Zellis Data Breach Claim
The MOVEit breach at payroll provider Zellis exposed employee data across several major UK employers. There is no single settlement — you must actively instruct a firm, and in Scotland the clock has nearly run out.
Group claims active. No single settlement — you must join one.
| Breach | MOVEit file transfer vulnerability exploited at Zellis, June 2023 |
|---|---|
| Who was affected | Current and former employees of organisations using Zellis payroll services |
| Named organisations | British Airways, BBC, Boots, DHL and others |
| Legal basis | UK GDPR / Data Protection Act 2018 |
| Structure | Multiple law firm group actions — not a single unified settlement |
| Typical awards | Hundreds to low thousands of pounds |
| Limitation | Six years in England and Wales; three years in Scotland |
| Cost to claim | Normally no win, no fee |
What happened
In early June 2023, attackers exploited a vulnerability in MOVEit, a widely used managed file transfer product from Progress Software. It became one of the largest supply-chain data incidents on record.
Zellis provides payroll services to a large number of UK employers. Because payroll data flowed through the compromised MOVEit environment, the personal data of current and former employees of Zellis's clients was accessed — including at British Airways, the BBC, Boots and DHL. The affected data varied by employer but generally included the sort of information payroll holds: names, addresses, dates of birth, national insurance numbers, and bank details.
The scope widened over time as further organisations were identified as affected, so the absence of your employer from early reporting does not settle the question.
Are you eligible?
You are likely eligible to bring a claim if you were employed by an organisation that used Zellis payroll services at the relevant time — including if you have since left — and your personal data was compromised in the incident.
Under UK data protection law you can claim compensation for non-material damage — the distress, anxiety, and loss of control over your personal data caused by the breach itself. Financial loss, where it exists, is claimed on top. This is the pivotal difference between UK and Australian data breach law and the reason UK claims are more straightforward.
How to check: organisations were obliged to notify affected individuals. Look for a notification letter or email from your employer in June–August 2023, and check the address and email they held for you at the time, which may not be your current one. If you cannot find one, ask your former employer's HR or data protection officer directly — you also have a right to make a subject access request asking what data they hold and whether it was affected.
The deadline that actually matters
There is no single claim deadline for this breach — no administrator, no claim form, no settlement date. What limits you is the statutory limitation period, and it is running.
- ✓England, Wales and Northern Ireland: six years from the date the cause of action accrued. For a June 2023 breach, that points to mid-2029.
- ✓Scotland: three years. For a June 2023 breach, that is already very tight or expired, depending on when your cause of action accrued and when you knew of it.
The shorter Scottish prescriptive period is the single most consequential fact on this page, and the reason several Scottish firms ran dedicated Zellis claims separately from the England and Wales actions.
How much compensation?
There is no fixed tariff, and any firm quoting you a guaranteed figure is overselling. What the pattern of UK data breach group actions supports:
- ✓Distress-only claims — the large majority — have typically resolved in the hundreds of pounds, sometimes into the low thousands where the data was especially sensitive or the distress well evidenced.
- ✓Claims with documented financial loss — fraud on your accounts, identity theft, costs of remediation — recover that loss on top, and the financial element can substantially exceed the distress award.
What moves your figure up: the sensitivity of the data exposed (bank details and national insurance numbers rank high), evidence that it was actually misused against you, and contemporaneous documentation of the impact on you.
Evidence: the part that decides your award
Distress is compensable but it has to be evidenced, and this is where most claimants underperform. Gather now:
- ✓The breach notification from your employer or Zellis.
- ✓Evidence of misuse — fraudulent transactions, accounts opened in your name, phishing or impersonation attempts that used details from the breach.
- ✓Costs incurred — credit monitoring subscriptions, replacing documents, phone calls, time off work.
- ✓Evidence of distress — GP records if you sought help, a contemporaneous note of when the anxiety started, correspondence showing you chasing banks or your employer.
- ✓Your credit report from Experian, Equifax or TransUnion, checked for entries you do not recognise.
A dated record made at the time is worth considerably more than a recollection three years later.
How the UK claims are structured
This is not one class action. Unlike the US and Australia, England and Wales has no general opt-out class action regime for data protection claims — and the Supreme Court in Lloyd v Google closed the door on representative actions for uniform "loss of control" damages without individualised assessment.
The practical consequence: Zellis claims are run as group actions in which each claimant is an individual client of a law firm, with claims managed collectively. Several firms are running them — Leigh Day, Jones Whyte, Thompsons Scotland and others. You must actively sign up with a firm; you are not automatically included in anything. That also means outcomes may differ between firms and cohorts, and there will not be one headline settlement figure covering everybody.
What to do
- 1Confirm you were affected — find the notification, or make a subject access request to your employer.
- 2Check your limitation period — and if you are in Scotland, treat it as urgent.
- 3Gather your evidence before you approach anyone.
- 4Instruct a firm running Zellis or MOVEit claims. Ask specifically what percentage is deducted from any award and whether after-the-event insurance is required.
- 5Consider a free complaint to the ICO in parallel. The Information Commissioner's Office cannot award you compensation, but the complaint is free and the regulatory record can support a civil claim.
Frequently Asked Questions
I worked at British Airways / BBC / Boots / DHL and left years ago. Can I still claim?
Yes. Former employees are covered — payroll data for leavers was in the same systems. What matters is whether your data was affected and whether you are within the limitation period.
Do I sue Zellis or my employer?
It depends on the roles under UK GDPR — your employer will generally be the data controller and Zellis the processor, and claims may be pursued against either or both. Your solicitor will identify the correct defendant; it is not a decision you need to make.
Does it cost anything?
Group data breach claims are normally run on no win, no fee. You should still ask for the success fee percentage in writing before signing.
How long will it take?
UK data breach group actions commonly take two to four years from instruction to resolution.
Can I claim if nothing bad has actually happened to me?
Yes — that is the point of non-material damage under UK law. The claim is for the distress and loss of control caused by the breach itself. The award will be lower than for someone defrauded, but the claim is real.
Is this the same as the MOVEit claim?
Zellis is one of many organisations compromised through the MOVEit vulnerability. If your data was exposed through Zellis payroll, the Zellis route is yours; other MOVEit-affected organisations have their own claims.
See every settlement you qualify for
Tell SettleScout which brands you use and it matches you with open settlements, estimates your payouts, and reminds you before every deadline.
Free to download. Premium plans available.