Showing posts with label data. Show all posts
Showing posts with label data. Show all posts

Tuesday, 31 March 2026

Data Breach - Farley and Others v Paymaster (1836) Ltd

Brighton Town Hall
Author Hassocks5489  Licence CCO 1.0  Source Wikimedia Commons























Court of Appeal (Lady Justice King, Lord Justice Warby and Lady Justice Whipple)  Farley and others v Paymaster (1836) Ltd (t/a Equiniti) [2025] EWCA Civ 1117 (22 Aug 2025)

This was an appeal against the order of Mr Justice Nicklin in Farley and Others v Paymaster (1836) Ltd (Trading As Equiniti) [2024] EWHC 383 (KB) (23 Feb 2024), striking out most of the individual claims in a collective action arising from a data breach.  The appeal came before Lady Justice King, Lord Justice Warby and Lady Justice Whipple on 17 and 18 June 2025.  Counsels' arguments were filmed and can be viewed on YouTube at Farley (appellant) v Paymaster (1836) Limited (t/a Equiniti) (respondent) 17 June and ent) 18 June. The Court of Appeal allowed the appeal on 22 Aug 2025 (Farley and Others v Paymaster (1836) Ltd (t/a Equiniti) [2025] EWCA Civ 1117 (22 Aug 2025).  Permission to appeal to the Supreme Court was granted on 17 Dec 2025.  The appeal is listed for 7 and 8 Oct 2026.

Background

The claimants were members of a pension scheme for officers of the Sussex Police administered by the defendant. In August 2019, the defendant administrator sent an annual benefit statement to each member of the scheme. The statement contained an overview of the member's accrued benefits together with his or her name, date of birth, national insurance number and details of his or her salary and pension details. It would have been apparent to anybody reading the statement that the member was or had been a police officer.   The defendant sent some 750 of those statements to wrong addresses. The members affected alleged that this was a misuse of their personal information and an infringement of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA relevance)
OJ L 119, 4.5.2016, pp. 1–88 ("the GDPR"). Those members complained that the infringement had led to injury to their feelings, and in some cases, psychiatric harm from fear of third-party misuse of their personal data. They sued the administrator for compensation for the damage that they had suffered under art 82 (1) of the GDPR.

The Defendant's Application

The defendant applied to strike out the claim for failing to disclose a cause of action, or alternatively summary judgment.  The application came on for hearing before Mr Justice Nickin on 27 and 28 Feb 2023.  The learned judge received written submissions on 18 and 19 May and 1 June 2023.   His lordship allowed the claims of 14 members to proceed as they could show that their statements had been read, but he struck out the remaining claims which numbered over 400.

The Appeal

The members whose claims had been struck out appealed on the ground that the judge had been wrong in law.   In particular, he had been wrong to regard disclosure of the benefit statement to a third party as an essential ingredient of a viable data protection claim. The appellants contended that posting the statement to the wrong address infringed their rights under the data protection legislation. The defendant argued that the compensation claims were factually incredible, insufficient or untenable as a matter of law, or so trivial that they should be dismissed as an abuse of process of the kind identified in Jameel v Dow Jones Inc [2005] EMLR 16, [2005] QB 946, [2005] 2 WLR 1614, [2005] EMLR 353, [2005] EWCA Civ 75.

The Issues

Lord Justice Warby, who delivered the lead judgment, summarized the main issues at para [5]:
The Data Protection Legislation

The learned Lord Justice condensed the data protection legislation in para [28] of his judgment:
"The GDPR is EU legislation with direct effect in all EU member states. It enacts a number of data protection rights and obligations and contains provision for their enforcement. Article 5 identifies six 'principles relating to processing of personal data' with which data controllers must comply. Articles 24, 25 and 32 require data controllers to 'implement appropriate technical and organisational measures' to ensure GDPR compliance. Article 82 confers a right to receive compensation for material or non-material damage suffered as a result of an infringement. The GDPR applied with effect from May 2018. By Part 2 of the [Data Protection Act 2018], Parliament enacted provisions supplemental to the GDPR. Those provisions also came into force in May 2018."
He explained at [29] that these are the legislative instruments that apply to the events with which the Court was concerned because the European Union (Withdrawal) Act 2018 provided for the GDPR to remain part of English law until 23:00 on 31 Dec 2020.

