply struck out."

The defendant had understandable concerns about costs and the difficulty of recovering them if it was successful, but that did not make the proceedings abusive.

The Supreme Court Appeal

The issue on which permission to appeal was granted is whether a threshold of seriousness applies to claims for damages under the GDPR and the Data Protection Act 2018.

Comment

This is an important decision on claims under art 82 (1) for compensation for material and non-material damage resulting from an infringement of the GDPR.  Should the Supreme Court allow Paymaster (1836) Ltd.'s appeal on thresholds of seriousness, its importance will be all the greater.  The Court of Appeal has ruled on what constitutes an infringement and whether concern over who may be reading confidential statement information of itself constitutes non-material damage.  The Court has also followed the CJEU's decisions on thresholds of seriousness and rejected the Jameel principle.  

Anyone wishing to discuss this case or this article may call me on +44 (0)20 7404 5252 during UK office hours or send me a message through my contact form at any time.

Sunday, 29 March 2026

Art 82 (1) GDPR - GP v Juris GmbH

Landgericht Saarbrücken
Author Anna16 Licence CC BY-SA 3.0  Source Wikimedia Commons

 









Jane Lambert

Court of Justice of the European Union (K. Jürimäe, President of the Chamber, N. Piçarra and N. Jääskinen (Rapporteur), Judges), Case 741/21 GP v juris GmbH  [2024] EUECJ C-741/21, ECLI:EU:C:2024:288, EU: C:2024:288

This was a request by the Landgericht Saarbrücken for a preliminary ruling on the interpretation of art 82 (1) and (3) of the GDPR (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA relevance) OJ L 119, 4.5.2016, pp. 1–88) read in conjunction with arts 29 and 83 and the 85th and 146th recitals. The request was made in the course of proceedings that the claimant, GP, had brought against juris GmbH, the defendant, for compensation for damage arising from the defendant's unauthorised processing of his personal data.

The Dispute

The defendant published online legal information as well as newsletters.  One of its subscribers was the claimant, a lawyer in independent private practice.  He discovered that juris GmbH had used his personal data for direct marketing.  He withdrew his consent to the processing of his personal data and closed his email and telephone updating accounts, but continued to receive newsletters from the defendant company.   Even though he had withdrawn his consent, he continued to receive mailshots from juris, including some with a code that enabled him to access an online form containing his personal data, which had been created long after he had withdrawn his consent to the processing of his personal data.

The Action

GP launched an action against juris GmbH in the Landgericht Saarbrücken (the intermediate court of first instance for Saarbrücken) for compensation for material and non-material damage under art 82 (1) of the GDPR. His material damage consisted of the costs of instructing a bailiff and notary.  He alleged that his loss of control over his personal data resulting from the unauthorised processing constituted non-material damage.  Juris denied liability.  It stated that it had established a system for managing objections to direct marketing.  Its explanation for the stray mailshots was isolated slip-ups by its employees, and that the cost of preventing such slip-ups altogether was prohibitive. Mere breaches of obligation under the GDPR, such as non-compliance with objections under art 21 (3), cannot, by themselves, constitute ‘damage’ within the meaning of art 82 (1).

The Reference

The Landgericht Saarbrücken decided to stay the proceedings and refer the following questions to the Court of Justice of the European Union ("CJEU") for a preliminary ruling under art 267 of the Treaty on the Functioning of the European Union:

"(1) In the light of recital 85 and the third sentence of recital 146 of the GDPR, is the concept of ‘non-material damage’ in Article 82 (1) of the GDPR to be understood as covering any impairment of the protected legal position, irrespective of the other effects and materiality of that impairment?
(2) Is liability for compensation under Article 82 (3) of the GDPR excluded by the fact that the infringement is attributed to human error in the individual case on the part of a person acting under the authority of the processor or controller within the meaning of Article 29 of the GDPR?
(3) Is it permissible or necessary [to base] the assessment of compensation for non-material damage [on the] criteria for determining fines set out in Article 83 of the GDPR, in particular in Article 83 (2) and 83(5) of the GDPR?
(4) Must the compensation be determined for each individual infringement, or are several infringements - or at least several infringements of the same nature - penalised by means of an overall amount of compensation, which is not determined by adding up individual amounts but is based on an evaluative overall assessment?"

