What counts as a personal data breach
A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. That definition is wider than most people expect — it is not only hacking.
What matters for a claim is not only that a breach happened, but that it caused you damage or distress, and that the organisation was at fault in failing to protect the data.
- Cyber attacks and ransomware Where an organisation's security failings let an attacker take customer or employee records.
- Email sent to the wrong people The classic example: a bulk email with every address in the To or Cc field instead of Bcc, often exposing membership of a sensitive group.
- Post and documents misdirected Letters, statements or medical records sent to a previous address or to the wrong person entirely.
- Medical records disclosed Health data is special category data. Unauthorised access to it — including by a curious member of staff — is treated seriously.
- Employee snooping Staff accessing records they have no business reason to look at. The employer is usually liable for it.
- Lost devices and paperwork Unencrypted laptops, phones, USB sticks and files left where they should not be.
- Data kept far too long Holding personal data for years past any lawful purpose, so a later breach exposes far more than it should have.
- Disclosure to an abuser or ex-partner Releasing an address or contact details to someone the data subject is trying to stay away from. Among the most serious breaches there is.
The ICO does not pay compensation
This is the most common misunderstanding we hear, and it costs people time.
The Information Commissioner's Office is the UK's data protection regulator. It investigates, it can require an organisation to change how it operates, and it can issue substantial fines. Those fines go to the Treasury, not to you. The ICO has no power to award you compensation.
Complaining to the ICO is still worth doing, and often worth doing first. It costs nothing, and a finding that an organisation breached the legislation is useful evidence if you go on to claim. But the ICO is not a route to a payment, and if compensation is what you are after, it is a civil claim that produces it.
The two are not alternatives. Many of our clients complain to the ICO and bring a claim.
When you do not have a claim
Most pages competing for these searches will not tell you this. It is the most useful thing on this page.
The Supreme Court held in Lloyd v Google that there is no right to compensation simply for "loss of control" of your data. You must show that the breach caused you material damage or non-material damage — in practice, financial loss or genuine distress. Being one of several million people named in a breach notification, with nothing having happened to you since, is not by itself a claim.
The High Court in Rolfe v Veale Wasbrough Vizards struck out a claim arising from a single misdirected email, describing the alleged distress as below the level the law is concerned with, and ordered the claimants to pay costs. There is a de minimis threshold, it is real, and falling below it can leave you worse off than doing nothing.
Warren v DSG Retail matters too. Where an organisation is itself the victim of a cyber attack, the court struck out the misuse of private information, breach of confidence and negligence claims, leaving only the statutory data protection claim. That narrows the routes available and affects how a claim is funded.
So the honest picture is this. A breach notification letter on its own is usually not enough. What turns it into a claim is what happened next: money taken, an account opened in your name, sensitive information reaching people who should never have had it, or distress serious enough that you can describe its effect on your life. If you have that, you may well have a good claim. If you have only the letter, we will tell you.
What makes a data breach claim strong
The claims that succeed tend to share the same features, and they are worth knowing because they tell you what to gather.
- Special category data was involved Health, sex life, sexual orientation, religion, ethnicity, political opinion, trade union membership, biometrics, or criminal offence data. The law treats these as needing the highest protection and the courts follow suit.
- The data actually reached someone Evidence that a third party received or opened it, rather than a theoretical risk of exposure. In Farley v Paymaster many claims failed precisely because there was no evidence anyone had opened the letter.
- There has been real misuse Fraudulent transactions, credit applications in your name, phishing that references the leaked data, or contact from someone who should not have your details.
- The distress is documented A GP record of anxiety, a sleep problem, time off work, or a course of treatment. Distress described in a witness statement carries far more weight when there is a contemporaneous record behind it.
- There are consequential costs Credit monitoring, replacing documents, calls and time spent putting things right, and any money you did not get back.
- The organisation was clearly at fault An ICO finding, an admission in the breach notification, or an obvious failing such as unencrypted data or no access controls.
Medical and NHS data breaches
Health data is special category data under Article 9 of the UK GDPR, and breaches involving it are treated more seriously than breaches of a name and address.
The patterns we see most are records sent to the wrong patient or the wrong address, results discussed with the wrong person, staff accessing the records of someone they know without any clinical reason, and details of a condition reaching an employer or a family member. Where a diagnosis is something a person had chosen not to share, the distress of it becoming known can be considerable — and the courts recognise that.
An NHS trust, a GP practice, a dental practice, a private clinic and a pharmacy are all data controllers, and all can be liable. Where the breach was caused by an employee acting without authority, the employer can still be liable for it.
Complaining to the trust or practice through its complaints procedure, and to the ICO, runs perfectly well alongside a claim, and the disclosure those processes produce is often useful.
What you can claim for
Compensation under Article 82 has two parts, and it helps to keep them separate in your mind because they are proved in completely different ways.
Material damage is financial loss caused by the breach. Money taken from an account and not refunded, the cost of credit monitoring, replacing identity documents, the cost of putting your credit file right, and any loss of earnings — for example time taken off work to deal with the consequences. This is arithmetic, it is provable with documents, and you should keep every receipt.
Non-material damage is the distress. Section 168 of the Data Protection Act 2018 confirms that distress counts as damage for these purposes. There is no tariff for it. A court assesses it on the facts: how sensitive the data was, how widely it went, whether it was misused, how long the anxiety lasted, and what effect it actually had on you.
That is why this page carries no compensation table. Anyone publishing one is inventing a tariff the law does not have, and the figures are usually chosen to encourage a claim rather than to describe reality. What we will do is tell you what your case looks like compared with the awards courts have actually made, once we know the facts.
What to do in the first week
If you have been told your data was involved in a breach, a few things are worth doing straight away — whether or not you ever claim.
- Keep the breach notification The letter or email telling you what happened, and any reference number. It is the foundation of everything that follows.
- Make a subject access request Article 15 of the UK GDPR entitles you to a copy of your personal data and information about the breach, free of charge, normally within one month. It is the most effective way to find out what was actually exposed.
- Check your credit file Look for applications you did not make. A statutory credit report is inexpensive and a fraud alert can be added if anything looks wrong.
- Change passwords and enable two-factor Particularly anywhere you reused the same password. This limits the damage and shows you acted reasonably.
- Write down the effect on you While it is fresh — what you have worried about, what you have had to do, sleep, time off. If you saw your GP about it, say so.
- Complain to the ICO Free, and a finding in your favour is useful evidence. Just do not expect a payment from it.
Time limits and how a claim runs
A data protection claim in England and Wales carries a six-year limitation period, so there is usually no immediate rush — but evidence is much easier to gather early, and organisations only retain breach records for so long.
A claim normally begins with a letter of claim setting out what data was involved, how the organisation failed, and the damage caused. Most organisations investigate and respond, and a significant proportion of well-founded claims settle without proceedings. Where they do not, the claim is issued in the county court.
One consequence of Warren v DSG is worth being clear about at the outset: because a data breach claim against an organisation that was itself hacked is likely to be a statutory claim alone, the funding options are narrower than in some other kinds of claim. We will explain exactly what a claim would cost you, and what you would keep, before you commit to anything.