FCA authorised · FRN 724952 0117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →

IT contracts

UK GDPR Article 82: data protection compensation claims, explained for IT firms

Article 82 of the UK GDPR lets anyone who suffers material or non-material damage from an infringement claim compensation from the controller or processor. For IT firms that host, support or build systems holding personal data, it is a direct route to a claim that sits apart from any ICO fine, and whether your PI or cyber policy answers it depends on the wording.

In short

Under Article 82, a person who suffers financial loss or distress because personal data was processed in breach of the UK GDPR can sue for compensation. A controller is liable for any damage caused by infringing processing. A processor, such as an MSP or SaaS provider handling a client’s data, is liable only if it broke a duty aimed at processors or acted outside the controller’s lawful instructions. Where several parties share responsibility, each can be pursued for the whole loss and then recover shares from the others. The ICO cannot award compensation; claims go through the courts. PI and cyber policies may respond to the claim, while fines are commonly excluded.

Start your PI proposal →or call 0117 325 0027 to speak to a broker

How Article 82 works

Last reviewed 7 October 2026 by the Apex professional indemnity team.

Article 82 creates a private right to sue. It is separate from the ICO’s enforcement powers, and it can be used by any person who suffers damage, not only the data subject.

ProvisionWhat it says, in short
Art 82(1)Any person who has suffered material or non-material damage as a result of an infringement has the right to compensation from the controller or processor.
Art 82(2)Any controller involved in processing is liable for damage caused by processing that infringes the Regulation. A processor is liable only where it has not complied with obligations specifically directed to processors, or has acted outside or contrary to the controller’s lawful instructions.
Art 82(3)A controller or processor escapes liability if it proves it is not in any way responsible for the event giving rise to the damage.
Art 82(4)Where more than one controller or processor is involved in the same processing and responsible for the damage, each is liable for the entire damage, to ensure effective compensation.
Art 82(5)A party that has paid full compensation can claim back from the others the part matching their share of responsibility.
DPA 2018 s.168“Non-material damage” includes distress. A court can order compensation to be paid to a representative body bringing the claim on someone’s behalf.

Controller or processor: why the label decides your exposure

Most IT service firms act as processors for their clients’ data. That narrows your Article 82 liability, but only while you stay inside the processor role. Article 28 sets out what that role involves:

The ICO puts the last point plainly: if you act outside your instructions or process for your own purposes, you become a controller for that processing, with a controller’s liability.

Three illustrative examples, not real claims:

  1. An MSP leaves a client’s backup storage open to the internet. Because Article 32 security is a processor duty, staff whose records were exposed can sue the MSP as well as the client.
  2. A SaaS provider starts using customer records to train its own analytics product. For that use it is likely to be a controller, not a processor, and loses the narrower Article 82(2) position.
  3. A developer hands a client’s data to an unapproved offshore subcontractor, which then suffers a breach. The developer answers to the client for the subcontractor’s failings.

Lloyd v Google: what claimants still have to prove

In Lloyd v Google LLC [2021] UKSC 50, a claimant tried to bring one representative action for millions of iPhone users over browsing data allegedly collected in 2011 and 2012, seeking a uniform sum for each user for “loss of control” of their data, without proving any individual financial loss or distress.

The Supreme Court refused to let the claim go ahead. Lord Leggatt, with whom the other justices agreed, held that:

Two limits matter. The claim was decided under the 1998 Act, and the court said it would leave the UK GDPR and the 2018 Act to one side (paras 15 and 16). So Lloyd does not settle how Article 82 itself is read. And it did not close the door on group claims; it rejected one way of framing them.

ICO fines and civil claims are different risks

The ICO enforces the law and can fine; it cannot award compensation. Its public guidance says so directly, and tells people that if an organisation will not pay, their next step is a claim in court.

PI and cyber wordings commonly exclude fines and penalties, or cover them only where the law allows. Do not assume that an indemnity promising to reimburse a client’s fine will be insured.

How PI and cyber insurance respond

For an IT firm, a data incident can produce several kinds of loss at once. Which policy answers each one depends on the wordings and on how the two policies are set up to fit together.