Judgment

The CJEU delivered its reply in Case 741/21 GP v juris GmbH  [2024] EUECJ C-741/21, ECLI:EU:C:2024:288, EU: C:2024:288 on 11 April 2024.

Legislation

The Court considered the 85th, 146th and 148th recitals of the GDPR and arts 4 (1), (7) and (12), 5, 21, 24 (1) and (2), art 25 (1), 29, 32 (1) (b), (2) and (4), 79, 82 (1), (2) and (3), 82 (2) (a), (b) and (k), (3) and (5) and 84 (1) of its provisions.

The First Question

Juris GmbH challenged the admissibility of the first question on the ground that the damage alleged by GP in the main proceedings, a loss of control over his personal data, did not occur.  It alleged that GP's data had been lawfully processed under his contract with the defendant company.  The CJEU rejected the challenge.  It was for the national court to determine the particular circumstances of the case, both the need for a preliminary ruling in order to enable it to deliver judgment in the proceedings before it and the relevance of the questions that it submits to the Court.  There was no reason in this case to doubt the question's relevance.

The Court reframed the Landgericht's first question as "whether Article 82 (1) of the GDPR must be interpreted as meaning that an infringement of provisions of that regulation which confer rights on the data subject is sufficient, in itself, to constitute ‘non-material damage’, within the meaning of that provision, irrespective of the degree of seriousness of the harm suffered by that person."  

Referring to para [58] of its judgment in  Case C‑687/21 BL v MediaMarktSaturn Hagen-Iserlohn GmbH, [2024] 1 WLR 2597, [2024] EUECJ C-687/21, ECLI: EU: C:2024:72, EU: C:2024:72, [2024] WLR(D) 53 and the cases cited therein, the Court noted that it had already interpreted art 82 (1) as meaning that the mere infringement of that regulation is not sufficient to confer a right to compensation.  The existence of ‘damage’, material or non-material, or of ‘damage’ which has been ‘suffered’ constitutes one of the conditions for the right to compensation laid down in art 82 (1).   So, too, does the existence of an infringement of that regulation and of a causal link between that damage and that infringement, those three conditions being cumulative.   Applying paras [60] and [61] of that judgment and the cases cited, a person seeking compensation for non-material damage under art 82 (1)  must establish not only the infringement of provisions of that regulation, but also that such infringement caused him or her such damage.

The Court added that it had interpreted art 82 (1) as precluding a national rule or practice which makes compensation for non-material damage subject to the condition that the damage suffered by the data subject has reached a certain degree of seriousness, while emphasising that that person is nevertheless required to demonstrate that the infringement of that regulation caused him or her such non-material damage (paras [59] and [60] of MediaMarktSaturn and the cases referred to in those paragraphs).

The answer to the first question was that art 82 (1) must be interpreted as meaning that an infringement of provisions of that regulation which confer rights on the data subject is not sufficient, in itself, to constitute ‘non-material damage’ within the meaning of that provision, irrespective of the degree of seriousness of the damage suffered by that person.

The Second Question

The Landgericht asked whether art 82 (3) must be interpreted as meaning a controller can be exempted from liability under art 83 (1) by claiming that the damage in question was caused by the failure of a person acting under his authority within the meaning of art 29.   

The Court observed that it had already held in Case C‑667/21 ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts ECLI:EU:C:2023:1022, EU: C:2023:1022, [2023] EUECJ C-667/21  from a combined analysis of art 82 (2) and (3) that that article provides for a fault-based regime, in which the controller is presumed to have participated in the processing constituting the breach of the GDPR in question, so that the burden of proof lies not with the person who has suffered damage but with the controller.

As an employee of the controller is a natural person acting under the authority of that controller, it is for that controller to ensure that his or her instructions are correctly applied by his or her employees. Accordingly, the controller cannot avoid liability under art 82 (3) simply by relying on negligence or failure on the part of a person acting under his or her authority.   If it were accepted that a controller could be exempted from liability merely by relying on the failure of a person acting under his or her authority, that would undermine the effectiveness of the right to compensation under art 82 (1).

The answer to the second question was that art 82 must be interpreted as meaning that it is not sufficient for the controller to claim that the damage in question was caused by the failure of a person acting under his or her authority within the meaning of art 29 to be exempted from liability under art 82 (3).

