What can the ICO do about employee data breaches?
Your employer must answer for mishandling your data. The ICO can force changes and impose penalties, but it cannot award you compensation.
A care agency emails your home address to strangers. A warehouse manager shares your sick note in a staff chat. You need the leak stopped, an explanation and, if it has harmed you, a remedy. The Information Commissioner’s Office can make your employer change how it handles your data. It cannot award you compensation. Knowing which route does what saves you waiting for money the regulator cannot give you.
- 72 hrs
- qualifying breach reporting, where feasible, after employer awareness
- 30 days
- employer must acknowledge your data complaint
- £17.5m
- higher-tier maximum, or 4% of worldwide turnover if higher
- 3 mths
- ICO’s recommended complaint window after last meaningful contact
What counts as an employee data breach?
Your employer will usually be the “controller” of your staff records. That means it decides why and how to use them. You are the “data subject”. The UK GDPR and Data Protection Act 2018 protect your payroll details, contracts, absence records, disciplinary files, CCTV images, emails about you and right-to-work documents. There is no minimum employer size or qualifying service for these data rights.
A personal data breach is a security failure causing accidental or unlawful loss, destruction, alteration, disclosure of, or access to personal data. It need not be an innocent mistake. These are examples of situations worth raising, not reports of actual cases:
- A care agency emails carers’ home addresses and phone numbers to an unintended recipient.
- A warehouse supervisor shares your fit note in a WhatsApp group whose members have no need to see it.
- A cleaning firm loses a folder containing cleaners’ passport scans.
Unlawful monitoring or keeping data too long can also breach data protection law without being a security incident. You can complain about those practices too. A supermarket using fingerprint clock-ins must justify the processing. Calling the system convenient does not settle whether it is lawful.
Under Articles 33 and 34 of the UK GDPR, your employer must report a personal data breach to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it, unless a risk to people’s rights and freedoms is unlikely. If the risk to you is high, it must normally tell you without undue delay. The two tests are different. Not every incident has to be reported to the ICO or to you.
What the ICO can and cannot do
The ICO regulates the organisation. It does not act as your solicitor and it has no power to award compensation.
| Power | What it means for you |
|---|---|
| Information and assessment notices | Obtain information and inspect compliance, including relevant records and systems |
| Interview notices and technical reports | Compel interviews and require expert reports using powers in force since 5 February 2026 |
| Warnings and reprimands | Warn about likely infringements or formally rebuke an organisation for an infringement |
| Enforcement notices | Require the employer to stop unlawful processing or put things right |
| Penalty notices | Impose financial penalties on organisations, subject to the applicable legal maximum |
| Prosecution | Bring criminal proceedings for offences such as unlawful obtaining or disclosure of personal data |
An order stopping unlawful monitoring may matter more to your working day than a headline fine. Ask for the change you need. Neither an order nor a fine means money is paid to you. Compensation for proven financial loss or distress is a separate matter under Article 82 of the UK GDPR and section 168 of the Data Protection Act 2018. Section 167 provides for court compliance orders.
When should you complain to the ICO?
Complain when your employer mishandles your data, ignores an access request or keeps using an unlawful monitoring system. You do not need to prove that the case deserves a fine. Start with the employer so it has a chance to put things right, then go to the ICO if its reply is inadequate or it does not respond.
Since 19 June 2026, section 164A of the Data Protection Act 2018 requires controllers to make it possible to complain, acknowledge receipt within 30 days, take appropriate steps without undue delay and tell you the outcome. Those steps include appropriate enquiries and progress updates. The 30 days are for acknowledgement, not a licence to leave the problem untouched or a fixed deadline for resolving every complaint.
The ICO asks you to complain within three months of your last meaningful contact with the organisation. Treat that as its recommended complaint window, not the time limit for a court claim. If the employer has gone silent, tell the ICO when you complained and when you followed up.
- Save what you can safely keep. Keep the message or screenshot showing what happened. Note the dates, who received your data and any effects, such as nuisance contacts, anxiety or money lost. Keep your own evidence somewhere you can access if your work account is closed. Do not copy whole staff databases or other people’s records.
- Send a written data complaint. Use the employer’s privacy contact, data protection officer or complaints address. Describe the incident and ask what was exposed, who received it, what steps have contained it and whether notification was required. Ask for a specific remedy, such as stopping unauthorised sharing. You do not need to identify the exact legal provision before complaining.
- Take an unresolved complaint to the ICO. Use the ICO complaint form. Attach your complaint, the reply or evidence of silence, and a short chronology. Explain any ongoing danger or sensitive information involved. The ICO helpline is 0303 123 1113.
- Protect the other deadlines. Speak to your union or an adviser about compensation and any retaliation. An employer complaint or ICO investigation is not a reason to put a court or tribunal claim on hold. Ask the adviser to work out the deadline for your claim and jurisdiction.