Interpretating the GDPR

Lord Justice Warby added at [30] that English courts are bound by principles laid down by the Court of Justice of the European Union ("CJEU") and decisions made by it before 31 Dec 2020 as these are "assimilated EU case law" but not by any principles laid down, or any decisions made, by the CJEU after that date.  English courts "may have regard" to such principles or decisions "so far as it is relevant to any matter before the court". In deciding how to approach the latter class of CJEU decisions, English courts are bound by the law of precedent.

Infringement Issue

His lordship said that the first question to be considered in determining whether the administrator's mistake amounted to an infringement of the GDPR was whether the claimants had set out a reasonable basis for alleging that the defendant had engaged in "processing" their "personal data" within the meaning of the regulation and of the Act.    

He considered the definitions of "personal data" in art 4 (1) of the regulation and s.3 (2) of the Act and described them as "language of extremely broad reach." He added that there had never been any dispute that the information at issue here fell within that language and concluded that clearly it did.  

He turned his attention to the definition of "processing" in art 4 (2) of the regulation and s.3 (4) of the Act. Their definitions, which were very similar, defined "processing" as "any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means" with such illustrative examples as "collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction."  He recalled the CJEU's discussion of art 4 (2) in para [35] of its judgment in Case  C-175/20 “SS” SIA v Valsts ieneumu dienests, EU: C:2022:124, ECLI: EU:C:2022:124, [2022] EUECJ C-175/20:
"It is apparent from the wording of that provision, in particular from the expression 'any operation', that the EU legislature intended to give the concept of 'processing' a broad scope. That interpretation is corroborated by the non-exhaustive nature, expressed by the phrase 'such as', of the operations mentioned in that provision."

Lord Justice Warby noted at [36] that it was common ground that the defendant's operations amounted to "processing."

The learned Lord Justice observed that the defendant might have argued that printing out the statements, stuffing them into envelopes and posting them were manual operations after the processing had been completed, but it did not do so. It actually admitted that those steps did constitute processing.   On the basis of that admission, his lordship ruled that there was no basis for striking out those aspects of the claims.

Compensation Issue

Art 82 GDPR provides:

"(1) Any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller ... for the damage suffered."
(2) Any controller involved in processing shall be liable for the damage caused by processing which infringes this Regulation ..."
Before 31 Dec 2020, s.168 (1) of the Data Protection Act 2018 amplified art 82 (1) of the GDPR (right to compensation for material or non-material damage), by adding that 'non-material damage' included distress.

The claimants had pleaded that each of them experienced "anxiety, alarm, distress and embarrassment" at the prospect or possibility that their personal data may have come into the hands of third parties and been misused or exposed to the risk of misuse. That was expressly pleaded as "non-material damage". Secondly, 42 of them alleged that the infringements aggravated a pre-existing medical condition for which general damages were sought without particularizing such aggravation as material or non-material damage.   The administrator invited the Court of Appeal to dismiss those claims as incredible under CPR Part 24.  His lordship declined the invitation as it would have been a strong thing to reject statements of truth without hearing from the witnesses. He did not consider that the Court would be justified in taking that step.

The defendant's next point was that on the true construction of the GDPR and the Data Protection Act 2018, compensation was not recoverable for emotional responses other than distress. Lord Justice Warby rejected that submission. He said that the governing provision was art 82, which referred to "non-material damage" without limitation. S.168 (1) of the Act added that this term "included distress" but it was plain that that was an illustrative point. S.168 did not purport to define or limit the scope of the term "non-material damage" in art 82. Indeed, it seemed clear that Parliament's aim in enacting s.168 (1) was not to limit the ambit of the right to compensation but rather to confirm its breadth.