The Third and Fourth Questions

The CJEU took the referring court's third and fourth questions together.  That court had asked whether art 82 must be interpreted as meaning that it is necessary to:
  • apply mutatis mutandis the criteria for setting the amount of administrative fines laid down in art 83 GDPR, and/or 
  • take account of the fact that several infringements of the GDPE concerning the same processing operation affect the person seeking compensation
 In determining the amount of damages due as compensation for damage under that article.

The CJEU began by pointing out that arts 82 and 83 serve different functions. Art 82 governs the right to compensation and liability while art 83 determines the ‘general conditions for imposing administrative fines.    It follows that the criteria set out in art 83 for determining the amount of administrative fines cannot be used to assess the amount of compensation under art 82.

The GDPR does not contain any provision relating to the assessment of the damages due under art 82.  For the purposes of that assessment, the national courts must apply the domestic rules of each Member State relating to the extent of monetary compensation, provided that the principles of equivalence and effectiveness of EU law are complied with (see paras [83] and [101] of Krankenversicherung Nordrhein and the cases referred to and para [53] of MediaMarktSaturn).   The Court has emphasized that art 82 has a compensatory function and not punitive. The right to compensation does not fulfil a deterrent, or even punitive, function. It follows that the amount cannot exceed the full compensation for that damage (para [86] of Krankenversicherung Nordrhein).

As to the way in which national courts must assess the amount of monetary compensation under art 82 of in the case of multiple infringements affecting the same data subject, it should, first of all, be pointed out that it is for each Member State to establish the criteria for determining the amount of that compensation, subject to compliance with the principles of effectiveness and equivalence of EU law.  Next, in view of the compensatory rather than punitive function of art 82, the fact that several infringements have been committed by the controller in relation to the same data subject cannot constitute a relevant criterion for the purposes of assessing the compensation to be awarded to that data subject under art 82. Only the damage actually suffered by the data subject must be taken into consideration to determine the amount of money due by way of compensation.

The answer to the third and fourth questions is that art 82 (1) of the GDPR must be interpreted as meaning that it is not necessary to:
  • apply mutatis mutandis the criteria for setting the amount of administrative fines laid down in art 83; and/or 
  • take account of the fact that several infringements of that regulation concerning the same processing operation affect the person seeking compensation
to determine the amount of money due as compensation for damage based on that article.

Ruling

The CJEU ruled as follows:

"1. Article 82 (1) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) must be interpreted as meaning that an infringement of provisions of that regulation which confer rights on the data subject is not sufficient, in itself, to constitute ‘non-material damage’ within the meaning of that provision, irrespective of the degree of seriousness of the damage suffered by that person.
2. Article 82 of Regulation 2016/679 must be interpreted as meaning that it is not sufficient for the controller, in order to be exempted from liability under paragraph 3 of that article, to claim that the damage in question was caused by the failure of a person acting under his or her authority, within the meaning of Article 29 of that regulation.
3. Article 82 (1) of Regulation 2016/679 must be interpreted as meaning that in order to determine the amount of damages due as compensation for damage based on that provision, it is not necessary, first, to apply mutatis mutandis the criteria for setting the amount of administrative fines laid down in Article 83 of that regulation and, second, to take account of the fact that several infringements of that regulation concerning the same processing operation affect the person seeking compensation."

Comment

This is another important authority on the assessment of compensation for the infringement of the GDPR under art 82 (1).  In this decision, the CJEU made clear that the rules for assessing fines under art 83  are not to be taken into account for determining compensation under art 82 (1).  The regulation sets no criteria for such assessment other than that the function art 82 (1) is not punitive but compensatory.  It is a matter for the national courts subject to the principles of equivalence and effectiveness of EU law.

Another takeaway from the decision is that a controller cannot escape liability under art 82 (3) GDPR by showing that its employee had slipped up.   It is surprising that juris GmbH believed that the point was worth arguing.   As the Court observed, it would have undermined the right to compensation under art 82 (1) had juris GmbH succeeded.

Anyone wishing to discuss this article may call me on +44 (0)20 7404 5252 during normal UK office hours or send me a message through my contact form.

