Skip to main content
| 16 Sept 2026

Patrick O'Kane is the author of Data Protection Litigation in the UK.

This will be included in our Intellectual Property and IT Law online service.

Who will benefit from reading this book?

Hopefully, anyone considering a compensation claim after their personal data has been lost, exposed or otherwise misused. We are seeing more cyber and data breaches happening. Last year, the cyber-attack on Jaguar Land Rover (JLR) was estimated to have cost £1.9 billion - the most economically damaging cyber event in UK history.

I wrote the book for anyone with an interest in data protection litigation whether they are a lawyer or a layperson. I wanted to write a practical guidebook rather than a dry, academic text.

Data protection cases are court proceedings brought by individuals or groups claiming loss or damage when their personal data have been mishandled. 
We often receive emails from companies telling us that they have lost our data. There have been some huge data breaches in the UK recently including breaches at Marks and Spencer, Co-op and JLR.

Increasingly, individuals are discovering that if an organisation loses their personal data and this causes them distress, they can claim compensation under the GDPR. 

People can bring data protection claims where companies break the law, for example by losing personal data, breaching data rights, unlawfully sharing or selling information, or using it without permission, including to train AI models.
Data protection litigation can be a maze. The legal framework post-Brexit can be complex and the UK case law unpredictable. This book aims to help lawyers and non-lawyers through the maze. The case law is very dynamic and interesting from the Naomi Campbell privacy case two decades ago right up to the recent Farley v Paymaster case.

Are there any key trends you foresee impacting data protection litigation in the UK over the next few years?

The first trend is clear: more data breaches are leading to more litigation. 

When companies accumulate data, they are often prone to losing it. 

For example, in the UK we have recently seen the Co-op cyber-attack in which 6.5 million Co-op members reportedly had their data compromised.

The second trend is the growing debate over whether data compensation claims should be subject to a threshold of seriousness, as debated in cases such as Farley v Paymaster. This case is going to the UK Supreme Court for a final ruling on this issue.

The third trend is the increase in AI-related claims. AI is being used more often to make decisions about people, from hiring to credit checks. When AI systems use personal data unlawfully or produce biased outcomes, litigation can follow. The US case of Mobley v Workday is a leading example where the claimant alleges that AI CV scanning software unfairly rejected over 100 of his job applications on the basis of his race.

What one key step can organisations in the UK take to avoid the risk of data protection litigation?

As the actor Ralph Fiennes says in the movie ‘Hail Caesar’, ‘Would that it were so simple’. The bad news is that data protection compliance is not cookie cutter so there is no one magical step that will work across all organisations.

Sometimes I wish there was. 

The good news is there are steps we can all take today to reduce our data protection risk.

A good first step is to find the weak spots in your data practices and fix them before they end up costing you money.

Companies should ask themselves a question: where could personal data escape out into the wild, and what can we now do to stop it?

For example, when British Airways (BA) suffered a cyber-attack back in 2018, the data of 400,000 people was compromised and this lead to the largest personal data group litigation ever in the UK. Tens of thousands of these people sued British Airways for breach of data protection law. It is understood that these cases settled out of court.

The breach left BA facing damaging headlines, a £20 million fine, and the enormous expense of dealing with compensation claims. BA could have avoided much of this pain if they had tightened up their website security before the cyber-attack occurred.

Companies need to identify the weak spots before claimants or cyber-attackers do. That means asking whether their systems are secure, their staff are properly trained, and their use of personal data is on the right side of the law.

The key thing to remember is that data protection compliance is not a like an annual dental check-up which is done and then forgotten. To borrow a phrase from American politics, data protection is ‘a permanent campaign’: organisations must continuously assess threats and tighten their security.

What is the most challenging aspect of working in data protection?

For me there are two ongoing challenges, these are new technology and new laws. 

Firstly, new technologies constantly create new challenges for data security. 
For example, quantum computers are still being developed and they use quantum physics - where data can exist in multiple contradictory positions at the same time - which allows them to be more powerful than other computers.

Quantum computing is so complex. As the joke goes, if you can explain it, you probably do not understand it. The fear is that quantum computers may one day be powerful enough to crack the encryption used to protect personal data, exposing it to hackers, and hostile nation states.

Secondly, keeping up with all the data protection, AI and cyber laws is challenging. One study showed that by 2024, 75% of the world's population were subject to a modern data protection law, which was a huge leap from just 10% of the world’s population being covered by such a law in 2020. The UK case law is also evolving so rapidly. In the book we consider how UK data protection case law has developed on things like damages, costs, data protection rights and AI. 

I really enjoy working in this field.