Skip to content
Free consultation · No Win, No Fee Claim now
3 Manor Row, Bradford, BD1 4PB
Make a claim

Data breach
compensation claims.

Has an organisation lost, exposed or misused your personal data? You may be entitled to compensation for the financial loss and the distress. We will tell you honestly whether you have a claim — including when you do not.

Data Breach
Data Breach Solicitors

Compensation when your
personal data is exposed

A data breach claim is a claim against the organisation that held your personal data and failed to keep it secure. Article 82 of the UK GDPR gives you a right to compensation for both material damage — money you actually lost — and non-material damage, which in practice means the distress of knowing your information is out there.

It is a genuine right and it is worth enforcing. It is also an area where you will find a great deal of nonsense written online, because it attracts claims farming. The courts have made clear over the last few years that there is no automatic payment simply for having been caught up in a breach, and that trivial claims can be struck out with costs against the person who brought them.

We act for individuals across England and Wales. Our first job on any enquiry is to tell you honestly whether what happened to you crosses the threshold — and if it does not, we will say so rather than run up a bill finding out.

Free Tool

Data breach claim checker

Tick what applies and add up anything the breach has actually cost you. It will tell you whether your situation looks like a claim — including when it does not. Nothing is recorded.

What happened
What it has cost you

Credit monitoring, replacing documents, correcting your credit file.

Tick what applies

The checker updates as you go.

Financial loss you can evidence £0
Distress element Assessed on the facts

No figure for distress, deliberately. There is no tariff for it under Article 82 — a court assesses it on the facts. Any tool that gives you a number has invented one. Since Lloyd v Google there is no payment merely for being in a breach, and in Rolfe a trivial claim was struck out with costs against the claimants. We would rather tell you where you stand than sell you a number.

What counts as a personal data breach

A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. That definition is wider than most people expect — it is not only hacking.

What matters for a claim is not only that a breach happened, but that it caused you damage or distress, and that the organisation was at fault in failing to protect the data.

  • Cyber attacks and ransomware Where an organisation's security failings let an attacker take customer or employee records.
  • Email sent to the wrong people The classic example: a bulk email with every address in the To or Cc field instead of Bcc, often exposing membership of a sensitive group.
  • Post and documents misdirected Letters, statements or medical records sent to a previous address or to the wrong person entirely.
  • Medical records disclosed Health data is special category data. Unauthorised access to it — including by a curious member of staff — is treated seriously.
  • Employee snooping Staff accessing records they have no business reason to look at. The employer is usually liable for it.
  • Lost devices and paperwork Unencrypted laptops, phones, USB sticks and files left where they should not be.
  • Data kept far too long Holding personal data for years past any lawful purpose, so a later breach exposes far more than it should have.
  • Disclosure to an abuser or ex-partner Releasing an address or contact details to someone the data subject is trying to stay away from. Among the most serious breaches there is.

The ICO does not pay compensation

This is the most common misunderstanding we hear, and it costs people time.

The Information Commissioner's Office is the UK's data protection regulator. It investigates, it can require an organisation to change how it operates, and it can issue substantial fines. Those fines go to the Treasury, not to you. The ICO has no power to award you compensation.

Complaining to the ICO is still worth doing, and often worth doing first. It costs nothing, and a finding that an organisation breached the legislation is useful evidence if you go on to claim. But the ICO is not a route to a payment, and if compensation is what you are after, it is a civil claim that produces it.

The two are not alternatives. Many of our clients complain to the ICO and bring a claim.

When you do not have a claim

Most pages competing for these searches will not tell you this. It is the most useful thing on this page.

The Supreme Court held in Lloyd v Google that there is no right to compensation simply for "loss of control" of your data. You must show that the breach caused you material damage or non-material damage — in practice, financial loss or genuine distress. Being one of several million people named in a breach notification, with nothing having happened to you since, is not by itself a claim.

The High Court in Rolfe v Veale Wasbrough Vizards struck out a claim arising from a single misdirected email, describing the alleged distress as below the level the law is concerned with, and ordered the claimants to pay costs. There is a de minimis threshold, it is real, and falling below it can leave you worse off than doing nothing.

Warren v DSG Retail matters too. Where an organisation is itself the victim of a cyber attack, the court struck out the misuse of private information, breach of confidence and negligence claims, leaving only the statutory data protection claim. That narrows the routes available and affects how a claim is funded.

So the honest picture is this. A breach notification letter on its own is usually not enough. What turns it into a claim is what happened next: money taken, an account opened in your name, sensitive information reaching people who should never have had it, or distress serious enough that you can describe its effect on your life. If you have that, you may well have a good claim. If you have only the letter, we will tell you.

What makes a data breach claim strong

The claims that succeed tend to share the same features, and they are worth knowing because they tell you what to gather.

