Complaining to the Information Commissioner about a Data Breach
The Information Commissioner's Office (ICO) regulates data protection in the UK. They handle complaints about misuse of personal data, failure to respond to Subject Access Requests, marketing breaches under PECR, and breaches of UK GDPR. Many complaints are resolved with a written reminder to the organisation; serious breaches lead to fines up to £17.5 million. This guide explains how to use the ICO and how to claim separately for compensation.
Key points
- The ICO enforces UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and Freedom of Information.
- Complaints to the ICO are free. Submit at ico.org.uk/make-a-complaint.
- The ICO can: investigate and warn, issue enforcement notices, impose monetary penalties (up to £17.5 million or 4% of global turnover under UK GDPR), and prosecute serious offences.
- Most complaints are resolved with a written warning to the organisation. Fines are rare — usually for serious or repeated breaches.
- The ICO cannot award compensation to you directly. For compensation, you can claim in the County Court under Article 82 UK GDPR.
- Compensation for non-material damage (distress) is available under Article 82, but it is assessed individually and courts have rejected claims for trivial breaches.
- Time limit: complain to the ICO within 3 months of the organisation's last meaningful response; a civil claim runs for 6 years (5 in Scotland).
What the ICO can and cannot do
The ICO is the UK's independent regulator for data protection. Its main powers:
- Investigate complaints about how organisations handle personal data.
- Issue Information Notices requiring organisations to provide evidence.
- Issue Enforcement Notices requiring organisations to change practices.
- Issue Monetary Penalty Notices — fines up to £17.5 million or 4% of global turnover under UK GDPR (Art 83). Since 5 February 2026, PECR penalties were aligned with the UK GDPR level by the Data (Use and Access) Act 2025 (Sch 13), replacing the old £500,000 cap.
- Prosecute some criminal offences — unauthorised obtaining or disclosure of personal data (section 170 DPA 2018), forced SARs (section 184), and obstruction.
- Audit public sector organisations and major data controllers.
What the ICO CANNOT do:
- Order the organisation to pay you compensation. You must claim that separately in court.
- Reverse the organisation's decision (e.g. compel them to give you a job after a SAR reveals discrimination — that is a different jurisdiction).
- Investigate complaints that are about data that is not personal data (mostly trade or legal disputes).
- Force organisations to keep specific data — they regulate processing, not retention strategy.
Common types of complaint
Most ICO complaints fall into one of these categories:
- Failed Subject Access Request — you asked for your personal data and the organisation did not respond, responded late (more than 1 month), or refused unreasonably.
- Data breach affecting you — your data was lost, stolen, or disclosed to someone who should not have had it.
- Inaccurate data — incorrect information held about you, and the organisation refuses to correct it.
- Unauthorised marketing — texts, calls, or emails after you opted out, or that you never consented to (PECR territory).
- Excessive data collection — an organisation collecting more than necessary.
- Refusal of erasure request — you asked for your data to be deleted ("right to be forgotten") and were refused.
- FOI delays or refusals — public body did not provide information you requested under the Freedom of Information Act 2000.
Before complaining — try the organisation first
The ICO expects you to complain to the organisation first. This is sensible for two reasons:
- Most issues are resolved more quickly directly. Organisations are usually motivated to fix issues that could become ICO complaints.
- The ICO will often refuse to investigate cases where the organisation has not had a chance to respond.
How to complain to the organisation:
- Find the Data Protection Officer (DPO) — usually listed on the organisation's privacy notice.
- Submit a written complaint setting out the specific data protection issue and what you want done. Name the right, not just the grievance: access (Article 15), rectification (16), erasure (17), restriction (18), portability (20), or objection (21).
- Allow at least 1 month for a substantive response. A Subject Access Request must be answered within one calendar month, extendable by up to two further months for complex or numerous requests — but only if the controller tells you within the first month.
- If unsatisfied, request escalation through any internal review process.
- Get a "final response" or "deadlock" letter — this is the trigger for ICO escalation.
Who can complain and by when. Anyone whose personal data is being processed — a "data subject" — can complain, including on behalf of a child or someone who lacks capacity, and you can authorise a representative in writing. Section 165 of the Data Protection Act 2018 gives you the right to complain to the Commissioner; there is no fee and no requirement to have suffered loss. The ICO expects the complaint within three months of the organisation's last meaningful response, and may decline to act on older complaints without a good reason for the delay. If the organisation simply never replies, count three months from your complaint and go anyway.
How to complain to the ICO
Submit at ico.org.uk/make-a-complaint. Include:
- The organisation's name and address.
- Your data protection issue, in concrete terms.
- What you asked the organisation to do.
- Their response (if any).
- Copies of supporting evidence — emails, letters, screenshots, the original SAR.
- What you want the ICO to do (investigate, warn the organisation, change practices).
Process:
- Acknowledgement within days.
- Case officer assigned within 1-3 months.
- Investigation — the case officer writes to the organisation, requests evidence, drafts an opinion.
- Outcome — usually a letter explaining what the ICO found and what they have asked the organisation to do.
- If serious, the case may be escalated to enforcement action (fines, regulatory orders).
