What kind of breach this is
When a university mishandles your marks, medical information or disciplinary records, you are usually dealing with a personal data breach under the UK GDPR and the Data Protection Act 2018. A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Common examples in a university setting include an email or spreadsheet of marks sent to the wrong recipients, medical or disability evidence being seen by staff who had no need to see it, a disciplinary file being disclosed to other students, or records left visible or accessible online.
Two of these categories carry extra weight. Medical information is special category data under Article 9 UK GDPR, and disciplinary records may amount to data relating to alleged criminal conduct or otherwise highly sensitive information. The law treats disclosure of this kind of data more seriously, which is relevant both to how the university should have protected it and to the level of distress a court might recognise.
First establish what actually happened
Before treating this as a breach, work out the factual explanation. Not every disclosure is unlawful. If your marks were released to an appeals panel, or your medical evidence was shared with a mitigating circumstances committee, or your disciplinary record was passed to a professional body under a fitness to practise process, that may be a legitimate and expected use of the data. The key questions are what information was involved, who saw it, whether they were entitled to, how it happened, and what harm has resulted. A genuine breach is unauthorised or accidental disclosure to people with no proper reason to see the data, not routine internal processing.
Gather evidence early
1. Note the date you discovered the breach and how you found out.
2. Keep copies of any emails, screenshots, letters or documents showing what was disclosed and to whom.
3. Record who appears to have seen the information and in what circumstances.
4. Keep a note of any consequences, for example distress, anxiety, reputational harm, or a specific detriment such as an academic or employment consequence.
This evidence supports every route below, from an internal complaint to a compensation claim.
Step one: raise it with the university
The university is the data controller, so your first step is normally to complain directly to it. Most institutions have a Data Protection Officer and a data breach or complaints procedure. Put your complaint in writing, set out what happened, identify the data involved, and say what you want, for example an explanation, confirmation the data has been retrieved or deleted, an apology, steps to prevent recurrence, and compensation if you have suffered damage.
The university should investigate, tell you the outcome, and take remedial action. Depending on the risk, it may also have a legal duty to report the breach to the Information Commissioner’s Office within 72 hours and, where the breach is likely to result in a high risk to your rights and freedoms, to inform you directly. The disclosure of medical or disciplinary information is exactly the kind of case where those reporting duties are likely to be engaged.
Step two: a subject access request if you need more information
If you are unsure what the university holds or how your data has been handled, you can make a subject access request under Article 15 UK GDPR. This entitles you to a copy of your personal data and information about how it has been used and who it has been shared with. The university must normally respond within one month and cannot charge a fee in most cases. This can be a useful way to understand the scope of the breach and to identify who accessed your records.
Step three: complain to the Information Commissioner’s Office
If the university does not resolve your complaint, or you are unhappy with how it handled the breach, you can complain to the Information Commissioner’s Office (ICO), the UK data protection regulator. You should normally raise the matter with the university first and give it a chance to respond, usually allowing around a month, before going to the ICO.
The ICO can investigate, form a view on whether the university broke data protection law, require it to take action, and in serious cases take enforcement action. However, the ICO cannot award you compensation and will not advise you on a compensation claim. Its role is regulatory, so it is the right route if your main aim is accountability and getting the university to fix its practices, but not if your main aim is a financial payment.
Step four: claiming compensation
You have a right under the UK GDPR to claim compensation from the university if you have suffered damage as a result of it breaking data protection law. Damage covers both material damage, such as financial loss, and non-material damage, such as distress. Distress is often the main head of claim in cases involving disclosure of medical or disciplinary information.
You do not have to go to court first. You can ask the university to pay compensation as part of resolving your complaint, and it may agree. If it refuses, you can bring a claim in the county court. Be realistic about the level of award. Awards for distress in data cases are often modest, and the courts have discouraged trivial claims, so you should weigh the likely sum against the cost, delay and stress of litigation. You will normally need to show a real breach and a genuine, more than trivial adverse effect, supported by your evidence of what happened and how it affected you.
Step five: the Office of the Independent Adjudicator
If the data breach is bound up with a wider student complaint, for example about how your marks were handled, an unfair disciplinary outcome, or a failure to take medical evidence into account, you can also use the university’s internal complaints procedure and then, once you have a Completion of Procedures letter, take the matter to the Office of the Independent Adjudicator for Higher Education (OIA). The OIA reviews student complaints against most higher education providers in England and Wales. It can recommend remedies including an apology, a change of decision, or a financial payment, and its scheme is free to use. The OIA does not decide data protection law as such, but it can address the fairness and consequences of how the university treated you.
Choosing the right combination of routes
These routes are not mutually exclusive. In practice a sensible order is often to complain to the university first, use a subject access request if you need to understand the full picture, escalate to the ICO if you want the regulator to hold the university to account, use the OIA where the breach forms part of a broader academic or disciplinary grievance, and consider a compensation claim if you have suffered genuine financial loss or significant distress. Court action should generally be a last resort given cost and litigation risk, particularly where awards for distress may be small.
Watch the time limits
Act reasonably promptly. Universities and the ICO expect complaints to be raised without undue delay. The OIA generally requires a complaint within twelve months of the Completion of Procedures letter. A court claim for compensation is generally subject to a six year limitation period, but delay can weaken your evidence and your position, so it is best not to leave things.
Information that would sharpen the advice
The best next step depends on facts I do not yet have. It would help to know exactly what was disclosed and to whom, how you found out, whether the university has already responded, whether the breach caused a specific consequence beyond distress, and whether it is linked to an ongoing academic, mitigating circumstances or disciplinary matter. Those details determine whether this is best treated purely as a data protection issue, a wider student complaint, or both.
This answer draws on broad legal knowledge and checks current law, guidance and procedure against relevant sources.
How to make a data protection complaint to an organisationico.org.ukTaking your case to court and claiming compensationico.org.ukData protection: Make a complaintgov.ukPersonal data breaches: a guide | ICOico.org.ukKNOW WHERE YOU STAND
Ready to stop guessing?
The above is just an example answer. Sign up now to get personalised guidance and ask follow-up questions based on your own situation. Bring your legal issue, your contract, or your question. Lawyer Destroyer gives you clear, practical guidance so you can move forward with confidence.