Pre-Action Protocol Letter — Data Breach Compensation Claim
Formal letter before action for a compensation claim following a personal data breach under UK GDPR Article 82 and the Data Protection Act 2018.
This template was not drafted by a solicitor.
It is an editorial reference based on the official sources we cite. You are responsible for any document you send. For high-stakes matters (court proceedings, large sums, deportation, criminal allegations, child welfare), have a regulated solicitor review or draft your document.
When to use this template
Use this letter when an organisation has suffered a data breach involving your personal data and you have suffered material or non-material damage as a result — including distress, financial loss, or loss of control over your personal information. Send this letter before issuing county court proceedings to comply with Practice Direction — Pre-Action Conduct.
When NOT to use this template
Do not send this letter purely to obtain a response about the breach — use a DSAR instead. If your primary goal is to make the organisation improve its security rather than claim compensation, consider a complaint to the ICO first. This letter is not a substitute for reporting the breach to the ICO if you believe it was a serious violation.
Legal Basis
UK GDPR Article 82 (right to compensation for material or non-material damage caused by an infringement); Data Protection Act 2018 s.168 (right to compensation); UK GDPR Articles 5, 32 (security obligations). Confirmed in Vidal-Hall v Google Inc [2015] EWCA Civ 311 that non-material damage (including distress) is compensable.
Before you send
- Failing to identify the specific infringement — courts require you to show the organisation breached a specific UK GDPR provision, not merely that a breach occurred
- Not quantifying non-material damage — describe the distress in concrete terms (sleep disruption, anxiety, professional embarrassment)
- Overlooking the need to show causation — you must demonstrate the damage flowed from the breach
Common Mistakes to Avoid
- ✗Failing to identify the specific infringement — courts require you to show the organisation breached a specific UK GDPR provision, not merely that a breach occurred
- ✗Not quantifying non-material damage — describe the distress in concrete terms (sleep disruption, anxiety, professional embarrassment)
- ✗Overlooking the need to show causation — you must demonstrate the damage flowed from the breach
- ✗Sending the letter to a generic enquiries address rather than the Data Protection Officer
- ✗Issuing proceedings while the ICO is still investigating — not prohibited, but courts may stay proceedings
Build Your Letter
Fill in your details
Complete the fields below. Required fields are marked with *.
Optional fields
Letter preview
[YOUR FULL NAME] [YOUR ADDRESS] [YOUR EMAIL ADDRESS] [DATE OF LETTER] Data Protection Officer [ORGANISATION NAME] [ORGANISATION ADDRESS] --- Dear Sir or Madam, **LETTER BEFORE ACTION — COMPENSATION CLAIM FOR DATA BREACH** **UK GDPR Article 82 / Data Protection Act 2018 s.168** I write in accordance with Practice Direction — Pre-Action Conduct and Protocols of the Civil Procedure Rules 1998 to give you formal notice of my intention to issue proceedings for compensation arising from a personal data breach. **The Breach** On or around [DATE BREACH OCCURRED OR WAS NOTIFIED] you notified me / I became aware that [DESCRIPTION OF THE BREACH] (the "Breach"). The Breach involved the following categories of my personal data: [CATEGORIES OF PERSONAL DATA AFFECTED]. **The Infringement** The Breach constitutes an infringement of the UK General Data Protection Regulation in one or more of the following respects: - Failure to implement appropriate technical and organisational measures to ensure security appropriate to the risk, contrary to UK GDPR Article 5(1)(f) and Article 32; - [ANY ADDITIONAL UK GDPR INFRINGEMENTS]. **The Damage I Have Suffered** As a direct result of the Breach I have suffered the following damage: *Material damage:* [MATERIAL (FINANCIAL) DAMAGE SUFFERED] *Non-material damage:* [NON-MATERIAL DAMAGE (DISTRESS)] **My Claim** I am seeking compensation of £[COMPENSATION AMOUNT SOUGHT (£)] in respect of the above damage. I reserve the right to revise this figure as further information comes to light. **What I Require** Within **21 days** of the date of this letter (by [RESPONSE DEADLINE (21 DAYS FROM TODAY)]) please: 1. Confirm whether you accept liability for the Breach and the damage I have suffered. 2. Provide details of your insurer and/or the individual or team authorised to deal with this claim. 3. Provide copies of any incident reports, breach notifications to the ICO, or other internal documents relating to the Breach. 4. Set out your proposals for resolving this matter. **If You Do Not Respond** If I do not receive a satisfactory response by [RESPONSE DEADLINE (21 DAYS FROM TODAY)], I will issue a claim in the County Court (or, if appropriate, the High Court) for compensation under Article 82 UK GDPR without further notice. I have also reported / reserve the right to report this matter to the Information Commissioner's Office. Yours faithfully, [YOUR FULL NAME]
Unfilled fields appear as [FIELD NAME]. Review the letter carefully before sending. This template is a starting point — adapt it to your specific circumstances.