Skip to content

ICO Data Breach Complaints vs PECR Cookie Consent Complaints

The Information Commissioner's Office handles two quite different kinds of digital privacy complaint. One concerns your personal data being lost, exposed or mishandled, which falls under UK GDPR and the Data Protection Act. The other concerns cookies, tracking and unwanted marketing, which falls under the Privacy and Electronic Communications Regulations. Different laws, different enforcement powers, and different practical options for you as an individual. This comparison sets out which stream your complaint belongs in and what each can realistically achieve.

Tip: scroll the table sideways to see all columns →

FeatureData Breach Complaint (UK GDPR)Cookie Consent Complaint (PECR)
Governing legislationUK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018Privacy and Electronic Communications Regulations 2003 (PECR), implementing the EU ePrivacy Directive
Who can complainAny individual whose personal data has been processed unlawfully, lost, or disclosed without authorisationAny person who has received unsolicited direct marketing or been subjected to unlawful cookie tracking — including businesses
Time limit to complain to ICONo strict statutory deadline, but ICO guidance suggests complaining within 3 months of the organisation's final response to youNo strict statutory deadline; ICO typically expects complaint within 3 months of awareness; older complaints may receive lower priority
Evidence requiredEvidence of the breach (notification letter, email, press report) and your link to the breached organisation; DSAR response usefulScreenshots of cookie banners or pop-ups, copies of marketing emails with full headers, evidence that consent was not validly given or that opt-out was ignored
ICO enforcement powersReprimand, enforcement notice requiring remediation, assessment notices, and fines up to £17.5 million or 4% of global turnover (whichever is higher)Enforcement notice, monetary penalty up to £500,000 (increasing to UK GDPR levels for the most serious breaches under proposed reforms)
Maximum fines availableUp to £17.5 million or 4% of annual global turnover under UK GDPR for the most serious infringementsUp to £500,000 under current PECR (proposed reform will align with UK GDPR fines in future)
Escalation route if ICO does not actJudicial review of the ICO's decision; or civil claim against the data controller directly under s.169 DPA 2018Judicial review of the ICO's decision; civil claims under PECR Regulation 30 for damages where individual harm caused
Civil claim possibilityYes — individual can bring a court claim for material or non-material damage (including distress) against the data controller under UK GDPR Article 82Yes — Regulation 30 PECR allows individuals to claim compensation in court for damage caused by a PECR breach, but must show actual damage
Retention of ICO recordsICO keeps records of formal complaints and investigations; can inform future enforcement prioritiesICO publishes PECR enforcement actions; records used to build pattern evidence for enforcement against repeat offenders
Sector regulator involvementFinancial services data breaches may also involve FCA; healthcare breaches may involve CQC; media breaches may involve OfcomOfcom handles certain electronic communications matters; FCA handles unsolicited financial promotions; ICO handles all PECR cookie complaints

The ICO cannot award compensation directly to individuals — it can only fine and require remediation. To recover compensation, you must bring a civil claim in court. The ICO decision on your complaint can help evidence a civil claim. Always raise a complaint with the organisation first and allow them 4 weeks to respond before escalating to the ICO.

Which stream does your complaint belong in?

Ask what actually went wrong. If your personal data was lost, sent to the wrong person, left exposed, kept too long, or used for something you never agreed to, that is a data protection matter. If the issue is a website dropping tracking cookies before you consented, a consent banner with no genuine reject option, or marketing emails and calls you never asked for, that falls under the electronic communications rules instead. Some incidents involve both.

  • Data lost or misused? Complain to the organisation first, then to the regulator if the response is inadequate.
  • Cookies or unwanted marketing? The same first step applies, but the practical outcome is usually enforcement against the organisation rather than anything specific for you.
  • Want compensation? Neither stream provides it. The regulator can investigate, require changes and fine — a civil claim in court is the only route to damages.

