IT contracts
Article 82 of the UK GDPR lets anyone who suffers material or non-material damage from an infringement claim compensation from the controller or processor. For IT firms that host, support or build systems holding personal data, it is a direct route to a claim that sits apart from any ICO fine, and whether your PI or cyber policy answers it depends on the wording.
Part of: Professional indemnity for IT professionals
In short
Under Article 82, a person who suffers financial loss or distress because personal data was processed in breach of the UK GDPR can sue for compensation. A controller is liable for any damage caused by infringing processing. A processor, such as an MSP or SaaS provider handling a client’s data, is liable only if it broke a duty aimed at processors or acted outside the controller’s lawful instructions. Where several parties share responsibility, each can be pursued for the whole loss and then recover shares from the others. The ICO cannot award compensation; claims go through the courts. PI and cyber policies may respond to the claim, while fines are commonly excluded.
Last reviewed 7 October 2026 by the Apex professional indemnity team.
Article 82 creates a private right to sue. It is separate from the ICO’s enforcement powers, and it can be used by any person who suffers damage, not only the data subject.
| Provision | What it says, in short |
|---|---|
| Art 82(1) | Any person who has suffered material or non-material damage as a result of an infringement has the right to compensation from the controller or processor. |
| Art 82(2) | Any controller involved in processing is liable for damage caused by processing that infringes the Regulation. A processor is liable only where it has not complied with obligations specifically directed to processors, or has acted outside or contrary to the controller’s lawful instructions. |
| Art 82(3) | A controller or processor escapes liability if it proves it is not in any way responsible for the event giving rise to the damage. |
| Art 82(4) | Where more than one controller or processor is involved in the same processing and responsible for the damage, each is liable for the entire damage, to ensure effective compensation. |
| Art 82(5) | A party that has paid full compensation can claim back from the others the part matching their share of responsibility. |
| DPA 2018 s.168 | “Non-material damage” includes distress. A court can order compensation to be paid to a representative body bringing the claim on someone’s behalf. |
Most IT service firms act as processors for their clients’ data. That narrows your Article 82 liability, but only while you stay inside the processor role. Article 28 sets out what that role involves:
The ICO puts the last point plainly: if you act outside your instructions or process for your own purposes, you become a controller for that processing, with a controller’s liability.
Three illustrative examples, not real claims:
In Lloyd v Google LLC [2021] UKSC 50, a claimant tried to bring one representative action for millions of iPhone users over browsing data allegedly collected in 2011 and 2012, seeking a uniform sum for each user for “loss of control” of their data, without proving any individual financial loss or distress.
The Supreme Court refused to let the claim go ahead. Lord Leggatt, with whom the other justices agreed, held that:
Two limits matter. The claim was decided under the 1998 Act, and the court said it would leave the UK GDPR and the 2018 Act to one side (paras 15 and 16). So Lloyd does not settle how Article 82 itself is read. And it did not close the door on group claims; it rejected one way of framing them.
The ICO enforces the law and can fine; it cannot award compensation. Its public guidance says so directly, and tells people that if an organisation will not pay, their next step is a claim in court.
PI and cyber wordings commonly exclude fines and penalties, or cover them only where the law allows. Do not assume that an indemnity promising to reimburse a client’s fine will be insured.
For an IT firm, a data incident can produce several kinds of loss at once. Which policy answers each one depends on the wordings and on how the two policies are set up to fit together.
| Loss or claim | Policy usually looked to | Common limits and gaps |
|---|---|---|
| Your client sues you for breach of contract or negligence after your error exposed its data | Technology PI | Data or cyber exclusions in some PI wordings push this to the cyber policy |
| Individuals bring Article 82 claims against you directly | PI, or the liability section of a cyber policy | Check that claims by people who are not your clients are covered |
| Your own incident costs: forensics, restoring systems, notifying the controller | Cyber (first-party) | PI does not usually pay your own costs |
| Defending an ICO investigation | Some cyber policies, subject to the terms | Often a sub-limit |
| ICO fine on you, or a client’s fine passed to you by contract | Commonly excluded | Some wordings cover fines only where insurable by law |
| Uncapped data protection indemnity | PI or cyber up to the limit, if the loss is covered at all | Anything above the limit, and liability wider than the general law |
Data protection super-caps and carve-outs from the main liability cap are covered on our page on limitation of liability clauses in IT contracts.
If this affects your business, these are the points a broker will ask about:
Speak to a broker
PI and cyber for IT firms, placed by a named broker
Start the online proposal and save it as you go, or leave your number and a named broker will call you back, usually the same working day.
Apex Insurance Brokers is an independent insurance broker based in Bristol, established in 2009 and authorised and regulated by the Financial Conduct Authority. We are not tied to one insurer: we work with over 30 markets, including Lloyd’s syndicates through wholesale brokers, and every client has a named broker who handles the placement, mid-term changes, certificates for clients and the renewal.
Article 82 gives any person who suffers material or non-material damage because of an infringement of the UK GDPR the right to compensation from the controller or processor. Controllers are liable for damage from infringing processing; processors only where they breach processor duties or act outside lawful instructions. Each responsible party can be liable for the whole damage.
Yes. A processor is liable under Article 82(2) where it has not complied with UK GDPR obligations aimed at processors, such as security under Article 32, or has acted outside or contrary to the controller’s lawful instructions. If it decides the purposes and means of processing itself, it is treated as a controller for that processing.
Yes. Article 82 covers non-material damage, and section 168 of the Data Protection Act 2018 says that includes distress. The claimant still has to show that the infringement caused the damage. The ICO cannot award compensation, so claims are settled with the organisation or decided by a court.
In 2021 the Supreme Court held that a representative claim for a uniform sum per iPhone user could not proceed under the Data Protection Act 1998, because compensation needed proof of material damage or distress and individual assessment. The court left the UK GDPR to one side, so the case does not settle how Article 82 itself applies.
Often, in part. Technology PI may respond to a client’s claim, and sometimes to data subject claims, caused by your error, subject to the wording. Many firms also buy cyber cover for their own incident costs and regulatory investigations. Fines are commonly excluded, and contractual promises to reimburse a client’s fines may not be insured.
Send us your data processing terms with your proposal and a broker will check how your PI and cyber wordings would respond to a data claim. Or call 0117 325 0027.
Start your PI proposal Call 0117 325 0027Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not advice on your individual circumstances. Cover is always subject to the insurer’s acceptance and the policy terms, and this page does not guarantee that cover will be available or on what terms.