Can I Claim Compensation for a Data Breach?

Yes, you absolutely can claim compensation for a data breach if an organisation failed to comply with data protection obligations and you suffered damage as a result. It might seem difficult to grasp at first, but in today’s technology-forward world, your personal data is a precious commodity that needs to be protected – and the consequences of your data being negligently exposed can be severe. Here’s the thing: you do not necessarily need to have suffered financial loss to make a data breach claim. The exact requirements will depend on the nature of the claim, but it’s always worth a check!
Who can make a data breach claim?
There are three key criteria that must be satisfied in order for you to make a data breach claim:
- An organisation held your personal data.
- The organisation breached its obligations under UK data protection law – for example, by failing to appropriately protect personal data.
- You suffered material or non-material damage as a result of that breach.
Today, hundreds of companies likely have access to your personal data. For example, a supermarket might hold your data to arrange for food deliveries or to make transactions; a clothes retailer will track your preferences; a social network may use your data to inform the content (and ads!) that you see.
The most important thing is that, in using these services, you have consented to your data being used in a particular way, and the organisations providing the services are therefore legally required to keep your data safe.
Why? Well, data is more than lines of code flitting between apps. That information can be weaponised in a number of ways.
What counts as material and non-material damage?
Financial Loss
- Fraud: if a malicious actor gains access to your financial details, they may be able to obtain your money fraudulently.
- Identity theft: your personal details are what make you you. Stolen personal information may be used to impersonate you, open or access accounts in your name, or commit other forms of fraud.
- Unauthorised transactions: Most simply, a hacker with access to your bank details can use them for unauthorised purchases or transfers before the issue is identified and resolved.
- Additional costs: You may incur additional expenses such as replacing identity documents, paying for credit monitoring, or taking steps to secure your accounts.
Emotional Distress:
- Anxiety and stress: If the exposure of your data has led to significant stress, which has made your life demonstrably worse or more difficult, you could be eligible to receive compensation.
- Loss of sleep: Exposure of data ‘keeping you up at night’ is more than just an expression! Loss of sleep is considered a serious affliction that can result in underperformance at work, personal endangerment and more, and as such can result in compensation being paid out to those affected.
- Embarrassment or humiliation: In 2015, extramarital dating site Ashley Madison was targeted by hackers who exposed the data of its customers. Given that the membership of such a site being made public caused widespread embarrassment, the site’s US-based users launched three class-action lawsuits. Ashley Madison owner Ruby Life inc. settled for $11.2m (£8.57m).
Common situations that could lead to a claim
A company suffers a cyberattack: It might seem hyperbolic to talk about the dark web and black hat hacker groups, but in reality there’s a whole ecosystem of malicious actors locking horns with well-known organisations. Groups such as ‘ShinyHunters’ use extortion tactics to ransom data and selectively leak information to inflict maximum damage on organisations and consumers. If your data is caught up in a cyberattack, you could be eligible to seek compensation.
Your information is emailed to the wrong person: Sending personal information to the wrong recipient is a common form of data breach. If your information is received by the wrong person, that’s a data breach that could have significant consequences, especially if the information includes financial, medical or other sensitive personal data.
Your employer exposes confidential records: Your employer has a legal responsibility to keep your data secure and an obligation to ensure they only process what’s necessary for legitimate purposes. Confidential employment records, payroll information, disciplinary records or health information – if any of these types of records are disclosed or accessed without authorisation, there could be grounds for a data breach claim.
A public body loses sensitive data: Public authorities hold significant amounts of personal data and are required to protect it appropriately. If sensitive personal data is lost, disclosed or accessed without authorisation because appropriate safeguards were not in place, affected individuals may have grounds to seek compensation.
Common misconceptions
“I didn’t lose any money.” – It’s not always the case that you need to have suffered financial loss. Compensation may also be available if you have suffered genuine distress or anxiety resulting from the data breach, even if you haven’t experienced financial loss.
“The company apologised.” – Apologies are good, but often they aren’t enough to make you whole, and they don’t prevent you from bringing a claim. Remember, in certain circumstances, companies are legally required to inform you in a timely manner if your data has been exposed in a breach! The apology isn’t simply a courtesy or ‘good customer service,’ but may form part of a notification they're legally obligated to provide.
“My data wasn’t published online.” – It may be that your information has yet to be published. What’s more, a data breach may not involve the publication of the data in the first place: unauthorised access, loss, alteration or destruction of personal data can also form the basis of a claim. Even where there is no evidence that your information has been made available online, it doesn’t mean that it hasn’t been accessed by an unauthorised party or disclosed to others.
“The breach affected thousands of people.” – Data breaches can affect a single individual. In some cases, hundreds of thousands of people have been affected by a single data breach. So, it’s easy to think that your case is unimportant or that the damage you have suffered might not warrant compensation. Every case depends on its own facts, including the nature of the personal data involved, the circumstances of the breach, and the impact it has had on the individual concerned.
How can I check if I’m eligible for a data breach claim?
Pocket makes it easy to check if you could be eligible for a data breach claim. You’ll typically have to answer a few short questions confirming the following:
- You were a customer (etc.) of an organisation when a data breach occurred
- You were notified by said organisation that your data was exposed
- You suffered material or non-material damage as a result.
If it looks like you could be eligible to seek compensation, we’ll put you in touch with a trusted solicitor to take your claim forward. Generally speaking, they’ll investigate and advise on the merits of your claim before deciding to act on your behalf. If the solicitor can move forward with your claim, they should be able to explain how much compensation you could potentially receive and outline the next steps.
In most cases, our Pocket partners operate on a No-Win, No-Fee basis. Put simply, that means you pay nothing upfront – the partner law firm receives a ‘success fee’ that’s paid if you win your case. Terms and conditions vary, so it’s always worth checking the agreements you sign for specific details.
Think you may have a claim? Check your eligibility in just a few short questions and find out if you could be entitled to compensation.