Despite such authorities as Case C‑300/2 UI v Österreichische Post AG [2023] WLR(D) 221, EU: C:2023:370, [2023] EUECJ C-300/21, ECLI:EU:C:2023:370, Case C‑340/21 VB v Natsionalna agentsia za prihodite EU: C:2023:986, ECLI:EU:C:2023:986, [2024] WLR(D) 17, [2023] EUECJ C-340/21, Case C-456/22 VX v Gemeinde Ummendorf EU: C:2023:988, ECLI:EU:C:2023:988, [2023] EUECJ C-456/22 and Case C‑687/21 BL v MediaMarktSaturn Hagen-Iserlohn GmbH, [2024] 1 WLR 2597, [2024] EUECJ C-687/21, ECLI:EU:C:2024:72, EU: C:2024:72, [2024] WLR(D) 53 to the contrary, the defendant administrator contended that there was a threshold of seriousness which the claimants had not cleared. It argued that the courts of the United Kingdom are no longer bound by decisions of the CJEU handed down after 23:00 on 31 Dec 2020, that they were bound by Lloyd v Google LLC  [2022] 2 All ER 209, [2022] HRLR 1, [2022] 1 All ER (Comm) 1107, [2022] AC 1217, [2021] 3 WLR 1268, [2022] EMLR 6, [2021] UKSC 50 and Prismall v Google UK Ltd [2024] EWCA Civ 1516, [2025] 2 WLR 1224 and that they should not follow the CJEU because its reasoning was flawed and that a threshold of seriousness would eliminate trivial claims and achieve coherence in the law.

Lord Justice Warby did not accept those arguments.  He reviewed the authorities on which the defendant relied and concluded that they did not support the contention that there was a threshold of seriousness for data protection claims in English law.  As for whether the English courts should take a different course from the CJEU, he accepted that it was an option for Parliament.  A judicial decision to do so would require compelling legal reasons.  He remarked at para [67] of his judgment:
"...... the GDPR is an international legal instrument which had direct effect in this jurisdiction at the material time. Further, its domestic successor, the UK GDPR, is post-Brexit legislation in which Parliament decided to adopt the identical language, so far as material to this case. Self-evidently, divergent interpretations of the same legislative text tend to undermine legal certainty. It seems to me that, other things being equal, it makes good legal sense for the court to interpret and apply the GDPR in conformity with settled CJEU jurisprudence."
He analysed the CJEU decisions mentioned above but could see no sufficiently weighty reason for departing on this appeal from the settled CJEU jurisprudence on the threshold of seriousness issue.

However, he said that it was clear from those cases that a claimant could recover compensation for fear of the consequences of an infringement, provided the alleged fear was objectively well-founded.

The Jameel Issue

The defendant relied on the Jameel principle in the strikeout application.   It was summarized by the Court of Appeal in para [175] of their judgment in Municipio de Mariana v BHP Group (UK) Ltd [2022] EWCA Civ 951, [2022] 1 WLR 4691, [2023] 1 All ER 611, [2022] WLR(D) 300, [2022] WLR 4691:
"[P]roceedings may ... be abusive if, even though they raise an arguable cause of action, they are (objectively) pointless and wasteful, in the sense that the benefits to the claimants from success [are] likely to be extremely modest and the costs to the defendants in defending the claims wholly disproportionate to that benefit" (citing Jameel (Yousef) v Dow Jones Co Inc [2005] EWCA Civ 75, [2005] QB 946)

The Supreme Court considered the principle further in Mueen-Uddin v Home Secretary  [2024] UKSC 21, [2024] EMLR 13, [2024] 3 WLR 244, CLW/24/23/1, [2024] 3 All ER 985, [2024] WLR(D) 283.

