Thu 20 Aug 2026

Group proceedings and data breach litigation in Scotland

Since March 2026, three sets of group proceedings have been granted permission to proceed in the Court of Session, in which damages are sought for incidents involving the improper access to, or disclosure of, personal data.

We commented on one of these class actions earlier this year. You can read more here.

While these are the first sets of group proceedings in Scotland that concern such incidents involving personal data, we do not expect that they will be the last. That is not least because of the pervasiveness of personal data in business operations and as sophisticated cyber-attacks become increasingly common, as well as risks arising from data misuse (including human error).

In this article, we consider the characteristics of claims related to data incidents and why we can expect similar claims in future to be raised by way of group proceedings.

Background: group proceedings in Scotland

The framework for group proceedings (sometimes known as 'class actions' or 'collective proceedings' in other settings) was introduced in Scotland in 2018.

The broad purpose of the scheme is to enable civil claims which are sufficiently similar in fact and law to be pursued on behalf of all of the pursuers with such a claim by a nominated individual, the 'representative party'. The framework of group proceedings is said to be justified by the principle of access to justice, because it facilitates claims to be pursued where they might otherwise not be, for example because it would be uneconomical to do so. Group proceedings can only be brought on an 'opt-in' basis rather than an 'opt-out' basis, although as we comment below, that may be subject to change in future.

Group proceedings can only be pursued in the Court of Session, which is required to determine at an early stage whether permission should be granted for the case to proceed. The cases to date demonstrate that the Scottish approach at the early stage of group litigation is altogether more permissive than its counterparts elsewhere, in relation to the need to demonstrate commonality of claims and prospects of success, and in relation to the identity and credentials of a proposed representative party.

To date, only one application for permission to bring group proceedings has been refused - Donnelly v Johnson & Johnson ([2025] CSOH 77), which concerned injuries arising from hernia mesh implants - for reasons including that there were fundamental differences among the claims pursued by the seventeen individuals within the proposed class and the need for particular medical evidence to demonstrate the harm suffered. We have commented on the court's decision here.

Data litigation and group proceedings

There are three features of litigation following a data breach incident which, taken together, mean that such claims may be particularly prone to being pursued by way of group proceedings.

First, in a large-scale data breach incident of the type that has become common in the news, claims by affected data subjects may often proceed on a broadly similar factual and legal basis.

For example, where an incident has occurred in which a customer database containing personal data is improperly obtained by an unauthorised third party, a data subject may claim that they are entitled to damages because of the distress and anxiety associated with that incident, but it may go no further than that in terms of identifying particular loss.

Second, absent any special circumstances, any such claims by a base of affected customers are generally likely to be low in individual value.

Third, the factual and legal issues associated with a data subject's claim might be sufficiently complex that it may not be economically efficient for either party to run the case until a final judgment. Two factors should be borne in mind:

  • It is not always straightforward to establish that a data controller is liable to data subjects when an incident occurs. If liability is not admitted, an action for damages will involve arguments about the sufficiency of protection in place to protect data, relative to its sensitivity. That can be a factually and legally complex issue.

  • In any case, a pursuer would typically have to establish that they suffered harm for which a right of compensation occurs, in light of the Supreme Court's decision in Lloyd v Google that 'loss of control' does not automatically give rise to such a right under data protection law.

When taken together, those three characteristics of claims related to data breach incidents mean that such cases may be seen as particularly well suited to be pursued via group proceedings in Scotland in certain circumstances. The claims might be of such a low value, and the issues so complex, that it could be most economically efficient (and seen as consistent with the principle of access to justice) to deal with common issues of liability and compensation collectively.

While it may not necessarily be a barrier to obtaining permission to proceed, difficulties may arise in relation to the onus on a pursuer to establish and quantify the harm they suffered if liability were established; the relative novelty of the group proceedings framework in Scotland means that there is limited authority on how such issues may be dealt with.

Looking ahead

Any business that is a significant data controller should be aware of the risk of litigation arising from a data breach incident, which should inform its approach to incident response from a legal and strategic perspective. The possibility of group proceedings in Scotland raises the stakes in that risk assessment, because of the higher aggregate value of claims and the greater cost of defending such claims.

As the data-related cases initiated in 2026 progress in the Court of Session, it will become possible to draw conclusions about the particular challenges that group proceedings of that nature will face, which in turn will inform assessments about how a data controller can robustly defend its position on liability and how the courts will scrutinise harm allegedly suffered by data subjects.

Adding to that mix of considerations, as we highlighted at the start of the year in our article about the need for balance in opt-out group proceedings, the Scottish Civil Justice Council (SCJC) is currently undertaking a consultation on the potential introduction of 'opt-out' procedure to the system of group proceedings. If 'opt-out' proceedings are introduced, it is possible that data-related litigation may be initiated by way of those rules, which will in turn introduce new issues for consideration.

MFMac's expert teams have extensive experience of group proceedings in Scotland, as well as specialist data protection lawyers, in order to provide comprehensive advice and representation to business organisations.

Make an Enquiry

From our offices we serve the whole of Scotland, as well as clients around the world with interests in Scotland. Please complete the form below, and a member of our team will be in touch shortly.

Are you contacting us as an individual or business? *


Are you an existing client? *


How would you like us to contact you?


Is this a personal or business dispute? *


Morton Fraser MacRoberts LLP will use the information you provide to contact you about your inquiry. The information is confidential. For more information on our privacy practices please see our Privacy Notice