My data was leaked — can I actually claim compensation, and how much?
Probably not just because your data was in a breach. UK law only pays out if you can show you suffered loss or distress because an organisation broke the rules — and where claims do succeed, the sums are usually modest. Lloyds' goodwill payments after its March 2026 app fault averaged around £38 each.
Last updated 31 July 2026. This page explains the law as it stands on that date. It is general information, not legal advice.
The bottom line
Being caught up in a data breach does not by itself entitle you to compensation. You have to show you suffered damage — financial loss or distress — because an organisation broke data protection law. The Court of Appeal held in August 2025 that there is no minimum seriousness threshold, but the Supreme Court is listed to reconsider that on 7 and 8 October 2026. The law is not settled.
Do I have a claim just because my data was in a breach?
No. Article 82(1) of the UK GDPR gives a right to compensation to "any person who has suffered material or non-material damage as a result of an infringement of this Regulation". Three separate things have to be true.
- An infringement. The organisation broke a data protection rule — for example, it failed to keep your information secure.
- Damage. Something happened to you. Material damage means financial loss. Non-material damage covers distress: section 168(1) of the Data Protection Act 2018 says so expressly.
- Causation. The damage happened *as a result of* the infringement, not merely around the same time.
This is why "my name was on the list" is not a claim on its own. In [Lloyd v Google LLC [2021] UKSC 50](https://www.supremecourt.uk/cases/uksc-2019-0213), decided on 10 November 2021 under the older Data Protection Act 1998, the Supreme Court stopped a representative claim brought for around four million iPhone users because compensation cannot be awarded for loss of control of data in the abstract, without looking at what each individual actually suffered. Later cases have changed how seriousness is treated, but the need to show what actually happened to you has not gone away.
Being notified is not proof of a claim either. Article 34 requires an organisation to tell you about a breach when it is likely to result in a high risk to your rights and freedoms. That letter is a warning, not an admission that you are owed money.
What did the Court of Appeal decide in Farley v Paymaster?
[Farley and others v Paymaster (1836) Ltd trading as Equiniti [2025] EWCA Civ 1117](https://www.judiciary.uk/wp-content/uploads/2025/08/Farley-and-others-v-Paymaster-trading-as-Equiniti.pdf) was decided on 22 August 2025. More than 750 annual pension benefit statements belonging to Sussex Police officers were posted to out-of-date addresses. They contained dates of birth, National Insurance numbers, salary, length of service and accrued pension benefits, and revealed that the recipients were police officers. At first instance, all but 14 of the 432 claims were struck out — only those 14 claimants were held to have a real prospect of showing that their statement had actually been opened and read.
| Question | Court of Appeal, 22 August 2025 | Position on 31 July 2026 |
|---|---|---|
| Is there a minimum seriousness threshold for non-material damage? | No. Article 82 imposes no such threshold. | This is the exact issue before the Supreme Court |
| Must you prove a third party read your data? | No. Unlawful processing is enough. | Stands; not part of the certified issue on appeal |
| Can fear of misuse be damage in itself? | Yes — but only where the fear is objectively well founded. | Stands; sent back for individual assessment |
| Are hypothetical or speculative worries enough? | No. | Unchanged and not in dispute |
It is not settled law. The Supreme Court granted Paymaster permission to appeal on 17 December 2025. The certified issue is: "Does a threshold of seriousness apply to claims for damages under the General Data Protection Regulation and Data Protection Act 2018?" The Supreme Court case page lists a hearing on 7 and 8 October 2026, and no judgment had been given as at 31 July 2026. Check that page before relying on the Court of Appeal's ruling.
Can worry or fear of misuse alone count as damage?
It can, but not automatically. The Court of Appeal's test is whether you had a reasonable basis for fearing that your information had been or would be misused — judged on the facts, not on how upset you say you are. A serving police officer whose home address and National Insurance number went to a stranger is in a very different position from someone whose marketing email landed in the wrong inbox. Courts will still reject claims built on speculation.
Mass claims are not being shut down wholesale, though. In [Spurgeon and others v Capita plc [2026] EWHC 241 (KB)](https://www.bailii.org/ew/cases/EWHC/KB/2026/241.html), handed down on 9 February 2026, Master Dagnall refused to strike out claims by 3,973 people arising from Capita's March 2023 cyber attack, rejecting the argument that standardised distress wording in the particulars of claim made the whole exercise an abuse of process.
How much do these claims realistically pay?
There is no statutory minimum or maximum. A court assesses each case on the type of data, what happened to it and the effect on you. Two real reference points are worth more than any advertised average.