The administrator relied on the principle in its strikeout and summary judgment application, but Mr Justice Nicklin did not accept it.  It cross-appealed to the Court of Appeal with limited success.  Lord Justice Warby said at para [6 (3)] of his judgment:

"The Jameel jurisdiction does not provide a reason to bypass that process. These claims as a class cannot be categorised as Jameel abuse although the question of whether any individual case is abusive will remain for consideration."

The fact that a claim was small did not mean that it was abusive.  Lord Justice Warby quoted Lord Justice Lewison in Sullivan v Bristol Film Studios [2012] EWCA Civ 570, [2012] EMLR 27 at [29]:

"The mere fact that a claim is small should not automatically result in the court refusing to hear it at all. If I am entitled to recover a debt of £50 .... it would be an affront to justice if my claim were simply struck out."

The defendant had understandable concerns about costs and the difficulty of recovering them if it was successful, but that did not make the proceedings abusive.

The Supreme Court Appeal

The issue on which permission to appeal was granted is whether a threshold of seriousness applies to claims for damages under the GDPR and the Data Protection Act 2018.

Comment

This is an important decision on claims under art 82 (1) for compensation for material and non-material damage resulting from an infringement of the GDPR.  Should the Supreme Court allow Paymaster (1836) Ltd.'s appeal on thresholds of seriousness, its importance will be all the greater.  The Court of Appeal has ruled on what constitutes an infringement and whether concern over who may be reading confidential statement information of itself constitutes non-material damage.  The Court has also followed the CJEU's decisions on thresholds of seriousness and rejected the Jameel principle.  

Anyone wishing to discuss this case or this article may call me on +44 (0)20 7404 5252 during UK office hours or send me a message through my contact form at any time.

Thursday, 26 March 2026

Construction of art 82 (1) GDPR: Case C‑590/22 AT and another v PS GbR and others

Wesel Court House
Author KingKurt  Licence CC BY-SA 4.0  Source Wikimedia Commons

 











Jane Lambert

Court of Justice of the European Union (K. Jürimäe, President of the Chamber, K. Lenaerts, President of the Court, N. Piçarra, N. Jääskinen (Rapporteur) and M. Gavalec, Judges) Case C‑590/22 AT and another v PS GbR and others ECLI:EU: C:2024:536, [2024] EUECJ C-590/22, EU: C:2024:536

This was a request by the Wesel Amtsgericht for a preliminary ruling on the interpretation of art 82 (1) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ 2016 L 119, p. 1) (‘the GDPR’) pursuant to art 267 of the Treaty on the Functioning of the European Union.  The request was made in proceedings between AT and BT against PS Gesellschaft bürgerlichen Rechts ("PS GbR") and its members for compensation for the disclosure of their personal data to third parties without their consent as a result of an error by the firm.

The Proceedings

PS GbR was a tax consultancy, and AT and BT were two of its clients.  AT and BT instructed PS GbR to draw up their tax return.  The consultancy carried out their instructions but sent the return to AT and BT's previous address.  AT and BT recovered the envelope that had contained the tax return but found that it contained only a covering letter and a copy of the return.  The missing documents contained the names, dates of birth, tax identification numbers, religious denominations, bank details, professions, places of work and disability status of AT and BT, as well as their children's personal data.  AT and BT sued PS GbR and its members for €15,000 compensation in the Wesel Amtsgericht, the lowest civil court in the German legal system.

