No Single Law — a Patchwork You Have to Navigate
There is no single comprehensive federal data-breach law in the US. Instead, all 50 states (plus DC and other territories) have their own breach-notification statutes, with different definitions of what counts as a breach and different notification deadlines. A growing number of states now use fixed day-counts rather than vague language: for example, California tightened its rule in 2025–2026 (SB 446) to a hard 30-calendar-day notification deadline from discovery, subject to law-enforcement delay; Florida also uses 30 days (with a possible 15-day extension for good cause); other states use 45 or 60 days. Many states still use qualitative language like "without unreasonable delay" instead of a fixed number. verify your specific state’s current deadline before relying on a number, since this changes often
The FTC can bring enforcement actions against companies for inadequate data security or broken privacy promises under its general Section 5 "unfair or deceptive practices" authority — this produces regulatory penalties and required changes to a company’s practices, not a personal payment to you. HIPAA (healthcare data) and the Gramm-Leach-Bliley Act (financial data) are sector-specific federal laws with no private right of action at all — your recourse for a HIPAA or GLBA breach is generally a regulatory complaint (to HHS Office for Civil Rights, within 180 days of discovery for HIPAA) or a separate state-law claim on the same facts, not a federal lawsuit under those statutes themselves.
California is a notable exception: the CCPA, as amended by the CPRA, gives consumers a limited private right of action specifically for breaches of nonencrypted, nonredacted personal information caused by a business’s failure to maintain reasonable security — allowing statutory damages of $100 to $750 per person per incident (or actual damages if higher), without needing to prove a specific dollar loss. The CPRA also eliminated the original 30-day pre-suit "cure" notice that used to let companies avoid liability by fixing the problem after the fact. Very few other state privacy laws include any comparable private right of action for a breach.
What You Can Realistically Recover
Amounts depend heavily on whether you can show actual, documented harm
California CCPA/CPRA statutory damages
For qualifying breaches of nonencrypted, nonredacted data caused by a business’s failure to maintain reasonable security: $100–$750 per person per incident, or actual damages if greater — no need to prove a specific dollar loss.
Class-action settlement — "no proof" tier
Commonly $25–$250 per person for simply being part of the affected class, without documenting a specific loss. [verify against the specific settlement’s claims administrator]
Class-action settlement — documented-loss tier
Can reach $500–$25,000 where you document actual identity theft, fraud-resolution time, or credit-monitoring costs tied to the specific breach — requires real paperwork, not just a claim of harm.
EU and UK: A Right to Compensation, But Not Automatic
Under GDPR, controllers must notify the relevant supervisory authority "without undue delay and, where feasible, not later than 72 hours" after becoming aware of a breach (Article 33), unless the breach is unlikely to risk individuals’ rights and freedoms. Individuals themselves only need to be notified (Article 34) where the breach is likely to result in a high risk to their rights and freedoms — there’s no fixed deadline for that individual notice, only "without undue delay."
Article 82 gives a right to compensation for material or non-material damage caused by a GDPR infringement, but the CJEU’s 2023 ruling in UI v Österreichische Post (Case C-300/21) clarified that mere infringement of the GDPR does not automatically entitle you to compensation — you must show an infringement, actual damage (which can include non-material harm like distress), and a causal link between them. The court also held there’s no minimum "seriousness" threshold once actual damage is shown, but the GDPR itself sets no rules for quantifying damages — national courts apply their own domestic law, so awarded amounts vary significantly by member state.
In the UK post-Brexit, UK GDPR plus the Data Protection Act 2018 (section 168) carry over the same 72-hour supervisory-notification structure and a parallel Article 82-style compensation right, explicitly including distress as non-material damage. Complaints go to the Information Commissioner’s Office (ICO), which targets resolving 90% of cases within six months — but the ICO itself cannot award you compensation; it only pursues regulatory enforcement. A compensation claim under Article 82/section 168 must be brought separately in court, generally within the ordinary 6-year civil limitation period under the Limitation Act 1980. verify current ICO service standards and limitation rules before relying on them
How to Pursue a Claim, Step by Step
The right route depends on your country and whether you can document actual harm
Save the breach notice and any follow-up communications
Keep the exact notification you received, including the date, what data categories were affected, and any remediation offered (credit monitoring, identity-theft protection).
Document any actual harm as it happens
Save records of unauthorized charges, new accounts opened in your name, time spent on fraud resolution, and any credit-monitoring or identity-protection costs you paid yourself — this evidence is what turns a "no proof" claim into a documented-loss claim.
US — check for a class action and file a claim form
Most individual recovery in the US comes through a class-action settlement rather than an individual lawsuit; watch for a settlement notice and file your claim form by its deadline, choosing the documented-loss tier if you have supporting records.