- Lloyds Banking Group. After a software fault on 12 March 2026 let Lloyds, Halifax and Bank of Scotland app users briefly see fragments of other customers' transactions, the bank told the Treasury Committee that up to 447,936 customers were potentially affected, and that by 23 March it had paid just over £139,000 in goodwill payments to around 3,625 customers for distress and inconvenience — an average of about £38 each. These are the bank's own figures, not the ICO's, and no ICO findings have been published.
- Farley. The claims the Court of Appeal revived were reported in legal commentary as pleaded at around £1,250 each. Nothing has been awarded: the case was sent back for individual assessment and is now under appeal to the Supreme Court.
Ignore advertised 'average payouts'
Figures such as "average payouts of around £6,000", or ranges like "£1,000 to £42,900", come from claims-firm marketing. They are not drawn from any published record of court awards. Treat them as advertising, not as a benchmark.
If the organisation is a regulated financial firm, the Financial Ombudsman Service can look at your complaint free of charge. Its published guidance is candid about the scale: a one-off small error with minimal impact is usually met by an apology or an award of under £100, £100 to £300 covers a larger single mistake or repeated small errors, and the higher bands are reserved for serious, sustained disruption. That is the realistic scale for most people, most of the time.
The organisation, the ICO, the ombudsman or the courts: who does what?
The ICO cannot award you compensation. It regulates organisations. It can investigate, give a view, issue reprimands and impose fines — but a fine is paid to the Treasury, not to you.
| Route | What it can do | Cost to you | What it cannot do |
|---|---|---|---|
| The organisation — DPA 2018 s.164A, in force 19 June 2026 | Must make complaining easy, acknowledge you within 30 days, respond and tell you the outcome | Free | Nothing forces it to pay you |
| The ICO — DPA 2018 s.165 | Investigate, give a view on whether the law was broken, take enforcement action | Free | Award you compensation, or order a payment to you |
| Financial Ombudsman Service — regulated firms only | Direct a firm to pay for distress and inconvenience; binding on the firm if you accept the decision | Free to you | Deal with councils, the NHS, schools or other non-financial bodies |
| County court or High Court — Article 82 and DPA 2018 s.180 | Award compensation; make a compliance order under s.167 | Court fees, plus costs risk if you lose | Be quick or cheap once a claim is defended |
Complaining to the organisation first is now the default route. Since 19 June 2026, section 103 of the Data (Use and Access) Act 2025 has inserted sections 164A and 164B into the Data Protection Act 2018. What has not gone is your right to go to the regulator. The DUAA omitted Article 77 of the UK GDPR on the same date, but section 165 of the Data Protection Act 2018 was widened to cover UK GDPR infringements and now carries that right. The ICO's guidance is that you should complain to the organisation and give it a reasonable period — it points to around 45 days — before bringing the complaint to the regulator.
In England and Wales, claims for a sum recoverable by statute are generally subject to a six-year time limit (Limitation Act 1980, section 9). Scotland has its own, different rules on prescription.
Claims companies, cold calls and fake 'compensation' texts
If someone rings you out of the blue offering to run a data breach claim, that call is very likely unlawful. Regulation 21A of PECR has banned unsolicited direct marketing calls about claims management services since 8 September 2018, unless you consented to receive them. A legitimate solicitor should not be cold-calling you.
- No genuine claim needs an upfront fee. Requests for money, card details, bank details or ID documents to "release" your compensation are the standard fraud pattern.
- Check the regulator's own register. Solicitors are regulated by the SRA; claims management companies in Great Britain are regulated by the FCA. Look the firm up yourself — never on a number or link supplied in the message.
- Fake enforcement texts are an active enforcement priority. On 20 May 2026 the ICO fined KRA Consultancy Ltd £300,000 over more than 5.5 million unsolicited marketing texts, some of them posing as bailiff enforcement notices, which generated over 60,000 complaints to the ICO and the 7726 spam reporting service.
- 'No win, no fee' is not free. Success fees and insurance premiums come out of the award. On a claim worth a few hundred pounds, that can leave very little.
Practical first steps
- Step 1 Find out what was actually involved Read the breach notification and ask the organisation precisely which of your data was affected. Checking your email address on the free, independent service haveibeenpwned.com shows which known breaches it has appeared in. It is not run by the ICO.
- Step 2 Write to the organisation Set out what happened, what harm it caused you, and what you want. Since 19 June 2026 it must acknowledge your complaint within 30 days under section 164A.
- Step 3 Keep evidence of harm, not just upset Bank statements, fraud reports, correspondence, medical notes, a dated diary of what you did and when. A documented consequence is far stronger than generalised distress.
