Paddy Power Data Breach 2025 – Your Rights, What to Do & Compensation Guide

BySteve

11 July 2025

Paddy Power Data Breach 2025 – Your Rights, What to Do & Compensation Guide

If you’re one of the many Paddy Power customers who received a worrying email about a recent data breach, you’re not alone — and you’re right to be concerned. While the company claims that passwords and payment details weren’t affected, the exposure of your personal information is still serious. In this guide, I’ll explain exactly what happened, what data was compromised, and—most importantly—what you can do next. From protecting your account to making a formal complaint, claiming compensation, and escalating to the ICO, this is your complete action plan under UK GDPR.

Paddy Power Data Breach

Can You Claim Compensation for a Data Breach?

Under the UK GDPR and Data Protection Act 2018, you are entitled to compensation if you suffer:

  • Material damage (e.g. financial loss, identity theft, fraudulent transactions)

  • Non-material damage (e.g. stress, anxiety, distress caused by the breach)

You do not have to prove financial loss to claim for emotional distress.

So, What Are Your Options?

1. Ask Paddy Power Directly

In your complaint (or follow-up), you can say:

“I would also like to know if you are offering compensation to affected customers, either for distress caused or any material inconvenience. Please confirm what redress is available.”

They may offer something proactively — especially if enough people complain.

2. Make a Legal Claim

If they don’t offer anything, you have other routes:

  • Small Claims Court: You can pursue them for compensation (typically £250–£3,000 depending on severity).

  • No win, no fee solicitors: Law firms may take on your case if they believe the breach was serious. Some are already dealing with similar breaches from other companies.

  • ICO complaint: While the ICO doesn’t award compensation, their investigation could support your claim.

Now that you are armed with background knowledge, here’s a structured approach to what you can and should do now:

Understand What Was Breached

According to the email, the data exposed includes:

  • Username and email address

  • Your name and part of your address (first line + city)

  • Technical data (device ID and IP address)

  • Some recent betting activity

Not exposed: passwords, payment info, ID documents

Even though the breach didn’t include financial data or ID, the leaked info can still be used for:

  • Phishing scams

  • Social engineering (impersonation attempts)

  • Credential stuffing (trying your credentials on other sites)

Actions You Should Take

Check your Paddy Power account

  • Log in and make sure everything looks normal (no suspicious bets or account changes).

  • Change your password anyway (especially if reused elsewhere).

  • Enable 2FA (two-factor authentication) if they offer it.

Change passwords on other sites

If you’ve used the same password/email combo elsewhere, change them immediately.

Be alert for phishing emails

You may receive scam emails that appear to be from Paddy Power, banks, or other services. Be skeptical of:

  • Unexpected password resets

  • Prize/bonus offers

  • Emails requesting personal or banking information

Check your inbox rules

In case someone accessed your email (if it shares a password with Paddy Power), make sure no weird rules or forwards have been added.

Check for identity misuse

Although the breach didn’t include ID documents, scammers can still use partial data to impersonate you. If anything seems suspicious (credit checks, loan offers, etc.), consider:

Ask for Accountability

You have rights under the UK GDPR. You can:

  • Submit a formal complaint to Paddy Power, requesting a full breakdown of the data accessed, when it happened, how long they took to notify you, and what further protections they’re offering.

  • Escalate to the Information Commissioner’s Office (ICO) if you’re not satisfied:
    https://ico.org.uk/make-a-complaint

Contact Paddy Power

I couldn’t find an email address for Paddy Power’s Data Protection Officer, therefore I contacted them via their verified X feed @askpaddypower and sent a message. Here is the transcript of the totally unsatisfactory exchange. If the same thing happens to you then read on…

Why This is Problematic

  • Security Risk:
    Social media platforms (like Twitter/X) are not secure channels for sharing personal data like email addresses or usernames.

  • Poor GDPR Practice:
    Under the UK GDPR, organisations must provide a secure and direct way to contact their Data Protection Officer (DPO) or responsible team — especially in the event of a breach.

  • Inconsistent with Best Practice:
    Reputable companies usually:

    • Provide a dedicated data protection email (e.g., dataprotection@...)

    • Allow secure web form submissions

    • Avoid handling sensitive matters via public or semi-public platforms

What You Should Do Next

  • Refuse to share personal info via social media — this is very important.

  • Request the direct contact for their DPO again.
    You can add:

    “Under Article 13(1)(b) of the UK GDPR, I have a right to contact your data protection officer or responsible contact directly. Please provide the appropriate email address.”

  • If they still refuse, escalate:

Draft Complaint Template

This is a perfectly professional and legally compliant email template you are welcome to use when complaining to Paddy Power/Flutter.

Subject: Formal Complaint Regarding Data Breach Notification

To: “dataprotection@flutterint.com” <dataprotection@flutterint.com>

Dear Paddy Power Data Protection Team,

I am writing to express my serious concern regarding the recent data incident on your platform, as outlined in the email I received on [insert date you received it, e.g. 10 July 2025].

According to your communication, an unauthorised third party gained access to my personal data, including my name, email address, part of my postal address, details of my account activity, and technical information such as my device ID and IP address. While you state that payment details and passwords were not compromised, I am extremely dissatisfied that such a breach occurred at all.

