Kennedys data breach

Published 27 August 2025

Regrettably on Tuesday evening, a message was sent from law firm, Kennedys, to 194 individuals and law firms who had registered to receive updates in relation to the Church of England Redress scheme.  Due to human error, the email displayed the email addresses making them visible to all recipients.  No further personal details of individuals were shared. Attempts to recall the message were only partially successful. 

Kennedys has been working with the Church of England since March 2024 as its independent Scheme Administrator to help it develop further and manage its National Redress Scheme for victims and survivors of Church-related abuse. This was approved by the General Synod of the Church of England in July paving the way for the scheme to open for redress applications. 
  
Kennedys is deeply sorry for the hurt and concern caused to everyone affected by this significant error and accepts full responsibility. We have contacted everyone who received the message and have reported the incident to the Charity Commission, the Information Commissioner’s Office and the Solicitor’s Regulatory Authority. We will fully comply with any investigations.  
  
Additionally, we have launched a full internal investigation to understand how this could have occurred and will incorporate any lessons learnt into our procedures immediately. 

We understand the significant impact this will have on those affected for which we apologise unreservedly.  We remain committed to supporting victims and survivors of Church of England-related abuse to secure the financial redress, therapeutic, spiritual and emotional support, acknowledgement of wrongdoing on the part of the Church, apology and other forms of bespoke redress under this scheme.  Questions or concerns in relation to this data breach can be directed to KennedysDataProtectionOfficer@kennedyslaw.com