  • Special category data was involved Health, sex life, sexual orientation, religion, ethnicity, political opinion, trade union membership, biometrics, or criminal offence data. The law treats these as needing the highest protection and the courts follow suit.
  • The data actually reached someone Evidence that a third party received or opened it, rather than a theoretical risk of exposure. In Farley v Paymaster many claims failed precisely because there was no evidence anyone had opened the letter.
  • There has been real misuse Fraudulent transactions, credit applications in your name, phishing that references the leaked data, or contact from someone who should not have your details.
  • The distress is documented A GP record of anxiety, a sleep problem, time off work, or a course of treatment. Distress described in a witness statement carries far more weight when there is a contemporaneous record behind it.
  • There are consequential costs Credit monitoring, replacing documents, calls and time spent putting things right, and any money you did not get back.
  • The organisation was clearly at fault An ICO finding, an admission in the breach notification, or an obvious failing such as unencrypted data or no access controls.

Medical and NHS data breaches

Health data is special category data under Article 9 of the UK GDPR, and breaches involving it are treated more seriously than breaches of a name and address.

The patterns we see most are records sent to the wrong patient or the wrong address, results discussed with the wrong person, staff accessing the records of someone they know without any clinical reason, and details of a condition reaching an employer or a family member. Where a diagnosis is something a person had chosen not to share, the distress of it becoming known can be considerable — and the courts recognise that.

An NHS trust, a GP practice, a dental practice, a private clinic and a pharmacy are all data controllers, and all can be liable. Where the breach was caused by an employee acting without authority, the employer can still be liable for it.

Complaining to the trust or practice through its complaints procedure, and to the ICO, runs perfectly well alongside a claim, and the disclosure those processes produce is often useful.

What you can claim for

Compensation under Article 82 has two parts, and it helps to keep them separate in your mind because they are proved in completely different ways.

Material damage is financial loss caused by the breach. Money taken from an account and not refunded, the cost of credit monitoring, replacing identity documents, the cost of putting your credit file right, and any loss of earnings — for example time taken off work to deal with the consequences. This is arithmetic, it is provable with documents, and you should keep every receipt.

Non-material damage is the distress. Section 168 of the Data Protection Act 2018 confirms that distress counts as damage for these purposes. There is no tariff for it. A court assesses it on the facts: how sensitive the data was, how widely it went, whether it was misused, how long the anxiety lasted, and what effect it actually had on you.

That is why this page carries no compensation table. Anyone publishing one is inventing a tariff the law does not have, and the figures are usually chosen to encourage a claim rather than to describe reality. What we will do is tell you what your case looks like compared with the awards courts have actually made, once we know the facts.

What to do in the first week

If you have been told your data was involved in a breach, a few things are worth doing straight away — whether or not you ever claim.

  • Keep the breach notification The letter or email telling you what happened, and any reference number. It is the foundation of everything that follows.
  • Make a subject access request Article 15 of the UK GDPR entitles you to a copy of your personal data and information about the breach, free of charge, normally within one month. It is the most effective way to find out what was actually exposed.
  • Check your credit file Look for applications you did not make. A statutory credit report is inexpensive and a fraud alert can be added if anything looks wrong.
  • Change passwords and enable two-factor Particularly anywhere you reused the same password. This limits the damage and shows you acted reasonably.
  • Write down the effect on you While it is fresh — what you have worried about, what you have had to do, sleep, time off. If you saw your GP about it, say so.
  • Complain to the ICO Free, and a finding in your favour is useful evidence. Just do not expect a payment from it.

Time limits and how a claim runs

A data protection claim in England and Wales carries a six-year limitation period, so there is usually no immediate rush — but evidence is much easier to gather early, and organisations only retain breach records for so long.

A claim normally begins with a letter of claim setting out what data was involved, how the organisation failed, and the damage caused. Most organisations investigate and respond, and a significant proportion of well-founded claims settle without proceedings. Where they do not, the claim is issued in the county court.

One consequence of Warren v DSG is worth being clear about at the outset: because a data breach claim against an organisation that was itself hacked is likely to be a statutory claim alone, the funding options are narrower than in some other kinds of claim. We will explain exactly what a claim would cost you, and what you would keep, before you commit to anything.

What compensation can cover

Two categories, proved in different ways. Keep documents for the first and a written account for the second.

  • Money taken and not refunded
  • Fraudulent credit taken out in your name
  • The cost of credit monitoring and protective registration
  • Replacing identity documents
  • Putting your credit file right
  • Lost earnings and time spent dealing with it
  • Anxiety, distress and loss of sleep
  • Treatment where the distress caused a recognised condition

How a claim runs

  1. Free assessment Day 1

    You tell us what data was involved and what has happened since. We tell you honestly whether it crosses the threshold — this is the conversation where we say no if the answer is no.

  2. Subject access request Weeks 1–5

    We ask the organisation for a copy of your data and the detail of the breach. They normally have one month to respond.

  3. Letter of claim Months 2–3

    We set out the failings, the data involved and the damage caused, supported by your evidence and any ICO findings.

  4. Investigation and response Months 3–6

    The organisation and its insurers investigate. Well-evidenced claims are frequently resolved at this stage.