Saturday, 28 March 2026

Entitlement to Compensation - East Dunbartonshire Council v Paton

Southbank Marina
Author G, Laird Licence CC BY-SA 2.0 Source Wikimedia Commons

 











Jane Lambert

Sheriff Appeal Court Civil (Appeal Sheriff O'Carroll) East Dunbartonshire Council v Paton [2026] SAC (Civ) 17 (4 March 2026)

This was an appeal by East Dumbartonshire Council against an award of compensation under art 82 (1) UK GDPR to the father of a child for damage incurred as a result of the council's delay in rectifying a risk assessment form.  The local authority did not dispute that it had caused damage by the delay for which it had to pay compensation.  Nor did it dispute the amount of compensation.  The only issue in the appeal was whether the compensation had been paid to the right person.

Background

The child had been a pupil at a school maintained by the appellant council where she suffered bullying. Her father complained to the head teacher, who prepared a draft form assessing the risk to the child's physical safety as "medium" and the risk to her emotional well-being as "high".  The school sent the draft to the child's father for his consideration.

The school introduced control measures which led it to reduce its assessment of the risk to the child's physical safety as "low" and her emotional well-being as "medium".  The girl's father accepted that the measures had reduced the risks to his daughter but expressed concern that the risk to her well-being remained "medium".  He sought further advice from the school on reducing the risk to his child's well-being which the school provided the same day.

Despite the control measures, further difficulties arose which prompted the father to complain to the school.   The school rejected most of his complaints, whereupon the father resorted to the Scottish Public Services Ombudsman.  The ombudsman requested a risk assessment from the council.   Instead of sending the draft that had been shown to the child's father, the authority prepared a modified form showing the risk to her emotional well-being as "low".

Claim for Rectification

After seeing the modified form, the father asked the local authority to amend the risk assessment to his daughter's well-being.  The council admitted that its risk assessment had been wrong but refused to modify it.   The father issued proceedings in the Sheriff's Court claiming rectification of the assessment form under art 16 GDPR and compensation for damage resulting from the council's delay in rectifying the form under art 82 (1).  The council admitted that the modified assessment form was incorrect and that it should be rectified, but contended that the data belonged to the child rather than her father and that, for that reason, the claim should fail. 

The Sheriff's Decision

The Sheriff found in favour of the father and awarded him compensation under art 82 (1).  He held that the information on the form was the father's personal data.  He found that it was incorrect and should be rectified. He also found that the father had sustained damage as a result of the council's delay in rectifying the record.   In reaching his decision, the Sheriff relied on the judgments of the Court of Justice of the European Union in Case C-434/16 Nowak v Data Protection Commissioner  [2017] EUECJ C-434/16, [2018] WLR 3505, [2018] 1 WLR 3505, EU: C:2017:994, [2018] 2 CMLR 21, ECLI:EU:C:2017:994, [2018] WLR(D) 8 and Mrs Justice Heather Williams in Ashley v Commissioners for His Majesty's Revenue and Customs [2025] EWHC 134 (KB).

The Appeal

The Council appealed to the Sheriff Appeal Court on the ground that the data relating to the child's risk assessment belonged to her and not her father and that he had not been entitled to seek rectification or compensation.  The appeal came on before Appeal Sheriff O'Carroll who delivered judgment in East Dumbartonshire Council v Paton [2026] SAC (Civ) 17 on 4 March 2026.  In para [23] of his judgment, the learned Appeal Sheriff dismissed the appeal.

Approach

In para [16], Appeal Sheriff O'Carroll and adopted considered the approach of the court below:

"What the case law and the two cases cited demonstrate in my view is that the correct approach to determining whether a right to access and associated rights exist, once the controller or processor of the data is identified, is firstly to identify the data to which access and rectification is sought. Then decide whether that data is personal data or not considering the statutory definition and wide interpretation of personal data adopted by the courts. Then, the task is to identify who is the subject of the data, that is to say the identified or identifiable person to whom the data relates. Then determine whether the data subject is entitled to rights of access or rectification or any other rights provided by the data protection legislation. Then, ascertain whether that that right has been asserted and exercised. Then, where the asserted right has been refused or blocked in some way, determine whether the data subject has a remedy and if so what and on what basis. Remedies include access, erasure, rectification, blocking and compensation, among others."

Whose Data? 

The learned Appeal Sheriff observed that the parties and first instance sheriff had narrowed the issue in dispute to a single question. Was the disputed data the personal data of the girl or her father?  In doing so, all concerned appeared to have assumed that the question was binary, that the data could be the personal data of only one or the other.