The mistake people make is expecting a personal remedy from a regulator. Its job is compliance across the board, not your individual redress, and a finding in your favour will not by itself put money in your pocket — though it is useful evidence if you later bring a claim.

Complain to the organisation first and give it the time the process allows. Keep screenshots, emails and dates: with cookie and marketing complaints in particular, the evidence disappears once a website is updated.

Frequently asked questions

Can I get compensation for a data breach?
Not from the regulator, which has no power to award you money — any fine it imposes goes to public funds. Compensation requires a civil claim in court for material loss or distress, and you must show the breach caused you actual harm rather than merely occurring. A regulatory finding in your favour can support such a claim. Be cautious of firms advertising bulk data breach claims: courts have been unsympathetic to claims involving minimal or purely speculative harm.
What should I do first if my data has been exposed?
Contact the organisation and ask what happened, what data was involved and what it is doing about it — they must tell you where the breach is likely to result in a high risk to you. Then protect yourself practically: change passwords, enable two-factor authentication, watch bank statements, and consider a credit reference agency notice if financial details were involved. Keep a record of everything, including the time you spend and any losses. Escalate to the regulator if the response is inadequate.
How do I stop unwanted marketing calls and emails?
Use the unsubscribe link on emails and ask callers in writing to stop, then register with the Telephone Preference Service for live sales calls. Keep a log of dates, numbers and what was said, because that record is what makes a complaint actionable. If contact continues after you have objected, complain to the organisation and then to the regulator, which does take enforcement action against persistent offenders. Report suspected scam calls separately to Action Fraud.
What can I do if a website will not let me reject cookies?
Non-essential cookies require consent that is as easy to refuse as to give, so a banner offering "accept all" with no equivalent reject option is a problem. Screenshot the banner and any settings panel, because sites change. Complain to the operator first, giving it a chance to fix things, then report it to the regulator with your evidence. Do not expect a personal outcome — reports of this kind feed enforcement work, and the practical result is usually a changed banner rather than anything for you.

Related guides

Data Breach Compensation and ICO Complaints

This guide is about redress: getting the Information Commissioner's Office to act on a data breach, and recovering compensation from the organisation responsible. It covers what the ICO will and will not do, the evidence that decides a compensation claim, and how group actions work. If you have only just found out about a breach and want to know whether you should have been told and what to do first, start with <a href="/digital-rights/data-breach-rights">when a company has a data breach</a>.

8 min

When a Company Has a Data Breach: Notification and Next Steps

A personal data breach occurs when an organisation accidentally or unlawfully destroys, loses, alters, discloses, or gives access to your personal data without authorisation. This guide covers the organisation's duty to tell you and to tell the regulator, and what you should do in the days afterwards to limit the damage. If you have already decided you want to complain to the ICO or claim compensation, go straight to <a href="/complaints-ombudsmen/data-breach-complaints">data breach compensation and ICO complaints</a>.

6 min

Cookie Consent and PECR: Your Digital Privacy Rights

Cookie banners, marketing emails, and tracking technologies are governed by the Privacy and Electronic Communications Regulations 2003 (PECR) alongside UK GDPR. Understanding your rights — and the obligations on organisations — helps you push back when consent is manufactured rather than freely given.

6 min

Complaining to the Information Commissioner about a Data Breach

The Information Commissioner's Office (ICO) regulates data protection in the UK. They handle complaints about misuse of personal data, failure to respond to Subject Access Requests, marketing breaches under PECR, and breaches of UK GDPR. Many complaints are resolved with a written reminder to the organisation; serious breaches lead to fines up to £17.5 million. This guide explains how to use the ICO and how to claim separately for compensation.

10 min

UK GDPR Rights for Individuals

The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018) give individuals in the UK eight legally enforceable rights over how organisations collect, store, and use their personal data. These rights apply whether the data is held by a business, public body, or online platform.

6 min

Disclaimer

The information on this page was correct at the time of writing. Amounts, thresholds, and rules may change. Always check the latest official guidance.