← Back to Blog

Your Personal Data Leaked or Misused? How to Claim Compensation for a Data Breach (UK)

You get the email nobody wants to receive: "We are writing to let you know about an incident affecting your personal data." A company has leaked, lost, or misused information about you — a database left exposed, an email with your details sent to the wrong person, records handed to someone who should never have seen them. The apology usually offers little more than a year of credit monitoring. What it rarely mentions is that, in the right circumstances, you may have a legal right to compensation — and that right can cover not just money you have lost, but the distress the breach caused you. Here is how it really works, and — just as importantly — where the limits are.

Where the Right to Compensation Comes From

The core right is in Article 82 of the UK GDPR, which says that anyone who has suffered material or non-material damage as a result of an infringement of the data protection rules has the right to compensation from the organisation responsible (the "controller", and in some cases the "processor"). Alongside it, section 168 of the Data Protection Act 2018 spells out that "non-material damage" includes distress. Together these are the foundation of every UK data-breach compensation claim.

In plain terms, there are two kinds of harm you can claim for:

The Catch: A Breach on Its Own Is Not Enough

This is the part the "you could be owed thousands" adverts skate over. The fact that an organisation broke the rules does not, by itself, entitle you to a payout. In the leading case Lloyd v Google (2021), the Supreme Court held that you cannot claim compensation for the mere "loss of control" of your data without showing that the breach caused you actual damage — real financial loss or genuine distress. You have to point to a specific harm the breach caused you, not just the fact that it happened.

Lloyd v Google also blocked a particular kind of US-style opt-out class action — one that tried to claim an identical, one-size-fits-all sum for millions of people without looking at how each person was actually affected. It did not ban group claims altogether, but it did mean that, in practice, each person's harm has to be looked at individually. The takeaway for you: to have a claim, be ready to explain concretely how the breach affected you — the worry it caused, the time you spent dealing with it, any fraud or financial loss that followed.

A Fast-Moving Area — Watch This Space

How much harm you must show is being actively fought over in the courts right now. In Farley v Paymaster (2025), the Court of Appeal held there is no minimum "seriousness" threshold a data-breach claim has to clear, and that a well-founded fear that your data might be misused can itself count as compensable distress — even if no one is proven to have actually accessed it. That is helpful to claimants. But it is not the final word: the case is going to the UK Supreme Court, with a hearing listed for October 2026, and the Supreme Court could narrow or overturn that position. Treat the current rules as favourable but unsettled — and never assume a trivial, no-effect breach is worth money.

The Myth That Costs People Their Claim: The ICO Does Not Pay You

Many people report a breach to the Information Commissioner's Office (ICO) and then wait for a cheque that never comes. Here is the crucial distinction: the ICO is the regulator. It can investigate an organisation, order it to change its practices, and issue fines that go to the public purse — but it cannot award compensation to you. Only a court can order an organisation to pay you.

That does not make complaining to the ICO pointless — an ICO finding that an organisation breached the rules can be useful supporting evidence if you later go to court. But if compensation is what you want, the ICO is a step along the way, not the destination.

How a Data-Breach Claim Actually Works

The usual route is:

Be wary of claims-management firms promising "£1,000s" and quoting an "average payout". There is no official tariff for data-breach distress — courts assess every case on its own facts, and many awards are modest. A firm that takes a large cut of a small award may leave you with very little.

How Long You Have to Claim

In England & Wales the general limit is six years under the Limitation Act 1980. In Scotland it is five years under the Prescription and Limitation (Scotland) Act 1973 (with a longer backstop). One nuance to be aware of: if your claim includes a recognised psychiatric injury, a shorter three-year personal-injury limit can apply to that part — so if the breach has genuinely affected your health, do not sit on it, and take advice promptly.

Putting It in Writing

Whichever route you take, it starts with a clear, firm letter to the organisation — one that identifies the breach, explains exactly how it affected you, refers to your right to compensation under Article 82 of the UK GDPR and the Data Protection Act 2018, and asks them to put things right. A letter that is specific about your harm is far more effective than a vague complaint, and it puts your claim formally on record.

Generate Your Data Breach Compensation Letter in Seconds

WriteMyLegalLetter drafts a clear, professional letter to the organisation that mishandled your data — setting out the breach, the harm it caused you, and your right to compensation under the UK GDPR, and putting your claim formally on record. Answer a few questions and your letter is ready.

Write My Data Breach Letter Now →