Skip to content

Complaining to the Information Commissioner about a Data Breach

ComplaintsUK-wideReviewed by Civil Help editorial team: 11 August 2026Next review: 13 May 202710 min
Verified against 4 sources

The Information Commissioner's Office (ICO) regulates data protection in the UK. They handle complaints about misuse of personal data, failure to respond to Subject Access Requests, marketing breaches under PECR, and breaches of UK GDPR. Many complaints are resolved with a written reminder to the organisation; serious breaches lead to fines up to £17.5 million. This guide explains how to use the ICO and how to claim separately for compensation.

Key points

  • The ICO enforces UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and Freedom of Information.
  • Complaints to the ICO are free. Submit at ico.org.uk/make-a-complaint.
  • The ICO can: investigate and warn, issue enforcement notices, impose monetary penalties (up to £17.5 million or 4% of global turnover under UK GDPR), and prosecute serious offences.
  • Most complaints are resolved with a written warning to the organisation. Fines are rare — usually for serious or repeated breaches.
  • The ICO cannot award compensation to you directly. For compensation, you can claim in the County Court under Article 82 UK GDPR.
  • Compensation for non-material damage (distress) is available under Article 82, but it is assessed individually and courts have rejected claims for trivial breaches.
  • Time limit: complain to the ICO within 3 months of the organisation's last meaningful response; a civil claim runs for 6 years (5 in Scotland).

What the ICO can and cannot do

The ICO is the UK's independent regulator for data protection. Its main powers:

  • Investigate complaints about how organisations handle personal data.
  • Issue Information Notices requiring organisations to provide evidence.
  • Issue Enforcement Notices requiring organisations to change practices.
  • Issue Monetary Penalty Notices — fines up to £17.5 million or 4% of global turnover under UK GDPR (Art 83). Since 5 February 2026, PECR penalties were aligned with the UK GDPR level by the Data (Use and Access) Act 2025 (Sch 13), replacing the old £500,000 cap.
  • Prosecute some criminal offences — unauthorised obtaining or disclosure of personal data (section 170 DPA 2018), forced SARs (section 184), and obstruction.
  • Audit public sector organisations and major data controllers.

What the ICO CANNOT do:

  • Order the organisation to pay you compensation. You must claim that separately in court.
  • Reverse the organisation's decision (e.g. compel them to give you a job after a SAR reveals discrimination — that is a different jurisdiction).
  • Investigate complaints that are about data that is not personal data (mostly trade or legal disputes).
  • Force organisations to keep specific data — they regulate processing, not retention strategy.

Common types of complaint

Most ICO complaints fall into one of these categories:

  • Failed Subject Access Request — you asked for your personal data and the organisation did not respond, responded late (more than 1 month), or refused unreasonably.
  • Data breach affecting you — your data was lost, stolen, or disclosed to someone who should not have had it.
  • Inaccurate data — incorrect information held about you, and the organisation refuses to correct it.
  • Unauthorised marketing — texts, calls, or emails after you opted out, or that you never consented to (PECR territory).
  • Excessive data collection — an organisation collecting more than necessary.
  • Refusal of erasure request — you asked for your data to be deleted ("right to be forgotten") and were refused.
  • FOI delays or refusals — public body did not provide information you requested under the Freedom of Information Act 2000.

Before complaining — try the organisation first

The ICO expects you to complain to the organisation first. This is sensible for two reasons:

  1. Most issues are resolved more quickly directly. Organisations are usually motivated to fix issues that could become ICO complaints.
  2. The ICO will often refuse to investigate cases where the organisation has not had a chance to respond.

How to complain to the organisation:

  • Find the Data Protection Officer (DPO) — usually listed on the organisation's privacy notice.
  • Submit a written complaint setting out the specific data protection issue and what you want done. Name the right, not just the grievance: access (Article 15), rectification (16), erasure (17), restriction (18), portability (20), or objection (21).
  • Allow at least 1 month for a substantive response. A Subject Access Request must be answered within one calendar month, extendable by up to two further months for complex or numerous requests — but only if the controller tells you within the first month.
  • If unsatisfied, request escalation through any internal review process.
  • Get a "final response" or "deadlock" letter — this is the trigger for ICO escalation.

Who can complain and by when. Anyone whose personal data is being processed — a "data subject" — can complain, including on behalf of a child or someone who lacks capacity, and you can authorise a representative in writing. Section 165 of the Data Protection Act 2018 gives you the right to complain to the Commissioner; there is no fee and no requirement to have suffered loss. The ICO expects the complaint within three months of the organisation's last meaningful response, and may decline to act on older complaints without a good reason for the delay. If the organisation simply never replies, count three months from your complaint and go anyway.

