When One Click Changes Everything

28/08/2025

A serious data protection failure has occurred within the Church of England’s Redress Scheme, managed by the law firm Kennedys Law. Personal details of nearly 200 survivors of church-related abuse were inadvertently disclosed in an email, prompting concern among victims, advocacy groups, and regulators.

What Happened

“Due to human error, the email displayed the email addresses making them visible to all of the recipients”

Kennedys Law accepted full responsibility, saying it was “deeply sorry for the hurt and concern caused to everyone affected.” The firm has reported the matter to the Information Commissioner’s Office, the Solicitors Regulation Authority, and the Charity Commission, and is carrying out an internal review to prevent recurrence.

Human Error and Human Impact

It’s important to recognise that this incident was almost certainly the result of a simple mistake, someone clicking “send” without blind copying recipients for example. Anyone who has worked in a pressured role knows how easily that can happen. I feel sorry for the individual involved, who will no doubt be devastated to realise the impact of their action.

But while mistakes happen, the consequences here are significant. This wasn’t just an admin slip: the recipients were survivors of abuse, entitled to the highest levels of confidentiality and care. The breach risks compounding harm for those who had already placed fragile trust in the scheme.

Response from the Church

The Church of England stressed that it is not the data controller of the scheme, but nonetheless expressed “profound concern” and said it was working with Kennedys to ensure stronger safeguards.

Bishop of Winchester, Philip Mounstephen, who set up the redress scheme, told Channel 4 News, “Let’s be very clear about this. Even though this wasn’t our error from a legal perspective, we will not shirk our moral responsibility. Survivors are deserving of the utmost care, confidentiality and respect. Our focus has to be on their wellbeing and we’ll continue to do everything we can to support them and uphold the integrity of the redress scheme, not for its own sake but because survivors vitally need it.”

Impact on Survivors

Survivor groups have voiced distress, with some emphasising that the breach undermines the very trust the Redress Scheme was created to rebuild. Survivors are legally entitled to lifelong anonymity, and the disclosure of their details, even just email addresses, could feel like another betrayal.

One victim that has waived their anonymity, has said that other victims will be feeling more exposed and more vulnerable with the trust broken completely. They acknowledge that the cause of the breach may have been a junior admin person that may not have received appropriate training or briefed.

Lessons for All Organisations

This incident is a stark reminder that most data breaches are not the result of hackers, but human error. One wrong click can expose hundreds of people’s information. That’s why it is critical that organisations handling sensitive data:

  • Put in place robust systems for group communications (such as mailing software or secure portals rather than ad-hoc emails).
  • Provide regular, bespoke training tailored to staff roles and the sensitivity of the data they handle and conduct routine audits.
  • Use technical safeguards (e.g. auto-BCC, controlled distribution lists, email send delay or email platforms that suppress recipient visibility).
  • Carry out regular Data Protection Impact Assessments (DPIAs) especially when working with vulnerable groups.

Final Thought

We must balance accountability with empathy. People make mistakes, but when working with survivors of abuse, the stakes are too high to rely on manual processes alone. Organisations should focus not only on apologising after breaches but also on building systems and training staff in ways that make such errors far less likely.

Leave a comment

  • With Great Power Comes Great Responsibility:

    Why AI Makes Data Protection More Important Than Ever 26/08/2026 I have always been fascinated by emerging technology. Part of working in data protection is trying to keep ahead of the game: understanding not only what technology can do now, but what it might be capable of next, and what that means for the people…

  • Cyber security is a data protection issue: lessons from the ICO’s ACRO reprimand

    14/08/2026 The Information Commissioner’s Office (ICO) has reprimanded ACRO Criminal Records Office following cyber security failings which potentially exposed the personal information of up to 10,920 people. The case is a useful reminder for organisations that cyber security is not simply an IT issue. It is a fundamental part of data protection compliance, accountability and…

  • Council officer convicted for unlawfully accessing personal data

    24/07/2026 The Information Commissioner’s Office (ICO) has recently highlighted an important reminder for all organisations that handle personal information: having access to a system does not mean you are entitled to access every record within it. A former Herefordshire Council employee has received a suspended prison sentence after unlawfully accessing approximately 490 personal records and…

  • Why Smart Companies Keep Getting Data Protection Wrong

    12/07/2026 The biggest data protection risk? It’s certainty. The organisations most likely to get into difficulty with data protection are rarely the ones asking difficult questions. They’re the ones convinced they’re already compliant. Whether it’s a multinational or a start-up, the mistakes are remarkably similar: Collecting data because they can, not because they need to.…