THE data security of abuse survivors has been breached by Kennedys Law LLP, the law firm chargeable for administering the Church of England’s Redress Scheme.
An announcement from Church House on Wednesday said: “We have been made aware of a deeply regrettable data incident involving the independent Redress Scheme administered by Kennedys Law LLP.
“This incident resulted within the unintended disclosure by Kennedys Law of email addresses belonging to individuals who had registered for updates on the Redress Scheme. . . We recognise the distress this has caused, particularly for survivors who trusted the scheme to handle their information with care and confidentiality.
“While the Church of England is just not the info controller for the Redress Scheme and doesn’t hold or manage the info in query, we’re nonetheless profoundly concerned. We are in discussions with Kennedys to know how this breach occurred and to make sure robust steps are taken to forestall anything similar from happening again.”
Kennedys had taken full responsibility for the incident, the statement said, and had reported the breach to the Information Commissioner’s Office.
It concluded: “This mustn’t have happened. We will proceed to watch the situation closely and support efforts to revive trust and confidence.”
An announcement issued by Kennedys on Wednesday said that a message had been sent to 194 individuals and law firms on Tuesday evening. The firm was “deeply sorry for the hurt and concern caused to everyone affected by this significant error and accepts full responsibility”. A full internal investigation was announced.
An email sent by the NST on Wednesday to individuals affected said: “We understand the discomfort, anxiety, and uncertainty this data breach will cause for a lot of victims, survivors, and their families — whether you were directly impacted or not. Please know that you just should not alone.” It provided details of sources of support, including Safe Spaces.
Kennedys, a world law firm, was announced because the administrator of the Redress Scheme in March 2024 — a move described as a “significant step towards our goal of offering redress to survivors and victims of church-related abuse” (News, 28 March 2024). Members of the Redress Survivor Working Group were involved in the choice process. The General Synod gave the scheme final approval last month. The Church Commissioners have committed £150 million to it.
A public website opened on 18 July, enabling prospective applicants to register their interest and receive advance notification of the scheme’s official opening date, once it is understood. On Tuesday, considered one of those affected, Canon Ian Gomersall, wrote on his blog that the breach “shatters my confidence in the method”. He suggested that “inadequate confidential care is being taken, and supervision and oversight of those handling the info can be inadequate.”
Questions or concerns in relation to this data breach may be directed to: kennedysdataprotectionofficer@kennedyslaw.com

