You, as a TalkTalk customer, may feel that the recent data breach, considered alongside a series of unpleasant dealings with the company, is the final straw, and you may be asking yourself: can I leave TalkTalk? I analysed the TalkTalk contract for BBC Radio 4’s PM programme in October 2015; the clip is below, and this is what I found.
What the contract said in 2015
As with many consumer contracts there was a cooling-off period, TalkTalk’s being 21 days, a week longer than the 14 days the law requires (Consumer Contracts Regulations 2013), during which a customer could change their mind without penalty. Beyond that, a customer wanting to leave early was very limited in what they could do without incurring a charge. The contract set out a complex system of “early termination charges”, distinct for each service and cumulative. A customer on the “Fibre Large” package who cancelled had to pay £15 for every month left on the contract, on top of the separate charges for phone, broadband and television, which in some cases added up to nearly £800.
TalkTalk’s own statement at the time read: “In the unlikely event that money is stolen from your bank account as a direct result of the cyber attack (rather than as a result of any information you give out) then as a gesture of goodwill, on a case by case basis, we will waive termination fees. It’s important to remember that the cyber attack was a criminal act and we are acting in line with our terms and conditions.” So the company might, as a gesture of goodwill and case by case, waive the fees. The number of cases in which it would do so was always likely to be small, because of the caveats, in particular “rather than as a result of any information you give out”: a customer who had been telephoned by a fraudster armed with the stolen data, and who gave that fraudster one more detail, was outside the offer.
What happened next
The attack, between 15 and 21 October 2015, exposed the personal data of 156,959 customers, including the bank account numbers and sort codes of 15,656 of them, through a vulnerability on web pages TalkTalk had inherited with its purchase of Tiscali in 2009 and never secured. In October 2016 the Information Commissioner fined TalkTalk £400,000, then a record, for breaching the security principle of the Data Protection Act 1998, finding that the company had ignored two earlier attacks on the same pages that summer (the ICO on how its investigation unfolded). Several of the people behind the attack were later prosecuted and imprisoned.
A customer’s rights after a data breach now
The law has moved a long way since 2015, mostly in the customer’s favour. Under the UK GDPR and the Data Protection Act 2018 a company must tell the Information Commissioner of a serious breach within 72 hours and tell the affected customers without undue delay, the Commissioner’s fines now run to £17.5 million or 4 per cent of worldwide turnover, and a customer who suffers loss or distress as a result of a breach has a right to compensation from the company. That right belongs to each customer individually; the Supreme Court held in Lloyd v Google [2021] UKSC 50 that a claim cannot be brought on behalf of everyone affected without showing what each person lost, so the group claims that were once threatened after breaches like this have largely given way to individual complaints and claims. Leaving the contract is a separate question and still turns on the contract’s terms and on Ofcom’s rules for telecoms providers, which is why the analysis above is worth reading even now: a breach of security does not, by itself, end a contract, and the route out is usually a complaint, then the ombudsman, then a negotiated exit. Cohen Davis advises individuals and businesses on data breach claims.
First published 28 October 2015. Reviewed and updated 28 September 2026.
