The UK’s Supreme Court is to decide whether people bringing claims for breaches of data protection law will need to show they have a sufficiently serious case to bring a claim for compensation.
A two-day hearing at the UK’s highest court will decide whether people claiming damages under UK data protection laws will need to meet a “threshold of seriousness” before they can pursue claims for damages.
The case comes amid complaints from businesses that they are having to spend time and money defending against data protection claims for data breaches that cause little damage to the people affected.
James Hyde, disputes partner at law firm, Addleshaw Goddard, said that businesses were facing a growing number of claims for data protection breaches, partly as a result of claimants using AI.
“Organisations are being inundated with trivial data privacy related claims, from individuals and from claimant firm groups,” Hyde told Computer Weekly. “Individual claims are also being fuelled by the use of AI. All of which is a significant drain on business time and money, and the court’s resources.”
The UK’s data protection watchdog, the Information Commission, saw the number of data protection complaints it received jump from 42,300 in 2024/25 to over 76,700 in 2025/26.
The case – Farley V Paymaster (1836) – which is being heard in the UK’s Supreme Court, was brought by over 400 current or former police officers from Sussex Police Force.
They are seeking damages after the police force’s pension administrator sent out annual benefits statements to their previous addresses.
The letters included personal information, including their date of birth, national insurance number, salary details and pension benefits.
However, they did not include any sensitive or special category data, such as ethnic origins, religious beliefs or trade union membership, or medical information.
Police claims originally struck out
The majority of police claims were initially struck out by the High Court in February 2024, as the police officers could not prove that the envelopes had been opened or that their data had been misused.
The current and former police officers subsequently dropped claims of damages for misuse of their data and argued in the Court of Appeal that they were entitled to compensation for breaches of the UK’s General Data Protection Regulation (GDPR) by the pension administrator, even if their data had not been misused.
The Court of Appeal found that a “threshold of seriousness” did not apply to claims of damages for improperly processing personal data under the GDPR and the Data Protection Act 2018.
In effect, the decision meant the police offices could claim for damages for data protection failures by the pension administrator even if their data had not been misused, provided they could show they had been harmed by the incident.
The “threshold of seriousness” continues to apply to people seeking damages for misuse of their data.
Paymaster (1836), which trades as Equiniti, is seeking to overturn that decision in the Supreme Court on 7 and 8 October.
Threshold could prevent claims in cases of ‘mass harm’
Lawyers representing the current and former police officers argue that setting a “threshold for serious” is not consistent with GDPR in Europe or the UK. People should be able to bring claims, even if they are only entitled to a modest sum in compensation.
They claim Equiniti made systemic breaches, including setting up its systems to have two address locations, failing to update information in its databases, and sending letters to the wrong addresses.
Minutes of the Sussex Police Pension Board show there were two other incidents when annual benefits statements have been sent to the wrong address.
The police officers affected told the court they had suffered annoyance, irritation and distress. Around 40 have reports from medical practitioners to support their claim.
The police officers’ arguments are supported by written submissions from the Open Rights Group and the UK’s data protection watchdog, which has been rebranded the Information Commission.
According to the Open Rights Group, a seriousness threshold would prevent people seeking redress in cases of “mass harm”, where breaches may affect thousands or millions of people, but each individual claim would be relatively small. It would also put the UK out of line with Europe on data protection legislation.
The Information Commission, in a separate intervention, also argues there should be no “threshold of seriousness” for compensation for damage for infringements of GDPR.
Police officers ‘unconcerned’
Paymaster 1863 argues that the police officers were given the opportunity to sign up for a fraud prevention service at the time of the breach, but “over 90%” were “apparently so unconcerned” that they did not bother.
Sussex Police conducted a risk assessment which found it was “unlikely” the police officers impacted would suffer serious consequences because of the limited nature of the data, and its limited distribution.
The incident is a “trivial, one-off breach” which cannot have given rise to “genuine feelings of distress” and “should not be taking up valuable court time and incurring huge levels of costs”, Equiniti argues in written court submissions.
Hyde said businesses were receiving large numbers of often trivial claims for data protection breaches, many of which were AI-generated.
This meant that businesses were having to “wade through” vast quantities of AI-generated material, often with incorrect or irrelevant matters, statutory and case references, to identify whether there is a valid claim.
“In legal proceedings or a threatened claim, the business just can’t ignore it, it has to deal with it,” he said.
Hyde said the Supreme Court appeal was about whether there is a threshold of seriousness for data protection claims under GDPR and the Data Protection Act.
“It doesn’t concern special category data or misuse of private information,” he said. “There remains a threshold of seriousness for claims of misuse of private information.”

