Pre-Action Protocol Letter — Data Breach Compensation Claim
Formal letter before action for a compensation claim following a personal data breach under UK GDPR Article 82 and the Data Protection Act 2018.
This template was not drafted by a solicitor.
It is an editorial reference based on the official sources we cite. You are responsible for any document you send. For high-stakes matters (court proceedings, large sums, deportation, criminal allegations, child welfare), have a regulated solicitor review or draft your document.
When to use this template
Use this letter when an organisation has suffered a data breach involving your personal data and you have suffered material or non-material damage as a result — including distress, financial loss, or loss of control over your personal information. Send this letter before issuing county court proceedings to comply with Practice Direction — Pre-Action Conduct.
When NOT to use this template
Do not send this letter purely to obtain a response about the breach — use a DSAR instead. If your primary goal is to make the organisation improve its security rather than claim compensation, consider a complaint to the ICO first. This letter is not a substitute for reporting the breach to the ICO if you believe it was a serious violation.
Legal Basis
UK GDPR Article 82 (right to compensation for material or non-material damage caused by an infringement); Data Protection Act 2018 s.168 (right to compensation); UK GDPR Articles 5, 32 (security obligations). Confirmed in Vidal-Hall v Google Inc [2015] EWCA Civ 311 that non-material damage (including distress) is compensable.
Before you send
- Failing to identify the specific infringement — courts require you to show the organisation breached a specific UK GDPR provision, not merely that a breach occurred
- Not quantifying non-material damage — describe the distress in concrete terms (sleep disruption, anxiety, professional embarrassment)
- Overlooking the need to show causation — you must demonstrate the damage flowed from the breach
Common Mistakes to Avoid
- ✗Failing to identify the specific infringement — courts require you to show the organisation breached a specific UK GDPR provision, not merely that a breach occurred
- ✗Not quantifying non-material damage — describe the distress in concrete terms (sleep disruption, anxiety, professional embarrassment)
- ✗Overlooking the need to show causation — you must demonstrate the damage flowed from the breach
- ✗Sending the letter to a generic enquiries address rather than the Data Protection Officer
- ✗Issuing proceedings while the ICO is still investigating — not prohibited, but courts may stay proceedings
Build Your Letter
Fill in your details
Complete the fields below. Required fields are marked with *.
Optional fields
Letter preview
[YOUR FULL NAME] [YOUR ADDRESS] [YOUR EMAIL ADDRESS] [DATE OF LETTER] Data Protection Officer [ORGANISATION NAME] [ORGANISATION ADDRESS] --- Dear Sir or Madam, **LETTER BEFORE ACTION — COMPENSATION CLAIM FOR DATA BREACH** **UK GDPR Article 82 / Data Protection Act 2018 s.168** I write in accordance with Practice Direction — Pre-Action Conduct and Protocols of the Civil Procedure Rules 1998 to give you formal notice of my intention to issue proceedings for compensation arising from a personal data breach. **The Breach** On or around [DATE BREACH OCCURRED OR WAS NOTIFIED] you notified me / I became aware that [DESCRIPTION OF THE BREACH] (the "Breach"). The Breach involved the following categories of my personal data: [CATEGORIES OF PERSONAL DATA AFFECTED]. **The Infringement** The Breach constitutes an infringement of the UK General Data Protection Regulation in one or more of the following respects: - Failure to implement appropriate technical and organisational measures to ensure security appropriate to the risk, contrary to UK GDPR Article 5(1)(f) and Article 32; - [ANY ADDITIONAL UK GDPR INFRINGEMENTS]. **The Damage I Have Suffered** As a direct result of the Breach I have suffered the following damage: *Material damage:* [MATERIAL (FINANCIAL) DAMAGE SUFFERED] *Non-material damage:* [NON-MATERIAL DAMAGE (DISTRESS)] **My Claim** I am seeking compensation of £[COMPENSATION AMOUNT SOUGHT (£)] in respect of the above damage. I reserve the right to revise this figure as further information comes to light. **What I Require** Within **21 days** of the date of this letter (by [RESPONSE DEADLINE (21 DAYS FROM TODAY)]) please: 1. Confirm whether you accept liability for the Breach and the damage I have suffered. 2. Provide details of your insurer and/or the individual or team authorised to deal with this claim. 3. Provide copies of any incident reports, breach notifications to the ICO, or other internal documents relating to the Breach. 4. Set out your proposals for resolving this matter. **If You Do Not Respond** If I do not receive a satisfactory response by [RESPONSE DEADLINE (21 DAYS FROM TODAY)], I will issue a claim in the County Court (or, if appropriate, the High Court) for compensation under Article 82 UK GDPR without further notice. I have also reported / reserve the right to report this matter to the Information Commissioner's Office. Yours faithfully, [YOUR FULL NAME]
Unfilled fields appear as [FIELD NAME]. Review the letter carefully before sending. This template is a starting point — adapt it to your specific circumstances.
Related Guides
Related Rights
Official Resources
Frequently asked questions
- When should I send a pre-action protocol letter for a data breach?
- This letter is used when you have suffered material or non-material damage, such as distress or financial loss, from a personal data breach. It serves as formal notice of your intention to sue under UK GDPR Article 82. Do not use it if you only want information about the breach; use a Data Subject Access Request for that. If your main goal is improving security, consider complaining to the ICO first.
- What specific details must I include to avoid my claim being rejected?
- You must identify the specific UK GDPR provision the organisation breached, such as failing to implement appropriate security measures under Articles 5(1)(f) and 32. You also need to demonstrate causation, proving the damage flowed directly from the breach. Additionally, you should describe non-material damage in concrete terms, such as sleep disruption or anxiety, rather than leaving it unquantified.
- What response is required from the organisation after I send the letter?
- The letter requires the organisation to respond within 21 days. They must confirm whether they accept liability, provide details of their insurer or authorised team, supply copies of incident reports or ICO notifications, and set out proposals for resolving the matter. If you do not receive a satisfactory response by the deadline, you can issue proceedings in the County Court or High Court.
- Does sending this letter replace the need to report the breach to the ICO?
- Yes, the letter is not a substitute for reporting a serious violation to the Information Commissioner's Office (ICO). You should report the breach to the ICO if you believe it was serious. While issuing court proceedings while the ICO is investigating is not prohibited, courts may stay (pause) the proceedings during that time.
- Who should I address the letter to and when should it be sent?
- You should address the letter to the organisation's Data Protection Officer, not a generic enquiries address. The letter must be sent before issuing county court proceedings to comply with the Practice Direction on Pre-Action Conduct. It formally notifies the organisation of your intention to claim compensation under UK GDPR Article 82 and the Data Protection Act 2018.