All sample legal documents

Data Breach Complaint Letter

A completed UK GDPR complaint to a controller after an account compromise, requesting facts, containment, data-subject support and a response without making an unsupported claim.

Jurisdiction: England and Wales - completed fictional worked example

Download Sample

An editable Microsoft Word version is available from the interactive page.

Important: This sample provides general legal information only and is not legal advice. Check the law, prescribed forms and signing requirements that apply to your exact jurisdiction and circumstances before use.

# DATA BREACH COMPLAINT LETTER

Date: 4 October 2029

Parties: George Patel and Northstar Energy Services Limited

## 1. People, purpose and legal route

To the Data Protection Officer, Northstar Energy Services Limited, 1 Station Approach, London SE10 8AB: I am George Patel, customer account NS-77104. On 28 September I received a password-reset email I did not request, followed by a call from a person who knew my address, meter number and partial payment history.

## 2. Facts, scope and supporting evidence

Your 30 September message says an unauthorised party accessed a customer portal between 25 and 28 September. It does not say whether my name, address, email, account credentials, meter data, payment details or identity documents were accessed, copied or exfiltrated.

## 3. Requests, duties and safeguards

Please confirm the incident timeline, categories and approximate extent of personal data, affected systems, containment and password reset measures, likely consequences and the controller's risk assessment. Tell me whether the Information Commissioner's Office was notified under Article 33 UK GDPR and what communication was made to affected data subjects under Article 34.

## 4. Records, review and communication

Please force a credential reset, invalidate sessions and confirm that payment details are not being used. I ask for practical fraud monitoring advice, a named contact and a secure way to verify future calls. Do not send sensitive data by ordinary email. Preserve logs relevant to my complaint.

## 5. Time limits, escalation and outcome

Please treat this as a formal complaint and respond within 28 days, explaining any information withheld for security or third-party reasons. I also reserve my separate UK GDPR rights of access, rectification, restriction and compensation where legally established; this letter is not an admission that loss has already occurred.

## 6. Reservations and practical protections

If the response is inadequate I may complain to the Information Commissioner's Office and seek independent advice. I will mitigate risk by changing reused passwords and reporting suspicious contact, but that does not release Northstar from its controller duties or prejudice limitation issues.

## 7. England and Wales law and signature

Service may be hand delivery, post or email to george.patel@example.co.uk as independent permitted methods. Please acknowledge receipt and identify the DPO handling the complaint. Yours faithfully, George Patel.

Create a version for your situation

Create a tailored Data Breach Complaint