Security

If your data may have been affected by a breach

If a breach were ever likely to put your data at risk, we would tell you and the regulator within the required timescales and set out what to do. Here is how that works and how to protect yourself.

2 min read

72 hoursRegulator notified without undue delay
Told directlyIf there's a real risk to you
Clear stepsWhat to do, in plain terms

Our obligations

Under UK data-protection law, an organisation must report a qualifying personal-data breach to the Information Commissioner's Office without undue delay and within 72 hours where feasible, and must tell affected people directly if the breach is likely to result in a high risk to their rights. We take these duties seriously and would communicate honestly and quickly rather than downplay anything.

How we would tell you

If a breach were likely to affect you, we would contact you directly — not bury it — explaining what happened, what data was involved, what we are doing, and what you should do. Any such message would tell you to sign in yourself by typing credicorp.co.uk; it would never ask for your password or push you to a login link. That distinction matters, because scammers exploit breach fears — see recognising official communications.

What you can do

Whether or not a breach has occurred, a few habits keep you safe: use a unique password, turn on two-factor authentication, switch on alerts, and be alert to phishing that references a breach to panic you. If you are told your data was affected, follow the specific steps in that notice.

Reporting your own concern

If you believe your data has been exposed — through us or a scam using our name — tell us via reporting suspected fraud. You can also raise concerns with the ICO directly, and we would rather you told us early than waited.

Frequently asked questions

Would you tell me if my data was breached?

If a breach were likely to put you at high risk, yes — directly and promptly, explaining what happened and what to do. We'd also report qualifying breaches to the ICO within the required time.

A message says my data was breached and I must log in via a link — is it real?

Be very cautious. A genuine notice tells you to sign in yourself by typing our address and never asks for your password. A link demanding login is a classic scam exploiting breach fear.

What should I do to protect myself now?

Use a unique password, turn on 2FA and alerts, and stay alert to phishing. If you're ever told your data was affected, follow the specific instructions in that official notice.

Funding for UK limited companies

Credit Corp lends to your company, not to you personally — short-term working capital with no personal guarantee. See what your business could access.