乐于分享
好东西不私藏

AI看法(英国)|Farley等诉Paymaster——个人数据未被第三方读取亦可能构成违法处理

AI看法(英国)|Farley等诉Paymaster——个人数据未被第三方读取亦可能构成违法处理

Farley and Others v Paymaster (trading as Equiniti) — Misaddressed Personal Data May Constitute Unlawful Processing Without Proof of Third-Party Access

2025年8月22日,英格兰及威尔士上诉法院民事庭在 Farley and Others v Paymaster (1836) Limited (trading as Equiniti)([2025] EWCA Civ 1117)一案中作出判决。本案涉及养老金年度权益报表被错误寄往过期地址后,在无法证明信件曾被第三方拆阅的情况下,相关人员能否依据《通用数据保护条例》(GDPR)主张个人数据遭到违法处理并请求精神损害赔偿。

上诉人是由Paymaster负责管理养老金计划的432名现任或前任萨塞克斯警察。2019年8月,Paymaster向计划成员邮寄养老金年度权益报表。报表载有成员的姓名、出生日期、国民保险号码、警察任职情况、工资资料以及已经积累和预计获得的养老金权益,并被放入标有“私人及保密”的窗口信封中。

萨塞克斯警方向Paymaster提供了成员的最新地址,相关信息也已上传至其数据库。然而,Paymaster在生成报表时因系统错误提取了旧地址,导致超过750份报表被寄往成员已经不再居住的地址。约102份信件被原封退回,约60名成员自行取回报表,但大多数信件始终未能追回,其下落不明。

事件发生后,萨塞克斯警方向受影响人员发出通知,称数据泄露造成损害的风险较低,并建议其采取防范身份盗窃的措施。Paymaster也寄送了道歉信及替换报表,并承担受影响人员登记CIFAS反欺诈保护服务的费用。信息专员办公室认为事件源于Paymaster未能有效更新地址系统,但考虑到发生严重后果的可能性较低以及已经采取的补救措施,决定不再采取进一步监管行动。

包括上诉人在内的多名警员随后提起诉讼,主张Paymaster未能保障个人信息安全,违反GDPR及《2018年数据保护法》,并构成滥用私人信息。他们称,由于不知道报表是否落入第三方手中以及个人数据是否可能遭到滥用,自己产生了焦虑、恐惧、尴尬、烦恼和精神痛苦;部分人员还主张事件加重了其原有心理或精神健康问题。

一审高等法院认为,一项可成立的滥用私人信息或者数据保护请求,原则上要求原告证明报表确实曾被第三方拆开并阅读。仅将个人信息置于可能泄露的危险之中,属于没有实际发生侵权的“未遂事件”。由于只有14名原告能够提出报表可能已被他人拆阅的可争辩证据,法院允许这14项请求继续进行,驳回了其他绝大多数请求。432名原告就数据保护请求向上诉法院提起上诉。

上诉法院首先认定,一审法院错误地将第三方实际读取数据作为数据保护请求成立的必要条件。GDPR对“处理”的定义极为宽泛,包括对个人数据进行收集、记录、组织、存储、调整、检索、使用、传输和披露等任何操作。Paymaster将旧地址及新地址存入数据库、利用系统生成报表并将其寄往错误地址,均可能构成对个人数据的处理。即使无法证明信件被第三方拆阅,也不意味着没有发生“处理”,更不意味着相关行为不可能违反数据准确性、完整性、保密性以及采取适当技术和组织措施的义务。

法院强调,个人数据遭到实际披露并不是认定GDPR侵权的必要条件。数据控制者错误记录或使用地址并据此寄送包含个人数据的文件,本身便可能构成违法处理。因此,每一名上诉人均已提出具有合理基础的GDPR侵权主张,一审法院以无法证明第三方读取为由驳回这些请求属于法律适用错误。

关于损害赔偿,上诉法院指出,GDPR第82条要求请求人证明侵权行为造成了物质或非物质损害。仅仅证明发生违法处理,并不足以自动获得赔偿。但是,“精神痛苦”并不是唯一能够获得赔偿的非物质损害。《2018年数据保护法》第168条规定非物质损害“包括”精神痛苦,属于示例性而非限制性规定。焦虑、恐惧、压力等其他负面情绪在适当情况下也可能属于可以获得赔偿的非物质损害。

上诉法院同时采纳欧盟法院相关判例确立的原则,认定GDPR项下的非物质损害不存在最低严重程度门槛。只要请求人证明其确实遭受属于第82条范围内的损害,便不必进一步证明该损害达到特定严重程度。因此,法院不能仅以某人的焦虑较轻、持续时间较短或赔偿金额较低为由,直接驳回其请求。