Not a Binary Question

The Appeal Sheriff explained why that was wrong:

"However, as frequently occurs in practice, any given piece of information may amount to personal data simultaneously of more than one person. See the useful discussion in Jay, Data Protection Law and Practice (5th Edition), at paragraphs 13-033 et seq. Information may inextricably form personal data of two or more persons. In the Novak case for example, the court noted that the personal data sought by Mr Novak was also the personal data of the examiner. In DB v General Medical Council [2019] 1 WLR 4044, , the independent expert report obtained by the GMC regarding the competence of a GP's treatment, sought by the patient who alleged negligent treatment, was simultaneously the personal data of the patient and the GP (and it might be said, though not argued, that of the author as well). Another example might be a joint bank account statement: that will comprise the personal data of each joint account holder. In this appeal, the Council itself states in its submission, correctly, that the disputed data was also that of the head teacher. The legislation itself makes specific provision for access rights in such cases of mixed personal data: see Articles 5 and 15 of GDPR and Schedule 2, Part 3, paragraph 16 to the 2018 Act. See also paragraph 17 of Part 3 for specific provision made in the case of education officials (such as risk assessor in this case) which removes the reasonableness test as regards the disclosure of that education official's personal data in certain circumstances."

He concluded that it cannot be said that if the information comprised the personal data of the child, it could not also be the personal data of her father.

It was obvious that the risk priority rating for emotional well-being was the girl's, but it was also her father's in the particular circumstances of the case.  The sheriff found after hearing evidence that the purpose of the data was not only to inform the council's employees’ decisions regarding the safety and well-being of the child, it was also to satisfy her father that those matters were being adequately dealt with by the council's officers.

Comment

The fact that the same data may relate to more than one data subject is often used as a reason for withholding data on a subject access request.   This decision makes clear that such excuses cannot be relied upon.  That does not mean that third-party rights can be overridden.  They have to be protected by redaction or otherwise.

Anyone wishing to discuss this article may call me on 020 7404 5252 during normal UK office hours ot send me a message through my contact form at any time. 

Friday, 4 October 2019

Lloyd v Google LLC

Author Gciriani
Licence CC BY-SA 4.0
Source Wikipedia Google























Jane Lambert

Court of Appeal (Dame Victoria Sharp P, Sir Geoffrey Vos C, Lord Justice Davis) Lloyd v Google LLC [2019] EWCA Civ 1599 (2 Oct 2019)

This was an appeal against Mr Justice Warby's refusal to allow the claimant, Richard Lloyd ("Mr Lloyd"), to serve proceedings on Google LLC ("Google") outside the jurisdiction claiming damages on behalf of 4 million i-phone users for  allegedly tracking secretly their internet activity for commercial purposes between 9 Aug 2011 and 15 Feb 2012.  The appeal was heard on 16 and 17 July 2019 by the President of the Queen's Bench Division, the Chancellor and Lord Justice Davis. Judgment was given on 2 Oct 2019. The lead judgment was delivered by the Chancellor, Sir Geoffrey Vos.

The Issues
The facts in this appeal were very similar to those in Google Inc v Vidal-Hal and others [2015] 3 WLR 409, [2015] CP Rep 28, [2015] FSR 25, [2015] 3 CMLR 2, [2015] WLR(D) 156, [2015] EMLR 15, [2015] EWCA Civ 311, [2016] QB 1003, [2016] 2 All ER 337 where the Court of Appeal dismissed Google's appeal against Mr Justice Tugendhat's decision to allow a similar claim to be served  outside the jurisdiction (see Vidal-Hall and others v Google Inc [2014] EWHC 13 (QB) (16 Jan 2014)  [2014] EMLR 14, [2014] 1 WLR 4155, [2014] WLR 4155, [2014] FSR 30, [2014] 1 CLC 201, [2014] WLR(D) 21, [2014] EWHC 13 (QB)). However, the Chancellor pointed out at paragraph [3] of his judgment that there was one crucial difference between the two cases.   In Vidal-Hall, the individual claimants claimed damages for distress as a result of Google's breaches of the Data Protection Act 1998 ("DPA").  In the present case, Mr Lloyd claimed a uniform amount by way of damages on behalf of each person within the defined class without seeking to allege or prove any distinctive facts affecting any of them, save that they did not consent to the abstraction of their data.

