Home/Digital Rights/Data Breach & Privacy Violation
Digital Rights

Data Breach and Privacy Violation: What You’re Actually Owed

A breach notice alone doesn’t automatically entitle you to compensation — in both the US and EU, you generally need to show actual harm, not just that your data was exposed. Here’s how notification law, private lawsuit rights, and realistic settlement amounts actually work.

At a Glance

50 states
Separate US breach-notification statutes — no single federal law
$100–$750
CCPA/CPRA statutory damages per person, per incident (California only)
72 hours
GDPR deadline to notify the supervisory authority of a breach
$25–$250
Typical "no-proof" class-settlement payout tier per person [verify per settlement]

No Single Law — a Patchwork You Have to Navigate

There is no single comprehensive federal data-breach law in the US. Instead, all 50 states (plus DC and other territories) have their own breach-notification statutes, with different definitions of what counts as a breach and different notification deadlines. A growing number of states now use fixed day-counts rather than vague language: for example, California tightened its rule in 2025–2026 (SB 446) to a hard 30-calendar-day notification deadline from discovery, subject to law-enforcement delay; Florida also uses 30 days (with a possible 15-day extension for good cause); other states use 45 or 60 days. Many states still use qualitative language like "without unreasonable delay" instead of a fixed number. verify your specific state’s current deadline before relying on a number, since this changes often

The FTC can bring enforcement actions against companies for inadequate data security or broken privacy promises under its general Section 5 "unfair or deceptive practices" authority — this produces regulatory penalties and required changes to a company’s practices, not a personal payment to you. HIPAA (healthcare data) and the Gramm-Leach-Bliley Act (financial data) are sector-specific federal laws with no private right of action at all — your recourse for a HIPAA or GLBA breach is generally a regulatory complaint (to HHS Office for Civil Rights, within 180 days of discovery for HIPAA) or a separate state-law claim on the same facts, not a federal lawsuit under those statutes themselves.

California is a notable exception: the CCPA, as amended by the CPRA, gives consumers a limited private right of action specifically for breaches of nonencrypted, nonredacted personal information caused by a business’s failure to maintain reasonable security — allowing statutory damages of $100 to $750 per person per incident (or actual damages if higher), without needing to prove a specific dollar loss. The CPRA also eliminated the original 30-day pre-suit "cure" notice that used to let companies avoid liability by fixing the problem after the fact. Very few other state privacy laws include any comparable private right of action for a breach.

What You Can Realistically Recover

Amounts depend heavily on whether you can show actual, documented harm

California CCPA/CPRA statutory damages

For qualifying breaches of nonencrypted, nonredacted data caused by a business’s failure to maintain reasonable security: $100–$750 per person per incident, or actual damages if greater — no need to prove a specific dollar loss.

Class-action settlement — "no proof" tier

Commonly $25–$250 per person for simply being part of the affected class, without documenting a specific loss. [verify against the specific settlement’s claims administrator]

Class-action settlement — documented-loss tier

Can reach $500–$25,000 where you document actual identity theft, fraud-resolution time, or credit-monitoring costs tied to the specific breach — requires real paperwork, not just a claim of harm.

A GDPR/UK GDPR claim requires proof of actual damage: Following UI v Österreichische Post, EU and UK courts will not award Article 82 compensation for the mere fact that your data was breached — you need to show material loss or genuine non-material harm (distress, anxiety) and a causal link to the specific infringement. verify current national-court quantification practice in your country, since amounts vary significantly by member state

EU and UK: A Right to Compensation, But Not Automatic

Under GDPR, controllers must notify the relevant supervisory authority "without undue delay and, where feasible, not later than 72 hours" after becoming aware of a breach (Article 33), unless the breach is unlikely to risk individuals’ rights and freedoms. Individuals themselves only need to be notified (Article 34) where the breach is likely to result in a high risk to their rights and freedoms — there’s no fixed deadline for that individual notice, only "without undue delay."

Article 82 gives a right to compensation for material or non-material damage caused by a GDPR infringement, but the CJEU’s 2023 ruling in UI v Österreichische Post (Case C-300/21) clarified that mere infringement of the GDPR does not automatically entitle you to compensation — you must show an infringement, actual damage (which can include non-material harm like distress), and a causal link between them. The court also held there’s no minimum "seriousness" threshold once actual damage is shown, but the GDPR itself sets no rules for quantifying damages — national courts apply their own domestic law, so awarded amounts vary significantly by member state.

In the UK post-Brexit, UK GDPR plus the Data Protection Act 2018 (section 168) carry over the same 72-hour supervisory-notification structure and a parallel Article 82-style compensation right, explicitly including distress as non-material damage. Complaints go to the Information Commissioner’s Office (ICO), which targets resolving 90% of cases within six months — but the ICO itself cannot award you compensation; it only pursues regulatory enforcement. A compensation claim under Article 82/section 168 must be brought separately in court, generally within the ordinary 6-year civil limitation period under the Limitation Act 1980. verify current ICO service standards and limitation rules before relying on them

How to Pursue a Claim, Step by Step

The right route depends on your country and whether you can document actual harm

1

Save the breach notice and any follow-up communications

Keep the exact notification you received, including the date, what data categories were affected, and any remediation offered (credit monitoring, identity-theft protection).