  5. Negotiation or proceedings Months 6–18

    Most claims settle. Where an organisation will not engage, the claim is issued in the county court.

Been told your data was in a breach?

You have six years, so there is no need to panic — but do the first-week steps now while the evidence exists. Make a subject access request, keep the notification, check your credit file, and write down how it has affected you. Then talk to a solicitor who will tell you straight whether it is worth pursuing. A great many breach notifications do not amount to a claim, and you deserve to be told that by someone who is not paid to say otherwise.

Get an honest assessment
Common Questions

Data breach compensation FAQ

How much compensation can I get for a data breach?
There is no tariff, and any site showing you a table of figures has invented one. Compensation under Article 82 UK GDPR covers material damage — money you actually lost, which is provable arithmetic — and non-material damage, meaning distress, which a court assesses on the facts. What drives it is how sensitive the data was, how far it travelled, whether it was actually misused, how long the effects lasted and what they were. Tell us what happened and we will compare it with awards courts have really made.
Does the ICO pay compensation?
No. The Information Commissioner's Office regulates data protection: it investigates, requires organisations to change their practices and can issue fines. Those fines are paid to the Treasury, not to affected individuals. Compensation comes only from a civil claim. Complaining to the ICO is still worthwhile and costs nothing, and a finding in your favour is useful evidence in a claim — but it is not a route to a payment.
I got a breach notification letter. Do I automatically have a claim?
No, and this is where a lot of misleading advertising sits. In Lloyd v Google the Supreme Court held there is no compensation for mere loss of control of data — you must show material damage or genuine distress. In Rolfe v Veale Wasbrough Vizards the High Court struck out a trivial claim and ordered the claimants to pay costs. A notification letter with nothing having happened since is usually not enough. What creates a claim is what followed: misuse, fraud, sensitive data reaching the wrong people, or distress you can describe and evidence.
What is the time limit for a data breach claim?
Six years in England and Wales for a claim under the data protection legislation. That is longer than most people expect, so there is rarely an immediate deadline. Act early anyway: organisations retain breach records for limited periods, and a subject access request made soon after the breach produces far better evidence than one made years later.
Can I claim for a medical or NHS data breach?
Yes. Health data is special category data under Article 9 UK GDPR and is treated with particular seriousness. Records sent to the wrong patient or address, results discussed with the wrong person, staff accessing records without a clinical reason, or a diagnosis reaching an employer or relative are all capable of founding a claim. NHS trusts, GP and dental practices, private clinics and pharmacies are all data controllers, and an employer can be liable for an employee who accessed records without authority.
Do I need to prove financial loss to claim?
No. Section 168 of the Data Protection Act 2018 confirms that distress alone counts as damage. But the distress must be real and more than trivial — the de minimis threshold applied in Rolfe is a genuine obstacle to weak claims. Evidence helps enormously: a GP record, time off work, or a clear account of the effect on your daily life carries far more weight than a general assertion of upset.
What if the company was hacked — is it still their fault?
Often, yes. Being the victim of a cyber attack does not excuse an organisation that failed to take appropriate technical and organisational measures to protect your data. What Warren v DSG Retail decided is narrower: where the organisation was itself attacked, the misuse of private information, breach of confidence and negligence claims were struck out, leaving the statutory data protection claim. That affects the legal routes and the funding, not whether a claim exists.
Will claiming cost me anything if I lose?
We will explain the funding position in writing before you commit to anything, and we will not take on a claim we do not think should be brought. Be cautious of anyone promising a risk-free data breach claim: Rolfe shows that a weak claim can end in a costs order against the claimant, and since Warren v DSG the funding options in breach claims are narrower than they once were. Any firm not mentioning that is not giving you the full picture.
Should I complain to the organisation first?
Usually yes, and make a subject access request at the same time. Article 15 UK GDPR entitles you to a copy of your personal data and information about the breach, free of charge and normally within a month. That tells you what was actually exposed, which is the single most useful thing to establish before deciding whether to claim. Complaining to the organisation and to the ICO does not prevent a claim and frequently strengthens one.
This work is No Win, No Fee

Nothing to pay upfront. No fee at all if it does not succeed.

Claims of this type are handled under a conditional fee agreement. You pay us nothing to start, nothing as it runs, and no legal fee whatsoever if the claim does not win. If it does, our fee is a percentage of your compensation — capped, and agreed with you in writing before any work begins.

  • Nothing upfront No deposit, no hourly billing, no invoice while the case runs.
  • Nothing if you lose The fee is conditional on winning. If the claim fails you owe us nothing for our work.
  • Capped, and in writing You see the percentage and a worked example in pounds before you sign anything.

It is not the same as risk-free, and we will not tell you it is. Our fee genuinely is — but the wider costs position has exceptions worth understanding before you start. Read exactly how it works, and what it does not cover →

Related services

Has your data been exposed?

One free call and we will tell you whether you have a claim worth bringing — honestly, including when the answer is no.

Ask about this