The Chancellor analysed Mr Justice Warby's decision between paragraphs [25] and [39] of his judgment.  According to the Chancellor, the grounds on which the application had been refused were  "that: (a) none of the represented class had suffered 'damage' under section 13 of the Data Protection Act 1998 (the 'DPA'), (b) the members of the class did not anyway have the 'same interest' within CPR Part 19.6 (1) so as to justify allowing the claim to proceed as a representative action, and (c) the judge of his own initiative exercised his discretion under CPR Part 19.6 (2) against allowing the claim to proceed."

His lordship summarized the main issues raised by the appeal as follows:
"(a) whether the judge was right to hold that a claimant cannot recover uniform per capita damages for infringement of their data protection rights under section 13 of the DPA, without proving pecuniary loss or distress, (b) whether the judge was right to hold that the members of the class did not have the same interest under CPR Part 19.6 (1) and were not identifiable, and (c) whether the judge's exercise of discretion can be vitiated."
The Facts
Sir Geoffrey adopted the following paragraphs from Mr Justice Warby's judgment:
"[7]. The case concerns the acquisition and use of browser generated information or "BGI". This is information about an individual's internet use which is automatically submitted to websites and servers by a browser, upon connecting to the internet. BGI will include the IP address of the computer or other device which is connecting to the internet, and the address or URL of the website which the browser is displaying to the user. As is well-known, "cookies" can be placed on a user's device, enabling the placer of the cookie to identify and track internet activity undertaken by means of that device.
[8]. Cookies can be placed by the website or domain which the user is visiting, or they may be placed by a domain other than that of the main website the user is visiting ("Third Party Cookies"). Third Party Cookies can be placed on a device if the main website visited by the user includes content from the third party domain. Third Party Cookies are often used to gather information about internet use, and in particular sites visited over time, to enable the delivery to the user of advertisements tailored to the interests apparently demonstrated by a user's browsing history ("Interest Based Adverts").
[9]. Google had a cookie known as the "DoubleClick Ad cookie" which could operate as a Third Party Cookie. It would be placed on a device if the user visited a website that included content from Google's Doubleclick domain. The purpose of the DoubleClick Ad cookie was to enable the delivery and display of Interest Based Adverts.
[10]. Safari is a browser developed by Apple. At the relevant time, unlike most other internet browsers, all relevant versions of Safari were set by default to block Third Party Cookies. However, a blanket application of these default settings would prevent the use of certain popular web functions, so Apple devised some exceptions to the default settings. These exceptions were in place until March 2012, when the system was changed. But in the meantime, the exceptions enabled Google to devise and implement the Safari Workaround. Stripped of technicalities, its effect was to enable Google to set the DoubleClick Ad cookie on a device, without the user's knowledge or consent, immediately, whenever the user visited a website that contained DoubleClick Ad content.
[11]. This enabled Google to identify visits by the device to any website displaying an advertisement from its vast advertising network, and to collect considerable amounts of information. It could tell the date and time of any visit to a given website, how long the user spent there, which pages were visited for how long, and what ads were viewed for how long. In some cases, by means of the IP address of the browser, the user's approximate geographical location could be identified. Over time, Google could and did collect information as to the order in which and the frequency with which websites were visited. It is said by the claimant that this tracking and collating of BGI enabled Google to obtain or deduce information relating not only to users' internet surfing habits and location, but also about such diverse factors as their interests and habits, race or ethnicity, social class, political or religious views or affiliations, age, health, gender, sexuality, and financial position.
[12]. Further, it is said that Google aggregated BGI from browsers displaying sufficiently similar patterns, creating groups with labels such as "football lovers", or "current affairs enthusiasts". Google's DoubleClick service then offered these groups to subscribing advertisers, allowing them to choose … the type of people that they wanted to direct their advertisements to".
Proceedings in the USA
The US Federal Trade Commission bought proceedings for misrepresenting to Safari users that it would not place tracking cookies on their browsers or send targeted advertising which Google settled by agreeing to pay a civil penalty of US$22.5 million.  It also settled an action by 37 states and the District of Columbia on behalf of their consumers by agreeing to pay US$17 million damages and giving certain undertakings.

Proceedings in the UK
 Mr Justice Warby had noted at paragraph [14] of his judgment that similar proceedings had not been brought in the UK by the Information Commissioner but he mentioned Vidal-Hall's claim that I discussed above. 

