Received a GDPR Data Breach Letter — What You Need to Do
For anyone in the UK who has received a GDPR data breach or ICO letter — explaining what it means, key deadlines, and what to do next.
Opening an official letter about a data breach or a complaint to the Information Commissioner's Office (ICO) can feel alarming — especially if you are not sure what it means or what happens next. Take a breath. This document does not mean you are in serious legal trouble, and in many cases there are straightforward steps you can take to protect yourself. Here is a clear explanation of what you are dealing with and what to do about it.
What does this actually mean?
Under the UK General Data Protection Regulation (UK GDPR) — the law that controls how organisations handle your personal information — companies are required to tell you if your data has been involved in a breach. A data breach simply means your personal information (such as your name, email address, financial details, or health records) was accessed, lost, or shared without your permission.
You may have received one of two types of document:
- A data breach notification letter — sent by the organisation that lost or mishandled your data. This is them telling you what happened, what information was affected, and what they are doing about it.
- An ICO complaint acknowledgement or decision letter — sent by the Information Commissioner's Office, which is the UK's independent data protection regulator. This means either you or someone else has raised a concern, and the ICO is involved.
Neither letter automatically means a court case is coming. However, depending on what happened to your data, you may have the right to claim compensation for any distress or financial loss you have suffered.
Do you need to act immediately?
In most situations you have time to think clearly — but there are some important deadlines to be aware of:
- ICO complaints: If you want the ICO to investigate an organisation, you generally need to raise your concern within three months of the organisation's last meaningful response to you. Waiting too long can limit what the ICO can do.
- Court claims: If you decide to pursue compensation through the courts — typically the County Court in England and Wales — the standard limitation period (the legal deadline for starting a claim) is six years under the Limitation Act 1980 for most data protection claims. However, do not leave it unnecessarily late.
- Responding to the organisation: If the letter asks you to verify your identity or confirm certain details, try to respond within any deadline they have set — usually 30 days.
- Fraud or financial risk: If your bank details, National Insurance number, or passwords were involved in the breach, act quickly. Contact your bank and change passwords today — this is not a legal step, but it is the most urgent practical one.
Your next steps
- Read the letter carefully. Note what data was affected, when the breach happened, and what the organisation says it is doing to fix the problem.
- Secure your accounts. Change passwords, enable two-factor authentication (an extra login check — usually a code sent to your phone), and alert your bank if financial information was involved.
- Keep records. Save the letter and any emails. Note any distress, time spent dealing with this, or financial losses — these details matter if you later claim compensation.
- Contact the organisation directly. You can write to them asking for a full explanation. Under UK GDPR, they must respond to a subject access request (a formal request to see what data they hold about you) within one calendar month.
- Report to the ICO if you are not satisfied. If the organisation does not respond properly or you believe they handled your data unlawfully, you can complain to the ICO at ico.org.uk free of charge.
- Consider a compensation claim. If you have suffered financial loss or significant distress, UK GDPR and the Data Protection Act 2018 give you the right to claim compensation. Cases are usually heard in the County Court.
When should you speak to a solicitor?
You do not always need a solicitor straight away, but it is worth getting legal advice if:
- Sensitive data was exposed — such as health records, financial information, or details about your children
- You have already suffered financial loss or fraud as a result of the breach
- The organisation is ignoring you or disputing what happened
- The ICO has closed your complaint without the outcome you expected and you are considering going to court
- You are unsure whether your situation is strong enough to justify a claim
Many data protection solicitors offer a free initial consultation, and some work on a no win, no fee basis — meaning you only pay if your claim succeeds.
If you are not sure where to start, CaseBridger is a free tool that gives you instant AI-powered guidance tailored to your specific situation and can help you find a qualified solicitor who handles data protection claims in the UK.
Is this your situation?
Describe exactly what's happened and get specific guidance for your case. Free, instant, no jargon.
Get free legal guidance →