然而,不存在严重程度门槛并不意味着任何烦恼或负面感受均可获得赔偿。请求人仍须证明有关反应构成真正的非物质损害,并由GDPR侵权行为造成。仅因发生数据处理错误而产生的短暂不满、恼怒或失望,未必属于第82条意义上的损害。上诉人在原诉状中也未充分主张因Paymaster处理事件的方式或延迟通知本身产生的烦恼,因此不能仅依靠个人说明扩大总体诉讼请求的范围。

对于上诉人所主张的个人信息可能遭到身份盗用、欺诈或其他恶意利用的恐惧,法院认为此类恐惧在法律上可能构成非物质损害,但必须是“有客观依据的恐惧”,不能建立在纯粹假设或猜测之上。判断恐惧是否合理,应当以当事人产生恐惧时已经知道或应当知道的情况为基础,而不能仅因最终没有实际发生数据滥用便事后否定其合理性。

每名上诉人须具体说明并证明:其一,为什么有合理理由担心寄往旧地址的信件会被第三方拆开并阅读;其二,为什么有合理理由担心报表中的资料会被用于身份盗窃、欺诈或其所主张的其他用途。仅仅说明报表被寄往错误地址以及当事人因此感到担忧,不能当然构成有客观依据的恐惧。

法院指出,涉案信封明确标有“私人及保密”,收件人姓名清晰可见,一般人员通常会退回、保存或者丢弃此类信件,而不会擅自拆阅。受影响的750余人中,只有极少数能够证明信件曾被打开;事件发生近六年后,也没有出现个人信息被实际滥用的证据。此外,Paymaster、萨塞克斯警察及信息专员办公室均将风险评估为较低。这些因素均可能表明一般性的担忧缺乏充分客观基础。

但法院认为,各上诉人的具体情况可能不同。例如,信件被寄往何人实际控制的地址、当事人与该地址现住户的关系、双方之间是否存在纠纷,以及现住户是否可能利用工资和养老金资料,均可能影响恐惧是否合理。因此,法院不能以整体方式认定所有请求均有依据或者均属纯粹假设,而应逐一审查各上诉人的个人情况。

42名上诉人还主张事件加重了其原有心理或精神健康问题,并提交了心理评估报告。法院认为,如果有关人员对数据遭到滥用的恐惧具有客观依据,由此引起或者加重的心理损害原则上可以获得赔偿;反之,如果作为损害根源的恐惧本身缺乏合理基础,相关心理损害赔偿请求也不能成立。这些请求同样取决于对每名上诉人具体情况的审查。

Paymaster另行主张,这些请求可能获得的赔偿十分有限,而诉讼成本极高,继续审理属于浪费司法资源,应依据 Jameel v Dow Jones 原则认定为滥用诉讼程序。上诉法院没有接受这一整体性主张。法院指出,赔偿金额较低本身不能成为拒绝审理请求的理由。只要存在可争辩的侵权和损害请求,法院首先应通过案件分流、费用管理或转入郡法院小额索赔程序等方式实现比例适当的审理,而不应直接剥夺当事人的诉权。

上诉法院最终认定,每名上诉人均已提出具有合理基础的GDPR侵权主张,准许其就侵权问题提出的上诉;同时驳回Paymaster关于所有请求均低于严重程度门槛或者整体构成诉讼程序滥用的主张。至于各上诉人能否获得赔偿,则须根据其个人情况判断其恐惧是否具有客观依据。法院因此将该问题发回高等法院,由其决定自行审查,或者交由主事法官、郡法院进行个案审查和后续案件管理。

本案明确区分了“个人数据违法处理”“实际损害”与“损害赔偿”三个层次。数据未被第三方实际获取或读取,并不排除数据控制者已经违反GDPR;但证明违法处理也不意味着当事人自动享有赔偿。对于因潜在数据滥用产生的恐惧,法院既不能设置最低严重程度门槛,也必须审查该恐惧是否具有具体、客观和合理的事实基础。

On 22 August 2025, the Court of Appeal of England and Wales delivered its judgment in Farley and Others v Paymaster (1836) Limited (trading as Equiniti) ([2025] EWCA Civ 1117). The case concerned whether pension-scheme members could bring data-protection claims after annual benefit statements had been sent to outdated addresses, even though they could not prove that any unauthorised third party had opened or read the documents.

The appellants were 432 serving or former Sussex Police officers whose pension scheme was administered by Paymaster. In August 2019, Paymaster posted annual benefit statements to members of the scheme. The statements contained names, dates of birth, national insurance numbers, details of police service and salary, and accrued and forecast pension benefits. They were placed in window envelopes marked “Private and Confidential”.

Sussex Police had supplied Paymaster with updated addresses, which had been uploaded to its database. When the statements were generated, however, Paymaster’s system mistakenly retrieved previous addresses. More than 750 statements were consequently sent to outdated residential addresses. Approximately 102 were returned unopened and around sixty were recovered by the officers themselves, but most were never recovered and their fate remained unknown.

