When One Click Changes Everything

28/08/2025

A serious data protection failure has occurred within the Church of England’s Redress Scheme, managed by the law firm Kennedys Law. Personal details of nearly 200 survivors of church-related abuse were inadvertently disclosed in an email, prompting concern among victims, advocacy groups, and regulators.

What Happened

“Due to human error, the email displayed the email addresses making them visible to all of the recipients”

Kennedys Law accepted full responsibility, saying it was “deeply sorry for the hurt and concern caused to everyone affected.” The firm has reported the matter to the Information Commissioner’s Office, the Solicitors Regulation Authority, and the Charity Commission, and is carrying out an internal review to prevent recurrence.

Human Error and Human Impact

It’s important to recognise that this incident was almost certainly the result of a simple mistake, someone clicking “send” without blind copying recipients for example. Anyone who has worked in a pressured role knows how easily that can happen. I feel sorry for the individual involved, who will no doubt be devastated to realise the impact of their action.

But while mistakes happen, the consequences here are significant. This wasn’t just an admin slip: the recipients were survivors of abuse, entitled to the highest levels of confidentiality and care. The breach risks compounding harm for those who had already placed fragile trust in the scheme.

Response from the Church

The Church of England stressed that it is not the data controller of the scheme, but nonetheless expressed “profound concern” and said it was working with Kennedys to ensure stronger safeguards.

Bishop of Winchester, Philip Mounstephen, who set up the redress scheme, told Channel 4 News, “Let’s be very clear about this. Even though this wasn’t our error from a legal perspective, we will not shirk our moral responsibility. Survivors are deserving of the utmost care, confidentiality and respect. Our focus has to be on their wellbeing and we’ll continue to do everything we can to support them and uphold the integrity of the redress scheme, not for its own sake but because survivors vitally need it.”

Impact on Survivors

Survivor groups have voiced distress, with some emphasising that the breach undermines the very trust the Redress Scheme was created to rebuild. Survivors are legally entitled to lifelong anonymity, and the disclosure of their details, even just email addresses, could feel like another betrayal.

One victim that has waived their anonymity, has said that other victims will be feeling more exposed and more vulnerable with the trust broken completely. They acknowledge that the cause of the breach may have been a junior admin person that may not have received appropriate training or briefed.

Lessons for All Organisations

This incident is a stark reminder that most data breaches are not the result of hackers, but human error. One wrong click can expose hundreds of people’s information. That’s why it is critical that organisations handling sensitive data:

  • Put in place robust systems for group communications (such as mailing software or secure portals rather than ad-hoc emails).
  • Provide regular, bespoke training tailored to staff roles and the sensitivity of the data they handle and conduct routine audits.
  • Use technical safeguards (e.g. auto-BCC, controlled distribution lists, email send delay or email platforms that suppress recipient visibility).
  • Carry out regular Data Protection Impact Assessments (DPIAs) especially when working with vulnerable groups.

Final Thought

We must balance accountability with empathy. People make mistakes, but when working with survivors of abuse, the stakes are too high to rely on manual processes alone. Organisations should focus not only on apologising after breaches but also on building systems and training staff in ways that make such errors far less likely.

Leave a comment

  • When Someone Asks for Their Data

    15/02/2026 What Every Organisation Must Understand About Subject Access Requests in 2026 When someone asks to see the personal data your organisation holds about them, it is not a favour. It is not discretionary. It is a statutory right. Under UK data protection law, now refined by the Data (Use and Access) Act 2025, individuals…

  • Data Protection in 2026: What to Be Ready For

    24/01/2026 As we move into 2026, it’s tempting to look for the big new data protection law that will change everything overnight. In reality, that isn’t how this year is shaping up. Instead, 2026 looks set to be a year of consolidation, scrutiny and expectation‑raising. The rules themselves are largely familiar. What’s changing is what…

  • Why are the “Epstein files” so heavily redacted?

    29/12/2025 A data protection and transparency perspective When high-profile court documents are released to the public, there is often an expectation that they will reveal everything. So when the US Department of Justice (DoJ) released nearly 30,000 more pages of documents related to the late convicted sex offender Jeffrey Epstein, many people expected full transparency. Instead, they…

  • The New Data Protection Complaints Process

    How are you implementing the new data protection complaints process?