Most complaints are resolved within 6 months. Complex investigations (especially involving large data sets or sectors) can take 12-18 months.
Claiming compensation in court (separately)
The ICO does not award you compensation. That is a separate court claim, and it is worth understanding how the two interact.
- The right. Article 82 of the UK GDPR entitles a person who has suffered material damage (financial loss) or non-material damage (distress, anxiety) as a result of an infringement to compensation from the controller or processor. Section 168 of the Data Protection Act 2018 confirms that non-material damage includes distress.
- Where. The County Court. Claims under £10,000 go on the small claims track, which limits your costs exposure; larger or more complex claims do not, and adverse costs become a real risk.
- By when. Six years from the infringement in England and Wales (Limitation Act 1980), five years in Scotland.
- Evidence. An ICO outcome that found an infringement is persuasive supporting material but is not binding on the court, and the court decides both breach and damage for itself. Medical evidence, or a contemporaneous record of the effect on you, does far more work than assertion.
Two limits people underestimate. First, the courts have made clear that trivial breaches do not sound in damages: a claim must clear a threshold of seriousness, and a one-off misdirected email causing brief annoyance has repeatedly been struck out or dismissed as trivial. Second, there is no US-style class action. The Supreme Court in Lloyd v Google [2021] UKSC 50 refused to allow a representative action for "loss of control" of data brought on behalf of millions of users without proof of individual damage, so each affected person must establish their own loss — whether individually or grouped under a Group Litigation Order.
Awards in ordinary cases tend to be modest, and legal costs can easily exceed them. Take advice on proportionality before issuing, and be sceptical of firms that advertise data-breach group claims on a no-win-no-fee basis without explaining the costs risk.
If the ICO Does Not Act, or the Outcome Goes Against You
The ICO receives far more complaints than it can investigate in depth, and the commonest outcome is a letter to the organisation setting out what it should do differently — not an enforcement notice and not a fine. Treat that as the expected result rather than a failure.
Ask for a case review. If the ICO closes your complaint and you think it misunderstood the facts or missed evidence, ask for the outcome to be reviewed, identifying the specific point rather than restating the complaint. Reviews turn on new material or a clear error.
Complain about the service. The ICO has its own service-complaints process for delay or poor handling, and beyond that the Parliamentary and Health Service Ombudsman can consider maladministration by the ICO — via your MP, and normally within 12 months.
Use the court routes the ICO cannot use for you. Section 167 of the Data Protection Act 2018 lets you apply to court for a compliance order requiring a controller to comply with a data subject request — this is the remedy when an organisation simply refuses to answer a SAR, and it does not depend on the ICO doing anything. Section 168 and Article 82 cover compensation. Both are available whether or not the ICO upheld your complaint.
Judicial review of an ICO decision is possible but narrow: illegality, irrationality, or procedural unfairness only, and within three months. Disagreeing with how the Commissioner exercised a regulatory discretion is generally not enough.
Check whether another route fits better. Credit file inaccuracies can also go to the lender and then the Financial Ombudsman Service; unwanted marketing calls can be reported alongside a PECR complaint; and where data was misused by an employer, the employment tribunal may be the more effective forum for the underlying detriment.
Frequently asked questions
How long does the ICO take to investigate?
Will my name be public?
Can I get compensation through the ICO?
What if my data was leaked years ago and I just found out?
Can I take legal action AND complain to the ICO?
What to do next
- 1
- 2
- 3
- 4
Tools for this topic
Free interactive checks and calculators related to this guide.
- Which complaint route should I use?Wizard
- Complaint Route FinderTool
- Deadline CalculatorTool
- Complaint Letter GeneratorTool
- Find Your MP & CouncilTool
Related tools and templates
Compare your options, work through the steps, or send a letter.
Official bodies and resources
Citizens Advice
CharityProvides free, confidential, and independent advice on a wide range of issues including benefits, housing, debt, and employment.
Was this page helpful?
See also from across Civil Help
Data Subject Access Requests
A Subject Access Request (SAR) is a formal request you can make to any organisation asking them to provide a copy of all personal data they hold about you and information about how it is used. It is one of your most powerful rights under UK GDPR and is entirely free in most cases.
Digital6 min
Right to Erasure (Right to be Forgotten)
The right to erasure — sometimes called the "right to be forgotten" — allows you to request that an organisation delete your personal data in certain circumstances. It is one of eight rights under UK GDPR and can be a powerful tool for removing outdated, irrelevant, or unlawfully held data about you from online platforms and databases.
Digital6 min
Cookie Consent and PECR: Your Digital Privacy Rights
Cookie banners, marketing emails, and tracking technologies are governed by the Privacy and Electronic Communications Regulations 2003 (PECR) alongside UK GDPR. Understanding your rights — and the obligations on organisations — helps you push back when consent is manufactured rather than freely given.
Digital6 min
UK GDPR Rights for Individuals
The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018) give individuals in the UK eight legally enforceable rights over how organisations collect, store, and use their personal data. These rights apply whether the data is held by a business, public body, or online platform.
Digital6 min
Disclaimer