ICO Data Breach Complaints vs PECR Cookie Consent Complaints
The Information Commissioner's Office handles two quite different kinds of digital privacy complaint. One concerns your personal data being lost, exposed or mishandled, which falls under UK GDPR and the Data Protection Act. The other concerns cookies, tracking and unwanted marketing, which falls under the Privacy and Electronic Communications Regulations. Different laws, different enforcement powers, and different practical options for you as an individual. This comparison sets out which stream your complaint belongs in and what each can realistically achieve.
Tip: scroll the table sideways to see all columns →
The ICO cannot award compensation directly to individuals — it can only fine and require remediation. To recover compensation, you must bring a civil claim in court. The ICO decision on your complaint can help evidence a civil claim. Always raise a complaint with the organisation first and allow them 4 weeks to respond before escalating to the ICO.
Which stream does your complaint belong in?
Ask what actually went wrong. If your personal data was lost, sent to the wrong person, left exposed, kept too long, or used for something you never agreed to, that is a data protection matter. If the issue is a website dropping tracking cookies before you consented, a consent banner with no genuine reject option, or marketing emails and calls you never asked for, that falls under the electronic communications rules instead. Some incidents involve both.
- Data lost or misused? Complain to the organisation first, then to the regulator if the response is inadequate.
- Cookies or unwanted marketing? The same first step applies, but the practical outcome is usually enforcement against the organisation rather than anything specific for you.
- Want compensation? Neither stream provides it. The regulator can investigate, require changes and fine — a civil claim in court is the only route to damages.
The mistake people make is expecting a personal remedy from a regulator. Its job is compliance across the board, not your individual redress, and a finding in your favour will not by itself put money in your pocket — though it is useful evidence if you later bring a claim.
Complain to the organisation first and give it the time the process allows. Keep screenshots, emails and dates: with cookie and marketing complaints in particular, the evidence disappears once a website is updated.
Frequently asked questions
Can I get compensation for a data breach?
What should I do first if my data has been exposed?
How do I stop unwanted marketing calls and emails?
What can I do if a website will not let me reject cookies?
Related guides
Data Breach Compensation and ICO Complaints
This guide is about redress: getting the Information Commissioner's Office to act on a data breach, and recovering compensation from the organisation responsible. It covers what the ICO will and will not do, the evidence that decides a compensation claim, and how group actions work. If you have only just found out about a breach and want to know whether you should have been told and what to do first, start with <a href="/digital-rights/data-breach-rights">when a company has a data breach</a>.
8 min
When a Company Has a Data Breach: Notification and Next Steps
A personal data breach occurs when an organisation accidentally or unlawfully destroys, loses, alters, discloses, or gives access to your personal data without authorisation. This guide covers the organisation's duty to tell you and to tell the regulator, and what you should do in the days afterwards to limit the damage. If you have already decided you want to complain to the ICO or claim compensation, go straight to <a href="/complaints-ombudsmen/data-breach-complaints">data breach compensation and ICO complaints</a>.
6 min
Cookie Consent and PECR: Your Digital Privacy Rights
Cookie banners, marketing emails, and tracking technologies are governed by the Privacy and Electronic Communications Regulations 2003 (PECR) alongside UK GDPR. Understanding your rights — and the obligations on organisations — helps you push back when consent is manufactured rather than freely given.
6 min
Complaining to the Information Commissioner about a Data Breach
The Information Commissioner's Office (ICO) regulates data protection in the UK. They handle complaints about misuse of personal data, failure to respond to Subject Access Requests, marketing breaches under PECR, and breaches of UK GDPR. Many complaints are resolved with a written reminder to the organisation; serious breaches lead to fines up to £17.5 million. This guide explains how to use the ICO and how to claim separately for compensation.
10 min
UK GDPR Rights for Individuals
The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018) give individuals in the UK eight legally enforceable rights over how organisations collect, store, and use their personal data. These rights apply whether the data is held by a business, public body, or online platform.
6 min
Disclaimer