What happens after you complain?
The ICO assesses the complaint and decides how much investigation is appropriate. It may ask for more evidence, contact the organisation, give advice or take formal action. A complaint does not guarantee an investigation followed by a fine. You can see published action in the ICO’s enforcement register.
Its published service standards aim for acknowledgement within 14 days and an outcome in 90% of complaints within six months. Those are service targets, not guaranteed resolution dates or a promise that your employer will be sanctioned.
Example: a care worker’s rota leak
Lena’s manager emails a rota containing 40 carers’ home addresses and phone numbers to an unintended external recipient. The manager discovers it at 10am on Monday. If the risk to people’s rights is not unlikely, notification to the ICO is due without undue delay and, where feasible, no later than 10am on Thursday. The employer must assess separately whether the risk is high enough to require telling the carers directly.
Lena emails a complaint on Tuesday. The employer must acknowledge it within 30 days of receipt and respond without undue delay. After five weeks of silence despite a follow-up, she takes the evidence to the ICO. She asks the employer to contain the leak and improve email controls. If she has suffered distress or financial loss, she can seek advice on compensation without waiting for the ICO’s decision.
Fines, orders and personal accountability
There are two UK GDPR maximum fine levels. The standard maximum is £8.7 million or 2% of total worldwide annual turnover, whichever is higher. The higher maximum is £17.5 million or 4%, whichever is higher. Which level applies depends on the provision infringed. These are ceilings, not a price list for leaking a worker’s file.
Example: how the higher cap works
For an organisation with £80 million in worldwide annual turnover, 4% is £3.2 million. The higher-tier ceiling is therefore £17.5 million. At £800 million turnover, 4% is £32 million, so that is the ceiling. The actual fine depends on the facts and the ICO’s fining approach. A maximum figure tells you neither what it will impose nor whether it will fine at all.
Fines for worker surveillance are possible. In January 2024, the French regulator fined Amazon France Logistique €32 million over its monitoring of warehouse workers, including scanner activity. That is a French enforcement example, not a prediction of what the ICO will do in your case.
An individual who knowingly or recklessly obtains or discloses personal data without the controller’s consent can commit an offence under section 170 of the Data Protection Act 2018, subject to statutory exceptions and defences. This can cover snooping or leaking records. Under section 196, the offence is punishable by a fine, not imprisonment. The employer’s own data protection duties remain a separate question.
Will complaining get you compensation?
The ICO cannot award it. An employer can agree to pay compensation without a court case, but if payment is disputed you need a civil claim. A regulator’s finding may help as evidence; it is not an automatic damages award.
You can seek compensation for financial loss and for distress caused by an infringement. In Farley v Paymaster, trading as Equiniti, in August 2025, the Court of Appeal rejected a minimum seriousness threshold for data protection compensation. That does not make every leak payable. You still need to establish the infringement, damage and the link between them. Fear of misuse must be real and supported, not merely speculative.
The Supreme Court appeal on the compensation threshold remained pending as at 1 October 2026. A hearing was listed for 7 and 8 October, not a judgment. Do not treat the point as finally settled or rely on online promises of a standard payout.
In England and Wales, a claim may be brought in the county court; Scotland and Northern Ireland have their own court procedures. Get advice on the correct court, limitation or prescription period, fees and possible costs before issuing. Do not assume a modest claim will automatically go through a cheap small-claims process. Your union’s legal service, Citizens Advice or a law centre may be able to help.
If you are punished for raising it
A data complaint is not automatically protected whistleblowing. In Great Britain, you must reasonably believe that the information you disclose shows a relevant wrongdoing, such as a breach of a legal obligation, and that disclosure is in the public interest. A leak affecting a whole team can raise that issue. A purely personal grievance does not automatically qualify. GOV.UK explains the conditions; get advice on the content of your disclosure and who you make it to.
Workers can have protection against whistleblowing detriment, such as losing shifts. Employees dismissed because of a protected disclosure can claim automatic unfair dismissal without the ordinary two-year qualifying service requirement. That exception already exists under section 108 of the Employment Rights Act 1996. You do not have to wait for a future unfair dismissal reform.
Great Britain tribunal time limits changed on 1 October 2026. For most claims concerning events on or after that date, the usual limit is six months less a day. For most earlier events it remains three months less a day. Notify Acas within the applicable limit; early conciliation can pause the clock. Neither a grievance nor an ICO complaint does. Dates spanning the change need individual advice.
If you have been dismissed for whistleblowing, get advice immediately about interim relief. The application deadline is only seven days. Do not wait for an employer reply, an ICO outcome or an ordinary conciliation timetable.
