Data Breach Complaint Letter Template & Generator
How to complain about a data breach and request information and remedy — how to structure it, your rights, and a free letter generator.
← All Letter Templates & Generators · Data Protection & GDPR · Last updated 18 August 2026 · Directed and published by Matt Thompson, founder of UK Work Rights
This is free rights guidance, not legal advice. For advice specific to your situation, see our About page or contact Citizens Advice.
If you need to complain about a data breach and request information and remedy, a written letter is the recommended first step — it creates a clear record and shows you're pursuing the matter formally. Below is what a strong data breach complaint letter should include, plus a free tool to generate yours.
What this letter needs to cover
- Describe what data was involved and how the breach occurred
- Request full details of the breach, what data was affected and what steps the organisation is taking
- Reference their obligation to report to ICO within 72 hours
- Request confirmation of steps taken to prevent recurrence
- Reserve right to claim compensation
Your rights after a data breach
If an organisation has experienced a data breach involving your personal information, the organisation must tell you directly and without undue delay if the breach is likely to result in a high risk to you (UK GDPR Article 34). You can also ask what happened, what data was affected and what it is doing about it, and you can make a subject access request for your own information.
What to include before you send it
- Reference to the breach, including how and when you became aware of it
- A request for full details — what data was involved, how the breach occurred, and what risk it poses to you
- What remedial steps you expect — this could include credit monitoring, an apology, or compensation if you've suffered genuine harm or distress
- A request for confirmation of what's being done to prevent a recurrence
When compensation may be appropriate
You may be entitled to compensation for a data breach if you've suffered genuine financial loss or significant distress as a result — this isn't automatic for every breach, but a serious breach involving sensitive information causing real anxiety or harm can support a claim, either directly against the organisation or, if unresolved, through the courts.
Frequently Asked Questions
Should I also report this to the ICO?
You can report a data breach to the Information Commissioner's Office if you're not satisfied with the organisation's response, particularly if they've failed to properly investigate or respond.
How long does an organisation have to respond to a breach complaint?
From 19 June 2026 every organisation must give you a way to make a data protection complaint to it, acknowledge your complaint within 30 days, look into it without undue delay, keep you informed and tell you the outcome. If it does not, you can complain to the ICO.
Ready to write yours?
Answer a few questions and get a professionally drafted letter, ready to send — free, no account needed.
✉️ Generate This Letter Free →Comments
Comments are loading…