California — consider your CCPA/CPRA private right of action
If the breach involved unencrypted, unredacted personal data and a security failure by the business, you may have an individual statutory-damages claim, separate from any class action — get advice on whether this applies to your situation.
EU/UK — complain to your national DPA or the ICO, and separately consider a compensation claim
A DPA/ICO complaint can trigger regulatory enforcement against the company but does not itself pay you compensation. To seek money, you generally need a separate Article 82 (or section 168 DPA 2018) claim in court, backed by evidence of actual material or non-material harm.
Documents to gather
- The breach notification itself, with date and affected data categories
- Bank/credit card statements showing any unauthorized activity
- Records of time spent on fraud resolution or credit monitoring purchased
- Any correspondence with the company or a regulator about the breach
Timelines and Limitation Periods
Notification deadlines and your own claim deadline are two different things
The company’s deadline to notify you of a breach is separate from your own deadline to bring a claim — missing the company’s notification deadline doesn’t extend your own filing window, and vice versa.
| Jurisdiction | Limitation Period |
|---|---|
| US — company breach-notification deadline (varies by state) | Commonly 30, 45, or 60 days from discovery, or "without unreasonable delay" — check your specific state verify |
| US — individual claim statute of limitations | Governed by ordinary state tort/contract/statutory limitation periods, which vary by state and claim type verify per state |
| EU — GDPR supervisory-authority notification | 72 hours from the controller becoming aware of the breach (Article 33) |
| UK/EU — Article 82 compensation claim | Generally the ordinary national civil limitation period (UK: 6 years under the Limitation Act 1980) verify current rules in your country |
Realistic Outcomes and Caveats
Most people’s actual recovery comes from a class-action settlement or free credit monitoring, not an individual lawsuit — individual claims outside California’s CCPA statutory-damages provision are relatively rare and often not cost-effective without documented, significant harm.
Both US courts (in states without a specific statutory-damages provision) and EU/UK courts under Article 82 generally require you to show actual harm, not just that a breach occurred — a bare notification, without more, is unlikely to produce a payout on its own.
This page can help you understand your notification rights and possible claim routes, but it cannot predict a specific settlement amount or court outcome.
Common Pitfalls
Assuming a breach notice automatically means you’ll be compensated
Under both US state law (outside California’s CCPA private right of action) and GDPR/UK GDPR, you generally need to show actual harm, not just that a breach happened.
Not keeping records of actual harm
Documented-loss settlement tiers and stronger Article 82 claims both depend on having real evidence — save statements, fraud-resolution records, and receipts as they happen.
Confusing a regulator complaint with a compensation claim
An FTC, state AG, ICO, or EU DPA complaint can produce enforcement action against the company, but none of these bodies pays you directly — a separate compensation claim is usually required.
Missing your state’s specific notification-deadline nuance
Deadlines range from a hard 30 days in some states to vague "unreasonable delay" language in others — don’t assume one state’s rule applies to a breach involving a company based elsewhere.
Overestimating "no proof" settlement tiers
These commonly pay in the tens of dollars per person; larger recoveries generally require documented identity theft or financial loss.
Organize Your Data Breach Records
Use the calculator to document the breach notice, any harm you’ve experienced, and your correspondence with the company or a regulator.
Organize Your Data Breach Records
Use the calculator to document the breach notice, any harm you’ve experienced, and your correspondence with the company or a regulator.
This stays in your private workspace until you choose a next step. It does not submit a claim on your behalf on its own.
Official and Legal References
- Privacy Rights Clearinghouse — Data Breach Notification Laws, 50-State Survey
- California Civil Code § 1798.82
- FTC — Privacy and Security Enforcement
- HHS — Filing a HIPAA Complaint
- FTC — Gramm-Leach-Bliley Act
- GDPR Article 33 — Notification of a personal data breach
- GDPR Article 82 — Right to compensation
- CJEU Case C-300/21, UI v Österreichische Post — case summary
- ICO — Making a data protection complaint
US State Patchwork vs. EU/UK Single Compensation Right
The US has no comprehensive federal breach law — 50+ separate state statutes govern notification, and only California gives most consumers a real private right of action for breach-related damages, with fixed statutory-damages amounts. The EU and UK instead have a single, harmonized right to compensation under GDPR Article 82 (and the UK GDPR equivalent), but that right requires proof of actual material or non-material damage rather than offering fixed statutory amounts — meaning the practical value of a claim varies significantly by national court and case facts.
Frequently Asked Questions
Real edge cases, answered in plain language
I got a breach notice but nothing bad has happened yet — can I still get money?
Does filing an ICO or FTC complaint get me compensation?
What’s the difference between the "no proof" and "documented loss" settlement tiers?
Organize Your Data Breach Records
Use the calculator to document the breach notice, any harm you’ve experienced, and your correspondence with the company or a regulator.