The Reference

The court decided that it could not decide the claim without referring the following questions to the Court of Justice of the European Union:

"(1) Is it sufficient for the establishment of a claim for compensation under Article 82 (1) of [the GDPR] that a provision of [that regulation] serving to protect the claimant has been infringed or is it necessary that a further adverse effect on the claimant has occurred, beyond the infringement of the provision as such?
(2) Under EU law, does the establishment of a claim for compensation for non-material damage under Article 82 (1) of the GDPR require an adverse effect of a certain magnitude?
(3) In particular, is it sufficient for the establishment of a claim for compensation for non-material damage under Article 82(1) of the GDPR that the claimant fears that his or her personal data have come into the hands of third parties as a result of infringements of provisions of the GDPR, even though that circumstance cannot be positively established?
(4) Is it in conformity with EU law for the national court to apply mutatis mutandis the criteria of the second sentence of Article 83 (2) of the GDPR - which, according to the wording, apply only to administrative fines - when assessing compensation for non-material damage under Article 82 (1) of the GDPR?
(5) Must the amount of a claim for compensation for non-material damage under Article 82 (1) of the GDPR also be assessed by reference to the fact that the amount of the claim awarded serves to have a deterrent effect and/or to prevent the “commercialisation” (calculated acceptance of administrative fines/compensation payments) of infringements?
(6) Is it in conformity with EU law, when assessing the amount of a claim for compensation for non-material damage under Article 82(1) of the GDPR, to take into account simultaneous infringements of national provisions which have as their purpose the protection of personal data but which are not delegated or implementing acts adopted in accordance with that regulation or Member State laws [specifying rules] of that regulation?’

Legislative Context

The CJEU considered recitals (85), (146) and (148) and  arts 4 (1), (7), (10) and (12), 79 (1) and 83 (3) and (5) of the GDPR as well as the following paragraphs of art 82:

"1. Any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller or processor for the damage suffered.
2. Any controller involved in processing shall be liable for the damage caused by processing which infringes this Regulation. A processor shall be liable for the damage caused by processing only where it has not complied with obligations of this Regulation specifically directed to processors or where it has acted outside or contrary to lawful instructions of the controller.
3. A controller or processor shall be exempt from liability under paragraph 2 if it proves that it is not in any way responsible for the event giving rise to the damage.
......."

Judgment

The CJEU delivered judgment on 20 June 2024 (Case C‑590/22 AT and another v PS GbR and others ECLI:EU: C:2024:536, [2024] EUECJ C-590/22, EU: C:2024:536).

The First and Second Questions

The Court took the 1st and 2nd questions together.  In its view, the Amstgericht was asking whether art 82 (1) should be interpreted as meaning that the mere infringement of the GDPR would be sufficient to give rise to compensation or whether a claimant had also to show that the infringement had led to damage of a sufficient degree of seriousness.  

The CJEU has already held in para [32] of Case C‑300/2 UI v Österreichische Post AG [2023] WLR(D) 221, EU: C:2023:370, [2023] EUECJ C-300/21, ECLI: EU: C:2023:370 and para [34] of Case C‑741/21, GP v juris GmbH [2024] EUECJ C-741/21, ECLI: EU: C:2024:288, EU: C:2024:288 that it is clear from the wording of the article that the existence of ‘damage, whether material or non-material, constitutes one of the conditions for compensation under art 82 (1).  So, too, does the existence of an infringement and of a causal link between that damage and the infringement.  The three conditions are cumulative.

It follows that it cannot be held that any ‘infringement’ of the provisions of the GDPR, by itself, confers a right to compensation.  The answer to question 1 is that art 82 (1) of the GDPR must be interpreted as meaning that the mere infringement of the provisions of that regulation is not sufficient to confer a right to compensation.

The Third Question

The 3rd question was reframed as to whether art 82 (1) should be interpreted as meaning that a data subject's fear that his or her personal data had been disclosed to third parties without any certainty as to whether that had actually happened is sufficient to give rise to a claim for non-material damage under that article.  

Citing paras [30] and [44] of UI v Österreichische Post AG and para [64] of Case C‑687/21 BL v MediaMarktSaturn Hagen-Iserlohn GmbH, [2024] 1 WLR 2597, [2024] EUECJ C-687/21, ECLI: EU: C:2024:72, EU: C:2024:72, [2024] WLR(D) 53, the CJEU noted that the concept of ‘non-material damage’, within the meaning of art 82 (1), must be given an autonomous and uniform definition specific to EU law.  