Sussex Police notified the affected officers that the risk of harm was assessed as low and provided advice on protection against identity theft. Paymaster sent apology letters and replacement statements and offered to pay for registration with a fraud-protection service. The Information Commissioner’s Office concluded that the incident had resulted from Paymaster’s failure to update its systems effectively but, in view of the low likelihood of serious consequences and the remedial measures taken, required no further regulatory action.

The affected officers brought claims under the GDPR and the Data Protection Act 2018, as well as claims for misuse of private information. They alleged that uncertainty about whether their statements had reached third parties, and fear that their information might be misused, had caused anxiety, alarm, embarrassment and distress. Some also alleged that the incident had aggravated pre-existing psychological or psychiatric conditions.

The High Court held that a viable claim required each claimant to show a real prospect of proving that the statement had been opened and read by a third party. Merely placing personal information at risk was treated as a “near miss”. Fourteen claimants could advance an arguable case that their statements had been opened, but the remaining claims were struck out. The 432 appellants appealed against the dismissal of their data-protection claims.

The Court of Appeal held that the High Court had wrongly treated third-party access as an essential element of a data-protection claim. The GDPR defines processing broadly to include any operation performed on personal data, including collection, recording, organisation, storage, alteration and use. Paymaster’s storage of the former and updated addresses, its use of the database to generate the statements and its posting of those statements to the wrong addresses were capable of amounting to processing.

Actual disclosure of the data was therefore unnecessary to establish an infringement. Even if no third party opened the envelopes, Paymaster might have breached the GDPR principles of accuracy, lawfulness, fairness, integrity and confidentiality, as well as its obligations to implement appropriate technical and organisational safeguards. Every appellant had accordingly pleaded a reasonable basis for alleging an infringement.

The Court then distinguished an infringement from an entitlement to compensation. Article 82 of the GDPR requires proof of material or non-material damage caused by the infringement. An infringement alone does not automatically confer a right to compensation. Nevertheless, “distress” is not the only compensable form of non-material damage. Section 168 of the Data Protection Act provides that non-material damage “includes” distress and does not restrict compensation exclusively to that particular emotional response.

Following the consistent case law of the Court of Justice of the European Union, the Court of Appeal held that non-material damage under Article 82 is not subject to a minimum threshold of seriousness. A claim cannot therefore be dismissed merely because the alleged anxiety was mild, temporary or likely to attract only a modest award. The claimant must, however, still prove damage falling within Article 82. The absence of a seriousness threshold does not turn every transient feeling of annoyance or displeasure into compensable damage.

Fear that personal data may be misused in the future is capable of constituting non-material damage, but only where the fear is objectively well founded. A purely hypothetical or speculative risk cannot support compensation. Reasonableness must be assessed according to the circumstances known, or which should have been known, to the individual when the fear arose. The fact that no misuse ultimately occurred does not necessarily make an earlier fear unreasonable.

Each appellant would therefore need to identify a specific and reasonable basis for fearing both that the misaddressed envelope would be opened and read and that the information would then be misused. The mere fact that a statement was sent to an outdated address, followed by a subjective feeling of concern, was insufficient.

The Court observed that the envelopes were visibly private and confidential and addressed to named individuals. Ordinarily, a person receiving such correspondence would return, retain or discard it rather than open it. Only a small proportion of the statements were known to have been opened, and almost six years after the incident there was no evidence of actual misuse. The low-risk assessments made by Paymaster, Sussex Police and the Information Commissioner were also relevant.

Individual circumstances could nevertheless produce a different conclusion. The identity of the occupier at the former address, the relationship between that person and the appellant, any history of personal or financial conflict and the possible value of the disclosed information all required case-specific consideration. The Court therefore declined to determine the compensation claims collectively.

Forty-two appellants alleged that the incident had aggravated existing medical conditions. The Court held that consequential psychological or psychiatric injury could in principle be compensated if it arose from an objectively well-founded fear. If the underlying fear was not well founded, however, the associated medical claim would also fail.

Paymaster argued that the claims were likely to produce only modest compensation while generating disproportionate litigation costs and should therefore be struck out as an abuse of process under the Jameel principle. The Court rejected that argument as a basis for dismissing the claims as a class. A claim is not abusive merely because its financial value is low. Courts should first consider proportionate procedures, appropriate case allocation and costs management before adopting the exceptional course of striking it out.

The Court of Appeal consequently allowed the appeal on the infringement issue and rejected Paymaster’s arguments that the claims were subject to a seriousness threshold or were collectively abusive. It remitted the compensation issue to the High Court for individual examination, either in the High Court itself or through an appropriate procedure in the County Court.

The judgment distinguishes three separate questions: whether personal data were unlawfully processed, whether the infringement caused actual damage and whether that damage is compensable. Proof of third-party access is unnecessary to establish unlawful processing. It remains necessary, however, for a claimant seeking compensation for fear of future misuse to demonstrate a concrete and objectively reasonable foundation for that fear.

(以上链接见文末阅读原文)