Privacy & Data · United Kingdom · Compensation

Data-Breach Compensation in the UK: When Distress Can Support a Claim

A data breach does not automatically create a payout. But UK data-protection law recognises non-material damage such as distress, and a claimant can seek compensation where the legal requirements are met.

Distress Can Be Compensable Under UK Data-Protection Law

Article 82 UK GDPR provides a right to compensation for material or non-material damage caused by an infringement. Section 168 of the Data Protection Act 2018 expressly states that, for Article 82, "non-material damage" includes distress.

The ICO confirms that compensation can cover distress and other non-material damage. But there must be damage caused by the infringement: a breach of the law by itself does not automatically establish a compensable claim.

What Lloyd v Google Actually Decided

The Supreme Court's 2021 decision in Lloyd v Google [2021] UKSC 50 concerned the old Data Protection Act 1998 and a proposed representative/class-style claim. The Court held that the proposed representative action could not recover damages simply by proving that everyone fell within the alleged class; individual circumstances and entitlement had to be established.

It is therefore inaccurate to cite Lloyd as saying "no one can recover for distress without financial loss" under the current UK GDPR. The current regime is different, and the DPA 2018 expressly recognises distress as non-material damage.

You Still Need Evidence of Impact

The ICO warns that if a claimant cannot demonstrate damage or distress, a court may not award compensation and costs risks can arise. Build a contemporaneous record of what happened and its effect on you.

Financial or Medical Data Can Make the Evidence More Concrete

A breach involving health, financial or identity information can create serious risks, but the category of data alone does not establish a fixed compensation amount. The court looks at the circumstances and impact of the individual claim.

How to Approach the Company

  1. Ask the organisation for details of the incident and the data affected.
  2. Preserve the breach notice and all correspondence.
  3. Set out the harm you say the breach caused.
  4. Ask whether the organisation will settle compensation.
  5. If no agreement is reached, consider independent legal advice before court proceedings.

The ICO can investigate data-protection compliance but cannot award compensation. A compensation claim is ultimately for the organisation and, if necessary, the court to resolve.

What This Means Practically

Sources