The Court has already held in Case C‑340/21VB v Natsionalna agentsia za prihodite EU: C:2023:986, ECLI:EU: C:2023:986, [2024] WLR(D) 17, [2023] EUECJ C-340/21 and BL v MediaMarktSaturn Hagen-Iserlohn GmbH that the fear experienced by a data subject with regard to a possible misuse of his or her personal data by third parties as a result of an infringement of that regulation is capable, in itself, of constituting ‘non-material damage’, within the meaning of art 82 (1).  It added that the loss of control over personal data, even for a short period of time, may constitute ‘non-material damage’, within the meaning of art 82 (1), giving rise to a right to compensation, provided that the data subject can show that he or she has actually suffered such damage, however slight.

person who considers that his or her personal data has been processed in breach of the relevant provisions of the GDPR and seeks compensation on the basis of art 82 (1)  must therefore prove that he or she has actually suffered material or non-material damage.  However,  a mere allegation of fear, with no proven negative consequences, cannot give rise to compensation.

The CJEU concluded at para [36] that the answer to the 3rd question is that art 82 (1) must be interpreted as meaning that a person’s fear that his or her personal data have, as a result of an infringement of that regulation, been disclosed to third parties, without it being possible to establish that that was in fact the case, is sufficient to give rise to a right to compensation, provided that that fear, with its negative consequences, is duly proven.

The Fourth and Fifth Questions

In the 4th and 5th questions the Amtsgericht asked whether art 82 (1) should be interpreted as meaning that, to determine the amount of damages due as compensation for damage based on that provision, it is necessary, to apply the criteria for setting the amount of administrative fines laid down in art 83 mutatis mutandis and that a dissuasive function be conferred on the right to compensation.  The CJEU observed that arts 82 and 83 pursue different objectives. While art 83 determines the "general conditions for imposing administrative fines", art 82 governs the "right to compensation and liability."   The criteria set out in art 83 for the purposes of determining the amount of administrative fines cannot be used to assess the amount of damages under art 82 thereof (see para [57] ) of C‑741/21, GP v juris GmbH).  The answer to the 4th and 5th questions is that art 82 (1) must be interpreted as meaning that, in order to determine the amount of damages due as compensation for damage based on that provision, it is not necessary, first, to apply mutatis mutandis the criteria for setting the amount of administrative fines laid down in art 83, and, second, to confer on that right to compensation a dissuasive function.

The Sixth Question

In its 6th question, the Amtsgericht was asking whether art 82 (1) must be interpreted as meaning that, to determine the amount of damages due as compensation for damage based on that provision, account must be taken of simultaneous infringements of national provisions relating to the protection of personal data, but not intended to specify the rules of that regulation.  The Court ruled that it was not necessary to take account of simultaneous infringements of national provisions that relate to the protection of personal data, but which are not intended to specify the rules of that regulation.

The Ruling

The CJEU ruled as follows:
"1. Article 82 (1) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), must be interpreted as meaning that an infringement of that regulation is not, in itself, sufficient to give rise to a right to compensation under that provision. The data subject must also establish the existence of damage caused by that infringement, without, however, that damage having to reach a certain degree of seriousness.
2. Article 82 (1) of Regulation 2016/679 must be interpreted as meaning that a person’s fear that his or her personal data have, as a result of an infringement of that regulation, been disclosed to third parties, without it being possible to establish that that was in fact the case, is sufficient to give rise to a right to compensation, provided that that fear, with its negative consequences, is duly proven.
3. Article 82 (1) of Regulation 2016/679 must be interpreted as meaning that, in order to determine the amount of damages due as compensation for damage based on that provision, it is not necessary, first, to apply mutatis mutandis the criteria for setting the amount of administrative fines laid down in Article 83 of that regulation and, second, to confer on that right to compensation a dissuasive function.
4. Article 82 (1) of Regulation 2016/679 must be interpreted as meaning that, in order to determine the amount of damages due as compensation for damage based on that provision, it is not necessary to take account of simultaneous infringements of national provisions which relate to the protection of personal data but which are not intended to specify the rules of that regulation."

