Most individual UK data breach compensation payouts land in the hundreds to low thousands of pounds, not the five-figure sums claims firms advertise.
Article 82 of the UK GDPR gives you a right to compensation for financial loss and distress. What you recover depends on evidence of harm to you personally, not on how alarming the breach sounds.
What the law actually entitles you to
The right sits in Article 82 UK GDPR and section 168 of the Data Protection Act 2018. It splits into material damage, meaning money you lost, and non-material damage, meaning distress and disruption.
You claim against the organisation that held your data, not the criminals who took it. An accidental disclosure, such as an email sent to the wrong recipient, can found a claim just as a ransomware incident can.
In England and Wales you generally have six years to bring a claim. Waiting for the story to leave the news does not cost you that right.
Financial loss and distress get priced separately
Material damage is the easier half to argue. Fraudulent transactions, credit applications you had to unwind, replacement documents and lost earnings all convert into a figure you can evidence.
Non-material damage is where cases are won and lost. Courts value distress by analogy with personal injury guidance, so a diagnosed anxiety disorder is worth far more than being annoyed.
Sensitivity drives the number hard. Leaked health records, immigration status or debt details attract far more than a leaked postal address.
Why the ICO will never send you a cheque
The Information Commissioner’s Office enforces data protection law and can fine an organisation. It has no power to award you compensation, and penalties go to the Treasury rather than to victims.
Complaining to the ICO is still worth doing. A regulatory finding that an organisation failed to protect data is useful evidence in your own claim.
The mechanics of the incident matter too. Our analysis of the Crunchyroll data breach shows the timeline detail that separates negligence from bad luck.
The threshold that stops most small claims
Two decisions shape what is realistic. In Rolfe v Veale Wasbrough Vizards (2021), a claim over a single misdirected email was struck out because the upset fell below the level courts will compensate.
In Lloyd v Google (2021), the Supreme Court refused to allow a uniform per-person award for mere loss of control of data. Everyone in a mass breach has to prove their own damage.
The practical effect is that large breaches do not produce automatic payouts. A claim needs your specific consequences, documented.
Bringing a claim without giving away a third of it
Claims under £10,000 usually sit on the small claims track, where you can act for yourself and your costs exposure is limited. That suits most single-victim breach claims.
No-win-no-fee agreements are common, but the success fee comes out of your damages, so a modest award shrinks fast. Get the deduction in writing before signing.
Start with a letter of claim to the organisation’s data protection officer, setting out what happened and what it cost you.
Many settle at that stage, particularly where their own incident response process was slow, or where duties under the NIS2 compliance regime already put them under scrutiny.
How long does a UK data breach claim take?
A claim settled by correspondence can conclude in a few months. Contested claims that reach a hearing run considerably longer, depending on court listing times.
Can I claim if I have not lost any money?
Yes. Distress alone can support a claim, but it has to be genuine and evidenced, and trivial irritation will not clear the threshold the courts apply.
Do I need a solicitor to claim?
Not for a small claim. Legal help becomes worthwhile when the data was highly sensitive, when you suffered a diagnosed psychiatric injury, or when losses exceed the small claims limit.