Rolfe and others v Veale Wasbrough Vizards LLP [2021] EWHC 2809 (QB)
Citation
- Full case name: Rolfe and others v Veale Wasbrough Vizards LLP
- Neutral citation: [2021] EWHC 2809 (QB)
- Court: High Court of Justice, Queen’s Bench Division (Media and Communications List)
- Judge: Master McCloud
- Judgment: 2021
- Subject: data protection; breach of confidence; misuse of private information; de minimis; summary judgment
Facts
A firm of solicitors sent an email about unpaid school fees on behalf of a client. Because of a single typographical error in the email address, the message went to an unintended recipient rather than to the parents it was meant for.
The recipient told the firm about the mistake straight away and confirmed the following day that the email had been deleted. There was no evidence that the information had gone any further.
The parents and their daughter brought claims for breach of confidence, misuse of private information, negligence and breach of data protection law, seeking damages for distress and declaratory relief. The defendant applied for summary judgment.
Decision
Summary judgment was given for the defendant.
There was no credible case that any damage or distress had reached a level that would sustain a claim. The information disclosed was not sensitive, the error was isolated, it was corrected almost immediately, and there was no evidence of onward dissemination. The court was unimpressed by the way the distress had been described in the claim, and made clear that trivial breaches of this kind are not appropriate subjects for High Court litigation.
Costs were awarded on the indemnity basis, reflecting the speculative character of the claim and the exaggeration of the alleged distress.
Why it matters for insurance
For several years the UK saw a large volume of low-value data breach claims, frequently pursued in combination with several causes of action and with costs far exceeding the damages sought. Rolfe is one of the decisions that pushed back, and it sits alongside the Supreme Court’s refusal in Lloyd v Google to allow a representative action for loss of control of data without proof of damage.
For cyber insurers and their policyholders the practical significance is about strategy and cost. Most cyber wordings cover defence costs and regulatory response as well as damages, and the choice between settling a small claim and fighting it is a commercial one. Rolfe shows that fighting can be the cheaper course, particularly where the incident was small, promptly contained and well documented.
That, in turn, is an argument for incident records. The reason the defendant here succeeded so cleanly was that it could show exactly what happened, when the recipient was contacted, and when the email was deleted. Businesses that log incidents properly are in a materially better position both with an insurer and in litigation.
It should not be read as a rule that low-value data claims always fail. It is a decision on its own facts about the threshold, and cases involving sensitive information, repeated failures or wider disclosure are a different proposition.
See also
- Stadler v Currys Group — another modern decision on low-value data claims
- Lloyd v Google — the Supreme Court on loss of control of data
- Gulati v MGN — when privacy claims are worth substantial damages
- Jameel v Dow Jones — the proportionality principle in reputation claims
References
- Rolfe and others v Veale Wasbrough Vizards LLP [2021] EWHC 2809 (QB) (Master McCloud)
- Lloyd v Google LLC [2021] UKSC 50
- UK General Data Protection Regulation and the Data Protection Act 2018
Frequently asked questions
Does every data breach give rise to a claim for damages?
No. Rolfe confirms that a claim must cross a de minimis threshold. A single misdirected email containing non-sensitive information, corrected within a day and with no evidence of onward disclosure, did not do so, and summary judgment was given for the defendant.
Why were indemnity costs awarded?
Because the court regarded the claim as speculative and the alleged distress as exaggerated. Indemnity costs are a marker of the court's disapproval and they recover a higher proportion of the defendant's actual spend than standard basis costs.
What does this mean for cyber insurance?
It supports defending small claims rather than paying them, provided the incident was minor, contained quickly and properly documented. Good incident records are what make that possible, and they matter to the insurer as much as to the policyholder.
This page is insurance information for UK businesses, not legal advice. It summarises a reported judgment and explains why insurance buyers and brokers refer to it; it is not a substitute for reading the judgment or taking advice on your own facts. Case summaries are necessarily short and omit detail. Position stated as at August 2026.
Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This page is general information, not advice on a specific policy.