Comment

As this ruling was delivered after IP completion day, courts in England and Wales, Scotland and Northern Ireland are not bound by it or the principles contained in this judgment.  However, s.6 (2) of the European Union (Withdrawal) Act 2018, as amended, permits courts in those jurisdictions to have regard to it insofar as it is relevant to any matter before them.   This judgment will therefore be cited and considered in cases on the meaning and effect of art 82 of the UK GDPR (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation) (Text with EEA relevance)).

Anyone wishing to discuss this case may call me on +44 (0)20 7404 5252 or send me a message through my contact form.

Sunday, 11 January 2026

Data (Use and Access) Act 2025 - Part 1: Access to Business and Customer Data

Baroness Jones of Whitchurch
Author Roger Harris  Licence CC BY 3.0  Source  UK Parliament



























In Data Protection Law Reform (23 Dec 2025), I discussed the Conservative government's proposed Data Reform Bill and its Data Protection and Digital Information Bill.  Part 3 of that bill was headed "Customer Data and Business Data" and was intended to create a statutory framework for smart data, that is to say, sharing customer data and business data with third parties who will use that information to create new businesses and services.  The previous government set out its plans for smart data in The Smart Data Roadmap in April 2024.

As I mentioned in Data Protection Law Reform, the Data Protection and Digital Information Bill did not complete its passage through Parliament before the 2024 general election.  However, as Lady Jones of Whitchurch said on the second reading of the Data (Use and Access) Bill in the House of Lords on 19 Nov 2024, facilitating smart data was in the Labour Party manifesto.  In her speech, she said:
"My Lords, data is the DNA of modern life. It is integral to almost every aspect of our society and economy, from NHS treatments and bank transactions to social interactions. An estimated 85% of UK businesses handle some form of digital data, and the UK data economy was estimated to represent 6.9% of UK GDP. Data-enabled UK service exports accounted for 85% of total service exports, estimated to be worth £259 billion, but data use in the UK drives productivity benefits of around 0.12%, which is only one minute per worker per day."

That bill received royal assent on 19 June 2025.  I introduced it in Data Use and Access: Structure on 26 Dec 2025.

In that introduction, I said that the Act consisted of 8 parts and 16 schedules.   The first of those parts is headed "Access to customer data and business data" and consists of 26 sections.  It covers much the same ground as Part 3 of the Data Protection and Digital Information Bill, though Lady Jones said that there had been several important changes to make her bill more focused, more balanced, and better able to achieve its objectives.

The key provision of part 1 is s.1 (1):

"This Part confers powers on the Secretary of State and the Treasury to make provision in connection with access to customer data and business data."

S.2 (1) of the Act enables the Secretary of State or the Treasury to make regulations requiring a data holder to provide customer data to a customer at his or her request or to a person authorized by the customer to receive the data (an “authorized person”), at the customer’s request or at the authorized person’s request.  

"Customer data" is defined by s.1 (2) as information relating to a customer of a trader.  It includes information relating to goods, services and digital content supplied or provided by the trader to the customer or to another person at the customer’s request.  It could be information about 

  • prices or other terms on which goods, services or digital content are supplied or provided to the customer or another person, 
  • how they are used by the customer or other person, or 
  • their performance or quality when used by the customer or another person.
Such data can also include information relating to the provision of information described above or of other information relating to a customer of a trader, to a person in accordance with data regulations. A “trader” means a person who supplies or provides goods, services or digital content in the course of a business, whether acting personally or through another person acting in the trader’s name or on the trader’s behalf.