Loss or claimPolicy usually looked toCommon limits and gaps
Your client sues you for breach of contract or negligence after your error exposed its dataTechnology PIData or cyber exclusions in some PI wordings push this to the cyber policy
Individuals bring Article 82 claims against you directlyPI, or the liability section of a cyber policyCheck that claims by people who are not your clients are covered
Your own incident costs: forensics, restoring systems, notifying the controllerCyber (first-party)PI does not usually pay your own costs
Defending an ICO investigationSome cyber policies, subject to the termsOften a sub-limit
ICO fine on you, or a client’s fine passed to you by contractCommonly excludedSome wordings cover fines only where insurable by law
Uncapped data protection indemnityPI or cyber up to the limit, if the loss is covered at allAnything above the limit, and liability wider than the general law

Data protection super-caps and carve-outs from the main liability cap are covered on our page on limitation of liability clauses in IT contracts.

Common misunderstandings

What to check

  1. For each contract, record whether you are processor, controller or both, and keep to the documented instructions.
  2. Keep a list of sub-processors with the client’s written authorisation for each.
  3. Read the data protection indemnity and any super-cap against your PI and cyber limits.
  4. Ask whether your PI wording covers claims from data subjects and regulatory investigations, or leaves them to cyber.
  5. Resist clauses that make you reimburse a client’s regulatory fines.
  6. Notify your insurer early when an incident could lead to a claim.

Processing client data under contract?

If this affects your business, these are the points a broker will ask about:

Speak to a broker

PI and cyber for IT firms, placed by a named broker

Start the online proposal and save it as you go, or leave your number and a named broker will call you back, usually the same working day.

Start your PI proposal →or call 0117 325 0027

How Apex places this cover

Apex Insurance Brokers is an independent insurance broker based in Bristol, established in 2009 and authorised and regulated by the Financial Conduct Authority. We are not tied to one insurer: we work with over 30 markets, including Lloyd’s syndicates through wholesale brokers, and every client has a named broker who handles the placement, mid-term changes, certificates for clients and the renewal.

Related guides

Sources

Frequently asked

What is Article 82 of the UK GDPR?

Article 82 gives any person who suffers material or non-material damage because of an infringement of the UK GDPR the right to compensation from the controller or processor. Controllers are liable for damage from infringing processing; processors only where they breach processor duties or act outside lawful instructions. Each responsible party can be liable for the whole damage.

Can a data processor be sued for compensation?

Yes. A processor is liable under Article 82(2) where it has not complied with UK GDPR obligations aimed at processors, such as security under Article 32, or has acted outside or contrary to the controller’s lawful instructions. If it decides the purposes and means of processing itself, it is treated as a controller for that processing.

Can you claim compensation for distress under UK GDPR?

Yes. Article 82 covers non-material damage, and section 168 of the Data Protection Act 2018 says that includes distress. The claimant still has to show that the infringement caused the damage. The ICO cannot award compensation, so claims are settled with the organisation or decided by a court.

What did Lloyd v Google decide?

In 2021 the Supreme Court held that a representative claim for a uniform sum per iPhone user could not proceed under the Data Protection Act 1998, because compensation needed proof of material damage or distress and individual assessment. The court left the UK GDPR to one side, so the case does not settle how Article 82 itself applies.

Does professional indemnity insurance cover GDPR claims?

Often, in part. Technology PI may respond to a client’s claim, and sometimes to data subject claims, caused by your error, subject to the wording. Many firms also buy cyber cover for their own incident costs and regulatory investigations. Fines are commonly excluded, and contractual promises to reimburse a client’s fines may not be insured.

Ready to compare cover?

Send us your data processing terms with your proposal and a broker will check how your PI and cyber wordings would respond to a data claim. Or call 0117 325 0027.

Start your PI proposal Call 0117 325 0027

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not advice on your individual circumstances. Cover is always subject to the insurer’s acceptance and the policy terms, and this page does not guarantee that cover will be available or on what terms.