This guide is maintained as a current resource for July 2026 and covers only the laws of England and Wales. Information is for general guidance, not legal advice. Consult a qualified solicitor for advice specific to your situation.
Had your data exposed? Learn your rights under UK GDPR, the steps you must take to report it, and how to claim compensation for financial loss or distress.

A data breach happens when an organisation fails to adequately protect your personal information and that information is accessed, disclosed, lost or destroyed in an unauthorised way. Personal data can include your name, address, email, financial details, health records, and other information that identifies you. In the UK, the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 give you specific legal rights when your data is breached. This article explains those rights, the legal framework that protects you, the practical steps you can take after a breach, how to seek compensation, and what to expect from the process.
What Constitutes a Data Breach?
A data breach can arise from:
- Cyber‑attacks or hacking incidents.
- Human error, such as sending personal data to the wrong email address.
- Loss or theft of devices containing personal data.
- Inadequate security measures leading to unauthorised access.
Not every security incident has to be reported to you, but where there is a risk to your rights and freedoms, organisations must inform you and the Information Commissioner's Office (ICO) within a set timeframe.
Your Core Legal Rights
Right to Understand How Your Data Was Affected
Under UK GDPR, if an organisation determines that your personal data breach is likely to result in a high risk to your rights and freedoms, it must communicate details of the breach to you. This typically includes:
- The nature of the breach.
- The type of data that was compromised.
- The likely consequences.
- Remedial steps the organisation has taken or will take.
This right ensures transparency and helps you take protective steps, such as changing passwords, contacting your bank, or monitoring your credit file.
Right to Complain to the ICO
You can complain to the ICO, the UK's data protection regulator, if you believe an organisation has not complied with data protection law. The ICO can investigate and take enforcement action, including fines. However, the ICO cannot award compensation - only courts can do that.
Right to Claim Compensation
UK GDPR and the Data Protection Act 2018 give you the right to claim compensation if:
- Your personal data was breached because the organisation failed to comply with data protection law.
- You suffered either material damage (financial loss) or non‑material damage (distress, anxiety, loss of privacy) as a result.
This means you may have a claim even if no direct financial loss occurred, provided the breach caused distress. Courts have recognised claims for both material and non‑material harm.
Steps to Take After a Data Breach
1. Collect Evidence
Documenting what happened and how it affected you is essential. Useful evidence may include:
- Written communications from the organisation about the breach.
- Screenshots of breach notifications or emails.
- Records of financial loss or expenses incurred.
- Personal logs of distress, loss of sleep, or psychological impact.
This evidence will form the basis of any claim you pursue.
2. Contact the Organisation
Start by contacting the organisation responsible (the data controller) and asking:
- What happened and when.
- What data was affected.
- What steps they have taken to protect you.
Organisations may offer compensation directly, which can avoid court proceedings.
3. Report to the ICO
If you are not satisfied with the organisation's response, make a formal complaint to the ICO. While the ICO can investigate and fine organisations, it does not award compensation itself. Its findings may still support your civil claim.
4. Seek Legal Advice
Although you do not need a solicitor to make a claim, legal advice can help you assess the strength of your case, gather evidence, meet legal requirements, and navigate the court system. Some law firms offer No Win No Fee arrangements (Conditional Fee Agreements), where you only pay legal fees if your claim succeeds.
5. Initiate a Court Claim
If you cannot reach a settlement, you may take your claim to court. A civil claim for breach of data protection law is usually brought in the County Court or High Court depending on the value and complexity. A judge will decide whether your data protection rights were breached and, if so, whether you should receive compensation.
Time Limits for Bringing a Claim
Under the Limitation Act 1980, most claims for compensation must be started within six years of the breach. If you are claiming against a public body on human rights grounds, a shorter limitation period (often one year) may apply. Acting promptly is essential because missed deadlines can bar your claim.
What Compensation Might You Receive?
Compensation awards vary widely depending on the facts of the case. Courts consider factors such as:
- The severity of distress or anxiety caused.
- The extent of financial losses directly caused by the breach.
- The impact on your daily life, work and wellbeing.
Guidance like the Judicial College Guidelines may be used to assess non‑material damages, with higher awards for severe psychological harm and lower sums for less serious effects.
Compensation can cover:
- Financial losses (e.g. costs to protect against identity theft).
- Emotional distress, anxiety or depression linked to the breach.
- In rare cases, other impacts such as damage to reputation.
Practical Risks and Considerations
Proving Liability
To succeed in a claim, you must show:
- The organisation was responsible for the breach.
- The breach was caused by failure to follow data protection law.
- You suffered harm as a direct result of that breach.
If the organisation can show it took reasonable steps to prevent the breach, your claim may be weakened.
Costs and Settlement
Court proceedings can involve legal costs. Settling a claim without going to trial can save time and expense. No Win No Fee arrangements can limit upfront costs, but success fees are payable from any award you receive.
Group Claims
In high‑profile breaches, group litigation or collective actions may arise, where multiple claimants pursue compensation together. Such cases can attract legal expertise and shared resources, but individual claims vary based on personal impact.
Common Questions from our Readers
Do I need to prove financial loss to claim compensation?
No. UK GDPR allows claims for both material (financial) and non‑material (distress) damage if the breach caused you harm.
Can the ICO award me compensation?
No. The ICO can investigate and fine organisations, but it cannot award personal compensation. Only courts can do so.
What if the organisation offers an apology but no compensation?
You may still pursue a civil claim through the courts if the apology does not address your losses or distress and the breach involved failure to comply with data protection law.
Key Takeaways
If your personal data has been breached in the UK, you have specific rights under UK GDPR and the Data Protection Act 2018. These include the right to be informed about the breach, the right to complain to the ICO, and the right to claim compensation for financial loss or emotional distress. The process involves gathering evidence, contacting the responsible organisation, reporting to the ICO if necessary, and potentially bringing a court claim within strict time limits. Understanding your rights and options gives you greater control over how to respond to a data breach and seek appropriate remedies.