S.4 (1) enables the Secretary of State or the Treasury to make regulations requiring a data holder to publish business data or to provide it to a customer of the trader to whom the business data relates, or
to another person of a specified description.  “business data”, in relation to a trader, means information:

  • about goods, services and digital content supplied or provided by the trader,
  • relating to the supply or provision of goods, services and digital content by the trader, such as 
    • where goods, services or digital content are supplied or provided, 
    • prices or other terms on which they are supplied or provided, 
    • how they are used, or 
    • their performance or quality,
  • relating to feedback about the goods, services or digital content (or their supply or provision), and
  • relating to the provision of information described above to a person in accordance with data regulations.
There will also be regulations on enforcement, fees, financial services and other matters.

Other than reg 2 (a) of The Data (Use and Access) Act 2025 (Commencement No. 1) Regulations 2025, which provided for Part 1 of the Act: Access to Business and Customer Data to come into force on 20 Aug 2025, no regulations have been made.  There are likely to be further consultations on the secondary legislation, which I shall monitor.

Guidance from the Department for Science, Innovation and Technology accompanying the introduction of the bill on 24 Oct 2024 estimated that the legislation would bring an estimated £10 billion boost to the UK economy over 10 years.   Anyone wishing to discuss this article may call me on +44 (0)20 7404 5252 during UK office hours or send me a message through my contact form at any time. 

Further Information

Jane Lambert  Data (Use and Access) Act 2025: Structure 26 Dec 2025

Sunday, 3 December 2017

How the GDPR works

Author Mauro Cateb
Licence Creative Commons Attribution-Share Alike 3.0 unported

















Jane Lambert

In my introduction to the GDPR 2 Dec 2017 I wrote that the regulation sought to balance two conflicting imperatives, namely the need to protect the public from the harm that can result from malicious, negligent or even careless processing of data that identifies living individuals and the need to safeguard free flows of such data for legitimate purposes.  As I also wrote in that article, there is nothing new about any of that. That policy is exactly the same as that of the Data Protection Directive, the Data Protection Act 1998, the Data Protection Act 1984, the Council of Europe Convention and the OECD Guidelines.

The GDPR also seeks to achieve that objective in much the same way as previous legislation.  It establishes a set of principles for processing personal data (data by which living human beings can be identified) and machinery for monitoring and enforcing compliance.  That machinery takes the form of rights for data subjects (the individuals who can be identified from the data) and obligations upon data controllers (those who control the processing of personal data) and processors (those who carry out the processing) to take reasonable steps to minimize the risk or effect of non-compliance.

The GDPR's data processing principles require personal data to be:
(a) processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’);
(b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89 (1), not be considered to be incompatible with the initial purposes (‘purpose limitation’);
(c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’);
(d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’);
(e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89 (1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (‘storage limitation’);
(f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’)."
It is the data controller's duty to be responsible for and demonstrate compliance with those principles.

So long as data controllers and processors process personal data in accordance with those principles they are unlikely to go far wrong. However, if they stray from them, whether intentionally or not, they risk legal action in the civil courts or fines or other sanctions by the Information Commissioner or the equivalent supervisory authority of another EU member state.

As an obvious way round the legislation would be to export the data to a country that does not regulate the processing of personal data either at all or to the same extent and in the same way, the regulation restricts transfers of data abroad unless Commission is satisfied with the legal protection of personal data processing that is available in the recipient country or enforceable contractual arrangements are in place for the protection of such data. The GDPR makes clear that the regulation applies not just to data controllers and processors that are in the EU, but also to data controllers outside the EU which offer goods or services to data subjects in the EU or monitor the behaviour of such data subjects within the EU.

In the next few articles I shall drill down into each of those topics in more detail.  Should anyone wish to discuss this article, the GDPR or data protection generally, he or she should call me on +44 (0)20 7404 5252 during office hours or send me a message through my contact form.

Further Reading


Date
Author and Title
Publication
2 Dec 2017
NIPC Data Protection
1 Dec 2017
NIPC Data Protection
11 Aug 2017
NIPC Data Protection