Ask a union representative to help you raise the concern and keep a record of any threats or rota cuts. UNISON covers many care and NHS support jobs, Usdaw retail, Unite and GMB many warehouse and factory jobs, and IWGB parts of gig and cleaning work. If you are not a member, ask about help before assuming a union will fund a case that began before you joined. Acas, Citizens Advice, law centres and the whistleblowing charity Protect are other advice routes.
Agency, migrant and gig workers
Data rights do not depend on being an employee. Workers, agency temps and genuinely self-employed contractors can request their personal data and complain about its handling. What differs is who holds the records and which employment protections apply.
An agency and a hirer may each be controllers for different records. The agency might hold your payroll and passport scan; the warehouse might run CCTV. Explain which organisation did what, rather than assuming only the one paying you can answer. A self-employed courier can complain about a platform’s use of their personal data even if employment status is disputed.
If your visa is tied to the employer and you fear retaliation, seek advice from a union or an adviser who understands both employment and immigration law. Keep lawful copies of your own correspondence outside the work account. Do not assume an ICO complaint will protect your job or immigration position.
The ICO route and data protection framework apply across the UK. Northern Ireland employment claims use its separate tribunal system and the Labour Relations Agency, not Acas. The Great Britain six-month tribunal rule above must not be assumed to apply there. Ask for local advice on the deadline and conciliation requirements.
What changed in 2026?
- New ICO powers in force
The Data (Use and Access) Act commencement brought powers to compel interviews and require technical reports. The maximum PECR penalty for matters such as unlawful marketing rose from £500,000 to £17.5 million or 4% of global turnover. That is a separate regime from an ordinary staff-data breach.
- Controller complaints duty in force
Controllers must facilitate data complaints, acknowledge receipt within 30 days and respond without undue delay. Acknowledgement is not the same as resolution.
- Longer Great Britain tribunal limits in force
Most claims arising on or after this date have six months less a day, subject to the applicable rules. Earlier events usually retain their shorter limit. This affects employment claims linked to a breach, not the ICO’s complaint window.
Questions people ask
Does my employer have to tell me about a breach?
Normally, if the breach is likely to create a high risk to your rights and freedoms, it must tell you without undue delay. The duty has exceptions, for example where effective protection makes the data unintelligible to unauthorised people. Reporting to the ICO uses a different risk test. Ask the employer to explain its assessment.
How long does the ICO take?
Its published targets are acknowledgement within 14 days and an outcome in 90% of complaints within six months. An outcome can be advice rather than enforcement. Do not wait for it before getting advice on a court claim or job-related deadline.
Can the ICO order an employer to answer an access request or stop monitoring?
It has enforcement powers to require compliance. Whether it uses them depends on the facts. Identify the information you have not received or the monitoring you want stopped, and attach the employer’s response.
Can a colleague who snooped on my records be prosecuted?
Yes, if the facts meet a criminal offence such as section 170 and no exception or defence applies. The ICO can investigate and prosecute. Section 170 carries a fine, not a prison sentence. An accidental mistake does not automatically establish that offence.
Do you need an ICO decision before claiming compensation?
No. The compensation route is separate. An ICO finding may be useful evidence, but you still need to prove your civil claim. Get advice about the legal basis, deadline and costs before starting it.
Sources
- Data Protection Act 2018, legislation.gov.uk, including sections 167, 168 and 170
- Section 164A: complaints to controllers, legislation.gov.uk, in force from 19 June 2026
- Section 196: penalties for offences, legislation.gov.uk
- Statement on Data (Use and Access) Act commencement, ICO, 5 February 2026
- Personal data breaches: a guide, ICO, including UK GDPR Articles 33 and 34
- Responding to subject access requests, ICO
- Complaining after an inadequate response, ICO, including the three-month recommendation and limits on its role
- Data protection complaint form, ICO
- Maximum fine under UK GDPR and DPA 2018, ICO
- Service standards, ICO
- Annual report 2024/25, ICO, complaint volumes
- Response on changes to complaint handling, ICO
- Published enforcement action, ICO
- Orders stopping Serco Leisure’s biometric attendance monitoring, ICO, February 2024
- Farley v Paymaster [2025] EWCA Civ 1117, Court of Appeal, 22 August 2025, via BAILII
- Farley v Paymaster appeal, UKSC/2025/0185, Supreme Court, hearing listed for 7 and 8 October 2026
- Amazon France Logistique €32 million monitoring fine, EDPB/CNIL, January 2024
- Whistleblowing eligibility and public-interest conditions, GOV.UK
- Employment Rights Act 1996, section 43B, legislation.gov.uk
- Section 108: exceptions to qualifying service, legislation.gov.uk, including protected-disclosure dismissal
- Section 111: unfair dismissal time limits, legislation.gov.uk, amended from 1 October 2026
- Employment tribunal time limits, Acas, updated 1 October 2026, including transitional dates, conciliation and seven-day interim relief deadline