This represents a clear failure in your duty to protect customer data under the UK General Data Protection Regulation (UK GDPR). I have the following concerns and requests:

  1. Full Details of the Breach:
    • When did the breach occur, and when was it first detected?
    • How long was my data accessible to the third party?
    • What precise information about me was accessed?
    • Has my information been shared or sold on, or detected on any public forums or dark web platforms?
  2. Your Remedial Actions:
    • What steps have you taken to ensure the breach is fully contained?
    • How are you improving your systems to prevent this from happening again?
    • Are you offering any protective services to affected customers, such as credit monitoring?
  3. Reporting to Authorities:
    • Have you reported this breach to the Information Commissioner’s Office (ICO)?
    • If so, please provide your case reference number.
  4. My Rights:
    Please confirm how I can exercise my rights under the UK GDPR, including:

    • Access to all data you hold about me
    • The right to erasure (“right to be forgotten”), should I choose to request it
    • The right to lodge a complaint with the ICO

I expect a full response within 14 calendar days of this message. Depending on your reply, I may choose to escalate the matter to the Information Commissioner’s Office for further investigation.

I trust you will treat this matter with the seriousness it warrants.

Yours sincerely,
[Insert your name]
[Insert your email address]
[Optional: your postal address]

What to Expect Next

  • Paddy Power should acknowledge your complaint within a few days.

  • They’re legally expected to respond in full within 30 days (though you gave a reasonable 14-day deadline in your letter).

  • If they reply with a generic or unhelpful response, or fail to meet that timeframe, you’ll be well positioned to escalate it to the ICO with clear evidence that you gave them the chance to respond properly.

In the meantime:

  • Keep a record of all correspondence (including screenshots of any social media exchange).

If Flutter don’t respond or keep dodging you, this becomes part of your case. You can say:

“I attempted to contact support@paddypower.com as listed publicly, but the message was rejected with status code 5.7.1, indicating that the address is not fit for public use. This leaves dataprotection@flutterint.com as the only viable route — and even that was not offered to me directly despite multiple requests.”

Draft ICO Complaint Template

Here’s a draft complaint to the Information Commissioner’s Office (ICO) you can use to report Paddy Power’s handling of your data breach and GDPR rights. You can copy this into the ICO online complaint form or email it if preferred.


Subject: GDPR Complaint – Paddy Power Data Breach & Failure to Provide DPO Contact


Dear ICO Complaints Team,

I am writing to raise a formal complaint regarding Paddy Power (part of Flutter Entertainment) following their notification to me of a recent data breach affecting my account.

On [Insert Date], I received an email from Paddy Power stating that an unauthorised third party had accessed certain personal data, including:

  • My full name

  • Email address

  • Partial home address

  • Account activity

  • IP address and device ID

While they claimed no payment details or passwords were affected, I am concerned about the exposure of this personal information and the company’s subsequent handling of the matter.


My complaint relates to two specific failures:

1. Inadequate handling of the data breach

  • I have not been provided with a full explanation of the scope and cause of the breach.

  • I have not been offered compensation or meaningful redress for the risk and distress caused.

2. Failure to comply with Article 13(1)(b) of the UK GDPR

  • When I requested the direct contact details for Paddy Power’s Data Protection Officer (DPO) via their official Twitter/X support channel, they repeatedly refused to provide an email address.

  • Instead, I was redirected to public-facing customer service channels (live chat and social media), which are not appropriate for raising sensitive GDPR-related complaints.

  • I explicitly referenced my right under UK GDPR Article 13(1)(b) to contact the DPO, but this was still ignored.


What I Am Requesting:

  • Confirmation that Paddy Power has fulfilled its obligations to report this breach to the ICO.

  • An investigation into whether the organisation has met its legal obligations under the UK GDPR, including:

    • Transparency

    • Security of processing

    • Facilitating data subject rights

I have retained copies of the data breach notification email and the social media interaction, which I am happy to share upon request.

Thank you for your time and consideration.

Yours faithfully,
[Insert your Name]
[Insert your preferred email address]
[Optional: Postal address]

What To Do Next

  1. Protect your account

  2. Send the complaint email

  3. Log evidence

  4. Escalate to ICO

  5. Consider public/post press if unresolved

I hope this is guide has been useful. Don’t be fobbed off. Data breaches are serious.

FAQ

❓ What is the Paddy Power data breach?

Paddy Power notified customers that an unauthorised third party accessed some user data, including email addresses, partial home addresses, IP/device data, and account activity.

❓ Can I claim compensation under GDPR?

Yes. If you’ve suffered distress or financial harm, you may be entitled to compensation under Article 82 of the UK GDPR.

❓ Do I need to wait for Paddy Power to offer compensation?

No. You can request it directly. If they don’t respond or reject your request, you can escalate to the ICO or pursue a legal claim.

❓ How do I escalate to the ICO?

Visit ico.org.uk/make-a-complaint and submit your complaint online. Include screenshots and evidence of your contact with Paddy Power.

❓ What if Paddy Power refuses to give me their DPO contact?

Under Article 13(1)(b) of the UK GDPR, you’re legally entitled to a data protection contact. If they refuse, that itself may be a GDPR violation.

Share with friends

BySteve

Steve Bradley is the man behind this project, an unashamedly nostalgic website dedicated to horse racing’s golden days of the past, featuring vintage racecards, clippings and news stories plucked from the newspapers of the day. A devotee of horse racing’s halcyon days from the 1960s to the 1990s, Steve caught the racing bug as a small boy living near Catterick racecourse, where he was lucky enough to see the great Red Rum in action in the 1970s. He has undertaken private research commissions for various figures within the racing industry. Away from racing he enjoys spending time with his retired greyhound, bar billiards, music, TV, films, reading and travel.

If you enjoyed this article please let us know. Questions are also welcome!