This guide is maintained as a current resource for July 2026 and covers only the laws of England and Wales. Information is for general guidance, not legal advice. Consult a qualified solicitor for advice specific to your situation.
Limitation period guidance for data breach compensation claims in England and Wales, explaining time limits under UK GDPR, the Data Protection Act 2018, and related legal causes of action, including key exceptions, start dates, and court rules affecting claims.

Data breach compensation claims arise where an organisation fails to protect personal data in accordance with UK data protection law, resulting in financial loss, distress, or other harm. In England and Wales, these claims are subject to strict legal time limits known as limitation periods. If a claim is issued after the relevant deadline, it may be barred by the court regardless of its merits.
The limitation period depends on the legal basis of the claim, which may include breach of statutory duty under the UK GDPR, the Data Protection Act 2018, misuse of private information, negligence, or breach of the Human Rights Act 1998.
Legal Basis for Data Breach Compensation Claims
Data breach compensation claims commonly rely on:
- UK GDPR (Article 82) – right to compensation for material and non-material damage, including distress
- Data Protection Act 2018 – supplementary enforcement and procedural rules
- Misuse of private information – a tort claim developed through case law
- Negligence – where a duty of care is breached
- Human Rights Act 1998 – Article 8 (right to private and family life), in claims against public authorities
Each legal route has its own limitation framework, though courts often apply the Limitation Act 1980 as the starting point for civil claims in England and Wales.
General Limitation Period Under UK Law
Most civil claims are governed by the Limitation Act 1980, which sets the standard time limits for bringing proceedings. In general:
- 6 years is the default limitation period for most civil claims, including contractual and many tort-based claims
- Time usually runs from the date the cause of action arises (for example, when the breach occurs or damage is suffered)
For data breach compensation claims, this 6-year period is commonly relevant where the claim is framed in tort (such as misuse of private information or negligence).
Limitation Period for Data Protection and GDPR Claims
1. Claims under UK GDPR (Article 82)
Claims for compensation under UK GDPR Article 82 are typically treated as civil claims without a specific statutory limitation period in the GDPR itself. As a result, courts generally apply:
- 6-year limitation period in England and Wales (Limitation Act 1980 framework)
This applies whether the claim is brought for:
- Financial loss
- Distress (non-material damage)
- Combined losses
2. Data Protection Act 2018 Claims
The Data Protection Act 2018 supports UK GDPR rights and provides procedural mechanisms, including court applications under sections such as:
- Section 167 (compliance orders)
- Section 168 (compensation for contravention of UK GDPR)
These claims also generally follow the 6-year civil limitation period, unless a different cause of action applies alongside them.
Alternative Legal Routes and Their Limitation Periods
1. Misuse of Private Information
- Usually subject to a 6-year limitation period
- Classified as a tort claim
- Common in data breach cases involving publication or disclosure of sensitive information
2. Negligence Claims
- Standard limitation period: 6 years
- Time runs from when damage occurs, not necessarily when the breach happens
3. Human Rights Act 1998 Claims
Where a data breach involves a public authority:
- Limitation period is typically 1 year
- Courts may extend this period if it is equitable to do so
This is significantly shorter than other routes and can affect strategy in claims involving public bodies such as councils or NHS organisations.
When Time Starts Running
The start date for limitation depends on the type of claim:
- Data breach date – when the unauthorised access or disclosure occurred
- Date of knowledge – when the claimant became aware (or should reasonably have become aware) of the breach and resulting harm
- Ongoing breaches – limitation may run from the last act in a continuing course of conduct
In practice, disputes often arise over when a claimant “knew enough” to bring proceedings.
Extension and Suspension of Limitation Periods
The limitation period may be extended or paused in certain situations:
1. Deliberate concealment
If an organisation deliberately hides a breach, the limitation period may be postponed until discovery.
2. Lack of knowledge
Where harm is not immediately discoverable, courts may apply a delayed start based on reasonable awareness.
3. Children and protected parties
If the claimant is under 18, time usually does not start running until their 18th birthday.
Practical Issues in Data Breach Claims
1. Early evidence gathering
Claimants are expected to act promptly in:
- Requesting subject access information
- Preserving communications and notifications
- Documenting financial loss or distress
2. Pre-action protocol requirements
Before issuing proceedings, parties are generally expected to follow pre-action procedures, which may involve a letter of claim and exchange of information.
3. Risk of time-bar
If proceedings are issued after the limitation period expires:
- The defendant can raise a limitation defence
- The court may strike out or dismiss the claim
- Settlement leverage may be reduced significantly
Common Misunderstandings
1. “ICO complaints extend time limits”
Complaints to the Information Commissioner's Office do not pause or extend limitation periods for court claims.
2. “Ongoing investigation stops the clock”
Regulatory or internal investigations do not automatically suspend limitation time.
3. “Limitation runs from discovery of harm only”
This is not always correct. It depends on whether the court applies a “date of knowledge” approach or strict accrual rules.
Key Takeaways
The limitation period for data breach compensation claims in England and Wales is generally 6 years, based on the Limitation Act 1980 framework. This applies to most claims brought under UK GDPR, the Data Protection Act 2018, negligence, and misuse of private information.
However, where claims involve public authorities under the Human Rights Act 1998, the limitation period is typically 1 year, subject to possible extension.
The start of the limitation period depends on when the breach occurred or when the claimant became aware of the harm. Extensions may apply in cases involving concealment or minors.