2

Document any actual harm as it happens

Save records of unauthorized charges, new accounts opened in your name, time spent on fraud resolution, and any credit-monitoring or identity-protection costs you paid yourself — this evidence is what turns a "no proof" claim into a documented-loss claim.

3

US — check for a class action and file a claim form

Most individual recovery in the US comes through a class-action settlement rather than an individual lawsuit; watch for a settlement notice and file your claim form by its deadline, choosing the documented-loss tier if you have supporting records.

4

California — consider your CCPA/CPRA private right of action

If the breach involved unencrypted, unredacted personal data and a security failure by the business, you may have an individual statutory-damages claim, separate from any class action — get advice on whether this applies to your situation.

5

EU/UK — complain to your national DPA or the ICO, and separately consider a compensation claim

A DPA/ICO complaint can trigger regulatory enforcement against the company but does not itself pay you compensation. To seek money, you generally need a separate Article 82 (or section 168 DPA 2018) claim in court, backed by evidence of actual material or non-material harm.

Documents to gather

  • The breach notification itself, with date and affected data categories
  • Bank/credit card statements showing any unauthorized activity
  • Records of time spent on fraud resolution or credit monitoring purchased
  • Any correspondence with the company or a regulator about the breach

Timelines and Limitation Periods

Notification deadlines and your own claim deadline are two different things

The company’s deadline to notify you of a breach is separate from your own deadline to bring a claim — missing the company’s notification deadline doesn’t extend your own filing window, and vice versa.

JurisdictionLimitation Period
US — company breach-notification deadline (varies by state)Commonly 30, 45, or 60 days from discovery, or "without unreasonable delay" — check your specific state verify
US — individual claim statute of limitationsGoverned by ordinary state tort/contract/statutory limitation periods, which vary by state and claim type verify per state
EU — GDPR supervisory-authority notification72 hours from the controller becoming aware of the breach (Article 33)
UK/EU — Article 82 compensation claimGenerally the ordinary national civil limitation period (UK: 6 years under the Limitation Act 1980) verify current rules in your country

Realistic Outcomes and Caveats

Most people’s actual recovery comes from a class-action settlement or free credit monitoring, not an individual lawsuit — individual claims outside California’s CCPA statutory-damages provision are relatively rare and often not cost-effective without documented, significant harm.

Both US courts (in states without a specific statutory-damages provision) and EU/UK courts under Article 82 generally require you to show actual harm, not just that a breach occurred — a bare notification, without more, is unlikely to produce a payout on its own.

This page can help you understand your notification rights and possible claim routes, but it cannot predict a specific settlement amount or court outcome.

Common Pitfalls

Assuming a breach notice automatically means you’ll be compensated

Under both US state law (outside California’s CCPA private right of action) and GDPR/UK GDPR, you generally need to show actual harm, not just that a breach happened.

Not keeping records of actual harm

Documented-loss settlement tiers and stronger Article 82 claims both depend on having real evidence — save statements, fraud-resolution records, and receipts as they happen.

Confusing a regulator complaint with a compensation claim

An FTC, state AG, ICO, or EU DPA complaint can produce enforcement action against the company, but none of these bodies pays you directly — a separate compensation claim is usually required.

Missing your state’s specific notification-deadline nuance

Deadlines range from a hard 30 days in some states to vague "unreasonable delay" language in others — don’t assume one state’s rule applies to a breach involving a company based elsewhere.

Overestimating "no proof" settlement tiers

These commonly pay in the tens of dollars per person; larger recoveries generally require documented identity theft or financial loss.

Organize Your Data Breach Records

Use the calculator to document the breach notice, any harm you’ve experienced, and your correspondence with the company or a regulator.

Organize Your Data Breach Records

Use the calculator to document the breach notice, any harm you’ve experienced, and your correspondence with the company or a regulator.

This stays in your private workspace until you choose a next step.

This stays in your private workspace until you choose a next step. It does not submit a claim on your behalf on its own.

Official and Legal References

US State Patchwork vs. EU/UK Single Compensation Right

The US has no comprehensive federal breach law — 50+ separate state statutes govern notification, and only California gives most consumers a real private right of action for breach-related damages, with fixed statutory-damages amounts. The EU and UK instead have a single, harmonized right to compensation under GDPR Article 82 (and the UK GDPR equivalent), but that right requires proof of actual material or non-material damage rather than offering fixed statutory amounts — meaning the practical value of a claim varies significantly by national court and case facts.

Frequently Asked Questions

Real edge cases, answered in plain language

I got a breach notice but nothing bad has happened yet — can I still get money?

Does filing an ICO or FTC complaint get me compensation?

What’s the difference between the "no proof" and "documented loss" settlement tiers?

This page provides general information about data breach and privacy violation rights in the US, EU, and UK as of July 2026. It is not legal advice. Notification deadlines, private rights of action, and compensation rules vary significantly by state and country and change over time — confirm current rules for your specific location before relying on anything here.

Organize Your Data Breach Records

Use the calculator to document the breach notice, any harm you’ve experienced, and your correspondence with the company or a regulator.

Organize My Case