How to complain to the ICO

Submit at ico.org.uk/make-a-complaint. Include:

  • The organisation's name and address.
  • Your data protection issue, in concrete terms.
  • What you asked the organisation to do.
  • Their response (if any).
  • Copies of supporting evidence — emails, letters, screenshots, the original SAR.
  • What you want the ICO to do (investigate, warn the organisation, change practices).

Process:

  1. Acknowledgement within days.
  2. Case officer assigned within 1-3 months.
  3. Investigation — the case officer writes to the organisation, requests evidence, drafts an opinion.
  4. Outcome — usually a letter explaining what the ICO found and what they have asked the organisation to do.
  5. If serious, the case may be escalated to enforcement action (fines, regulatory orders).

Most complaints are resolved within 6 months. Complex investigations (especially involving large data sets or sectors) can take 12-18 months.

Claiming compensation in court (separately)

The ICO does not award you compensation. That is a separate court claim, and it is worth understanding how the two interact.

  • The right. Article 82 of the UK GDPR entitles a person who has suffered material damage (financial loss) or non-material damage (distress, anxiety) as a result of an infringement to compensation from the controller or processor. Section 168 of the Data Protection Act 2018 confirms that non-material damage includes distress.
  • Where. The County Court. Claims under £10,000 go on the small claims track, which limits your costs exposure; larger or more complex claims do not, and adverse costs become a real risk.
  • By when. Six years from the infringement in England and Wales (Limitation Act 1980), five years in Scotland.
  • Evidence. An ICO outcome that found an infringement is persuasive supporting material but is not binding on the court, and the court decides both breach and damage for itself. Medical evidence, or a contemporaneous record of the effect on you, does far more work than assertion.

Two limits people underestimate. First, the courts have made clear that trivial breaches do not sound in damages: a claim must clear a threshold of seriousness, and a one-off misdirected email causing brief annoyance has repeatedly been struck out or dismissed as trivial. Second, there is no US-style class action. The Supreme Court in Lloyd v Google [2021] UKSC 50 refused to allow a representative action for "loss of control" of data brought on behalf of millions of users without proof of individual damage, so each affected person must establish their own loss — whether individually or grouped under a Group Litigation Order.

Awards in ordinary cases tend to be modest, and legal costs can easily exceed them. Take advice on proportionality before issuing, and be sceptical of firms that advertise data-breach group claims on a no-win-no-fee basis without explaining the costs risk.

If the ICO Does Not Act, or the Outcome Goes Against You

The ICO receives far more complaints than it can investigate in depth, and the commonest outcome is a letter to the organisation setting out what it should do differently — not an enforcement notice and not a fine. Treat that as the expected result rather than a failure.

Ask for a case review. If the ICO closes your complaint and you think it misunderstood the facts or missed evidence, ask for the outcome to be reviewed, identifying the specific point rather than restating the complaint. Reviews turn on new material or a clear error.

Complain about the service. The ICO has its own service-complaints process for delay or poor handling, and beyond that the Parliamentary and Health Service Ombudsman can consider maladministration by the ICO — via your MP, and normally within 12 months.

Use the court routes the ICO cannot use for you. Section 167 of the Data Protection Act 2018 lets you apply to court for a compliance order requiring a controller to comply with a data subject request — this is the remedy when an organisation simply refuses to answer a SAR, and it does not depend on the ICO doing anything. Section 168 and Article 82 cover compensation. Both are available whether or not the ICO upheld your complaint.

Judicial review of an ICO decision is possible but narrow: illegality, irrationality, or procedural unfairness only, and within three months. Disagreeing with how the Commissioner exercised a regulatory discretion is generally not enough.

Check whether another route fits better. Credit file inaccuracies can also go to the lender and then the Financial Ombudsman Service; unwanted marketing calls can be reported alongside a PECR complaint; and where data was misused by an employer, the employment tribunal may be the more effective forum for the underlying detriment.

Frequently asked questions

How long does the ICO take to investigate?
Most complaints are resolved within 6 months. Complex cases involving large data sets, multiple parties, or significant public interest can take 12-18 months.
Will my name be public?
Generally no — the ICO redacts complainant details from published decisions. The organisation is named.
Can I get compensation through the ICO?
No. The ICO does not award compensation. For that, claim in the County Court under Article 82 UK GDPR within 6 years of the breach.
What if my data was leaked years ago and I just found out?
The time limit usually runs from discovery for fraud or concealment. For ICO complaints, raise it as soon as you become aware. For court claims, the 6-year limitation may be extended where the breach was concealed.
Can I take legal action AND complain to the ICO?
Yes — both routes can run in parallel. The ICO is the regulator (administrative remedy); the court provides civil compensation. Most lawyers will tell you to do both.

Official bodies and resources

Citizens Advice

Charity

Provides free, confidential, and independent advice on a wide range of issues including benefits, housing, debt, and employment.

Was this page helpful?

Disclaimer

This information is for general guidance only and does not constitute legal advice. You should seek qualified legal help if your situation requires it.