Data Protection — No Win No Fee
Data protection claims under the UK GDPR and Data Protection Act 2018 can be pursued on a no win no fee basis. Following Vidal-Hall v Google [2015], compensation is available for distress alone — without the need to prove financial loss.
What Are the UK GDPR and Data Protection Act 2018?
Direct Answer: The UK GDPR and DPA 2018 give individuals the right to claim compensation for data breaches causing material damage or distress. Claims can be brought on a no win no fee CFA basis. Since Vidal-Hall v Google, damages for distress alone (without financial loss) are recoverable.
The UK General Data Protection Regulation (UK GDPR) — the retained EU version of the GDPR — and the Data Protection Act 2018 form the UK's data protection framework. Article 82 of the UK GDPR provides that any person who has suffered material or non-material damage as a result of an infringement has the right to receive compensation from the controller or processor.
What Are Common Data Protection Claims?
- Data breaches — cyberattacks, hacking, accidental data exposure
- Unlawful data sharing — sharing personal data without consent or lawful basis
- Subject access request failures — failure to respond to SARs within the statutory timeframe
- Inaccurate data — failure to correct or erase inaccurate personal data
- Excessive data collection — collecting data beyond what is necessary
- Unsolicited marketing — breaches of PECR (Privacy and Electronic Communications Regulations)
What Role Does the ICO Play?
The Information Commissioner's Office (ICO) is the UK's independent supervisory authority for data protection. The ICO can investigate complaints, issue enforcement notices, and impose fines of up to £17.5 million or 4% of annual global turnover. However, the ICO cannot award compensation to individuals — this requires separate court proceedings.
Group Litigation
Large-scale data breaches affecting thousands or millions of people are increasingly pursued through group litigation orders (GLOs) or representative actions. Notable examples include claims arising from the British Airways data breach (2018), the Marriott Hotels breach, and various NHS data incidents.
Frequently Asked Questions
You May Also Be Interested In
Where this applies: This page covers England and Wales. The rules in Scotland and Northern Ireland are different.
Sources for this page
Every rule stated above is based on the primary sources below. Each link goes to the legislation, court rule or regulator itself so you can check it. Last verified 2 August 2026.
- Courts and Legal Services Act 1990, s.58 (conditional fee agreements)
The provision that makes CFAs lawful and enforceable. CFAs derive from this section, not from LASPO.
- Conditional Fee Agreements Order 2013, arts. 4–5 · in force from 1 April 2013
Art. 4 caps the success fee at 100% of base costs. Art. 5 caps what may be taken from damages in personal injury at 25% of PSLA plus past pecuniary loss, net of CRU, at first instance.
- Civil Procedure Rules, Part 44 (incl. rr.44.13–44.17, QOCS)
Qualified one-way costs shifting and its exceptions. Rule 44.14 was amended with effect from 6 April 2023.
Who wrote and checked this page
- Written and published by
- Edward & Amaury Solicitors (Edward & Amaury Ltd, company no. 12195443), regulated by the Solicitors Regulation Authority under no. 800525.
- Legal review
- Checked for England & Wales by Edward & Amaury Solicitors — Solicitors regulated by the SRA (no. 800525) (verify on the regulator’s register).Review is recorded against the firm. The individual reviewer is not named on this page.
- Review dates
- Last reviewed 2 August 2026. Next review due 2 February 2027.
Fee rules change. California’s medical malpractice fee limits changed on 1 January 2023, and the QOCS rules in England and Wales changed on 6 April 2023. If you spot something out of date, tell us — we publish corrections.