- Step 4 Escalate to the right body The ICO for a view on the organisation's conduct. The Financial Ombudsman Service if it is a bank, insurer or other regulated firm and you want money.
- Step 5 Get advice before signing anything Compare bringing a small claim yourself against a funded claim, and read the deduction terms in full before you agree to them.
This page is general information about what the law says. It is not legal advice about your situation, and this site is not the ICO.
Common questions
I've had a letter saying my data was in a breach. Am I automatically owed compensation?
No. Article 82 of the UK GDPR requires you to have suffered material or non-material damage as a result of the infringement. Notification under Article 34 means the organisation judged the breach likely to be high risk to you — it is not an admission that you are owed money. You still have to show what actually happened to you and connect it to the failure.
Can the ICO make a company pay me compensation?
No. The ICO regulates organisations. It can investigate, give a view on whether the law was broken, issue reprimands and impose fines — but fines are paid to the Treasury. Compensation has to come from the organisation agreeing to pay, from the Financial Ombudsman Service if the organisation is a regulated financial firm, or from a court claim under Article 82.
How much is a data breach claim actually worth?
There is no statutory minimum or maximum, and it depends on the type of data, what happened to it and the effect on you. For scale: Lloyds paid just over £139,000 in goodwill payments to about 3,625 customers after its March 2026 app fault, roughly £38 each; the revived claims in Farley v Paymaster were reported as pleaded at about £1,250 each, though nothing has yet been awarded. Advertised 'average payouts' of several thousand pounds come from claims-firm marketing, not court data.
Is Farley v Paymaster still good law?
As at 31 July 2026, yes — the Court of Appeal's judgment of 22 August 2025 stands. But the Supreme Court granted permission to appeal on 17 December 2025 and the hearing is listed for 7 and 8 October 2026 on whether a seriousness threshold applies. Check the Supreme Court case page (UKSC 2025-0185) before relying on it.
How long do I have to bring a claim?
In England and Wales, claims of this kind are generally subject to a six-year limit under section 9 of the Limitation Act 1980, running from when the cause of action accrued. Scotland has separate prescription rules. Do not leave it: evidence of distress and of what you did at the time gets much harder to assemble years later.
Someone texted me saying I'm owed thousands from a big-name breach. Is it genuine?
Treat it as fraud until proved otherwise. Unsolicited marketing calls about claims management services have been banned since 8 September 2018 under regulation 21A of PECR, and legitimate solicitors do not cold-call about data breach claims. Never pay an upfront fee, never send ID or bank details in response, and check the firm on the SRA or FCA register using contact details you found yourself.
Sources
This page summarises the following primary sources. Where they disagree with this summary, they take precedence.
- Article 82 UK GDPR — right to compensation and liability (legislation.gov.uk)
- Data Protection Act 2018, section 168 — non-material damage includes distress
- Data Protection Act 2018, section 165 — complaints by data subjects to the Commissioner (as amended, in force 19 June 2026)
- Data Protection Act 2018, section 180 — which courts hear compensation claims
- Data (Use and Access) Act 2025, section 103 — inserts DPA 2018 ss.164A and 164B and omits Article 77 UK GDPR, in force 19 June 2026
- The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026, SI 2026/82
- Lloyd v Google LLC [2021] UKSC 50, 10 November 2021 (UK Supreme Court)
- Farley and others v Paymaster (1836) Ltd t/a Equiniti [2025] EWCA Civ 1117, 22 August 2025 (judiciary.uk)
- UK Supreme Court case page — Farley v Paymaster, UKSC 2025-0185, hearing listed 7–8 October 2026
- Spurgeon and others v Capita plc [2026] EWHC 241 (KB), 9 February 2026 (BAILII)
- PECR regulation 21A — ban on unsolicited calls marketing claims management services
- Financial Ombudsman Service — compensation for distress or inconvenience (award bands)
- Treasury Committee — Lloyds Banking Group figures on the 12 March 2026 app incident
- ICO — KRA Consultancy Ltd monetary penalty notice, 20 May 2026
- ICO — make a data protection complaint about an organisation
Related guidance
-
We've had a data breach — do we have to tell the ICO within 72 hours, and do we have to tell customers?
You must tell the ICO within 72 hours only if a breach is likely to risk people's rights. Telling customers needs high risk. What changed in 2025-26.
-
How to ask a company for all the data it holds on you — and what to do if they ignore or redact it
How to make a subject access request under Article 15 UK GDPR, what an organisation may redact, the new stop-the-clock rule, and how to complain in 2026.