Applicable Law
Sir Geoffrey referred to paragraphs (2), (7), (8), (10), (11) and (55) of the recitals and arts 1, 22 and 23 of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data ("the Directive").  He also referred to ss.1 (1) (a) and (b), 3, 4 (1) and (4), 13 (1) and (2) and 14 (4) of the Data Protection Act 1998. Finally, he referred to CPR 19.6 (1), (2), (3) and (4).

Was the judge right to hold that a claimant cannot recover uniform per capita damages for infringement of their data protection rights under section 13 without proving pecuniary loss or distress?
The Chancellor affirmed that s.13 of the Data Protection Act 1998 has to be construed in accordance with art 23 of the Directive which had been adopted to give effect to art 8 of the European Convention on Human Rights. He also noted that the parties had agreed that there was a de minimis threshold for an award of damages. After considering the Court of Appeal's decisions in Gulati and others v MGN Ltd [2015] WLR(D) 232, [2015] EWHC 1482 (Ch) which was a case on the misuse of personal information, Halliday v Creation Consumer Finance Ltd (CCF) [2013] EWCA Civ 333 (15 March 2013) which was on damages under s.13 of the Data Protection Act 1998 and other authorities, his lordship concluded at [70] "that damages are in principle capable of being awarded for loss of control of data under article 23 and section 13, even if there is no pecuniary loss and no distress."  He added that it was only by construing the legislation in this way that individuals can be provided with an effective remedy for the infringement of their rights under the Act.

Was the judge was right to hold that the members of the class did not have the same interest under CPR Part 19.6(1) and were not identifiable?
CPR 19.6 (1) provides:
"Where more than one person has the same interest in a claim –
(a) the claim may be begun; or
(b) the court may order that the claim be continued,
by or against one or more of the persons who have the same interest as representatives of any other persons who have that interest."
Mr Justice Warby had held that a representative claim was disqualified unless (a) "every member of the class [had] suffered the same damage (or their share of a readily ascertainable aggregate amount [was] clear)", and (b) different potential defences were not available in respect of claims by different members of the class.  In the present case, for example, some in the claimant class would have been heavy internet users with much BGI taken; it was not credible that all the specified categories of data were obtained by Google from each represented claimant. The same variations would apply if the user principle were applied. Neither the breach of duty nor the impact of it was uniform across the entire class membership.

Sir Geoffrey believed that Mr Justice Earby had applied too stringent a test of "same interest" partly because of his earlier finding on recoverable damages.  H observed at [75]:
"Once it is understood that the claimants that Mr Lloyd seeks to represent will all have had their BGI – something of value - taken by Google without their consent in the same circumstances during the same period, and are not seeking to rely on any personal circumstances affecting any individual claimant (whether distress or volume of data abstracted), the matter looks more straightforward. The represented class are all victims of the same alleged wrong, and have all sustained the same loss, namely loss of control over their BGI. Mr Tomlinson disavowed, as I have said, reliance on any facts affecting any individual represented claimant. That concession has the effect, of course, of reducing the damages that can be claimed to what may be described as the lowest common denominator. But it does not, I think, as the judge held, mean that the represented claimants do not have the same interest in the claim. Finally, in this connection, once the claim is understood in the way I have described, it is impossible to imagine that Google could raise any defence to one represented claimant that did not apply to all others. The wrong is the same, and the loss claimed is the same. The represented parties do, therefore, in the relevant sense have the same interest. Put in the more old-fashioned language of Lord Macnaghten in The Duke of Bedford at [8], the represented claimants have a 'common interest and a common grievance' and 'the relief sought [is] in its nature beneficial to all'".
Mr Justice Warby had also held that a class of claimants having the same interest could not be identified. The Chancellor disagreed.  He said at [81]:  Havi
"In my judgment, therefore, the judge ought to have held that the members of the represented class had the same interest under CPR Part 19.6(1) and that they were identifiable."
Can the judge's exercise of discretion be vitiated?
Having reached a different conclusion on the other two issues, the Chancellor considered that it was appropriate for the court to exercise its discretion afresh.  Having considered carefully all the factors raised by both sides he concluded that this was a claim which, as a matter of discretion, should be allowed to proceed.

Conclusion
The President of the Queen's Bench Divison and Lord Justice Davis agreed with the Chancellor's judgment.  The appeal was therefore allowed and permission was granted to the claimants to serve their claim on Google in the USA.

Anyone wishing to discuss this appeal pr data protection generally should call me on +44 (0)20 7404 5252 or send me a message through my contact form.