Dealing effectively with the consequences of data breaches

30.09.2026

Companies and digital platforms promote the security of their users’ data. Should a massive data leak or data breach occur, the question arises as to how this can be managed in order to rebuild the trust of users and customers and retain them on the respective platforms in the long term. After all, the general principle is that if data is misused, users will leave.

Prof. Hartmut Hoehle (University of Mannheim) has addressed this topic in several studies that provide guidance for managers of companies and digital platforms.

Key takeaways
  • More compensation doesn't always help more.
  • Compensation should comply with industry standards.
  • The perception of fairness is the crucial link between the company’s response and future customer behaviour.
  • On social media, users' outrage wanes over time.

When it comes to compensation, less is sometimes more

An important insight for companies: the ‘the more, the better’ approach to customer compensation can backfire when it comes to data breaches. Prof. Hartmut Hoehle’s research team investigated the hacker attack on Sony PlayStation in April 2011.

77 million customer accounts were affected, and names, addresses and potentially credit card details were in circulation. In the wake of this massive data breach, Sony offered a generous compensation package, but this led to mixed reactions. Whilst customers tend to view high levels of compensation positively when assessing ‘service quality’, the excessively generous compensation led to a decline in repurchase intention – that is, the active willingness to do business with the company again. According to the research, overcompensation leads to scepticism: customers then suspect that the breach was more serious than communicated or question the company’s previous profit margins. Furthermore, feelings of guilt can arise if the gift far exceeds the perceived damage, which strains the economic relationship.

The Psychology of Fairness

The investigation into the massive data breach at the US retailer Target in 2013 also illustrates that restoring customer loyalty requires a finely tuned approach.

This study shows that the perception of fairness is the crucial link between the company’s response and future customer behaviour. Customer loyalty is most effectively maintained when the compensation matches the expectations that have been formed exactly – neither falling short of them nor significantly exceeding them. It is not the absolute dollar amount that matters, but the perception of fairness in how the incident was handled. The researchers examined, on the one hand, whether the financial compensation was perceived as appropriate – that is, fair – and, on the other hand, how the process for dealing with the data breaches was structured. Was the handling of the matter transparent? Were meaningful measures proactively offered? The interaction itself was also assessed, namely whether customers were informed with respect and honesty. Analyses show that procedural justice often carries greater weight than material value. Whilst a discount is fleeting, a well-structured process (such as credit monitoring) signals that the company takes the customer’s long-term security seriously.

Procedural justice often carries greater weight than material value.

What does this mean for companies?

The studies show that a modern response framework must go far beyond IT solutions. It requires a precise calibration of communication and compensation that focuses on long-term relationship repair. Companies should not wait until a crisis strikes to take action. Regular surveys on hypothetical crisis scenarios help to assess their own customer base in advance, so that tailored compensation can be offered in the event of a crisis.

Furthermore, compensation should comply with industry standards. Any company that falls short of industry standards immediately loses legitimacy. And it is important that companies invest in the quality of their processes. In the event of a crisis, this does far more to ensure reliable customer loyalty than monetary compensation ever could.

Social media: a special case

What is particularly interesting about Hartmut Höhle’s research is that his findings show that different rules apply to social networks and digital platforms such as Facebook and the like in the event of data breaches. The findings of a study by an international team of researchers show that ‘leaving’ social networks following data breaches often remains a theoretical concept.  The 2018 Cambridge Analytica scandal exposed the misuse of 87 million users’ data on Facebook, yet despite global outrage and a $5 billion fine, the majority of users ignored the ‘delete’ button. Rather, it became apparent that the loss of trust had almost completely evaporated within six months. Instead, an ‘attitudinal regression’ occurs: users gradually change their stance on the scandal over time. Their outrage wanes and apparently fizzles out. The researchers attribute this to the high switching costs that leaving a social media platform would entail – such as the loss of years’ worth of contacts or painstakingly curated content. Humans’ psychological ability to adapt is so efficient in this context that it replaces genuine trust. Alongside the fundamental challenge to data protection and the need for statutory regulation of social media platforms highlighted by these findings, companies should bear in mind when considering the study that, ultimately, forced loyalty resulting from lock-in effects is not genuine brand loyalty, but merely the result of a lack of alternatives. As soon as (mandatory) interoperability between social media platforms is established and the ‘switching costs’ for users fall, genuine market pressure would be restored and the handling of data breaches would take on an entirely different character.

Evidence-based understanding of the challenges

The research by Prof. Hartmut Hoehle and his co-authors demonstrates one thing in any case: what determines the long-term consequences of a data breach is how customers perceive it in retrospect and react to it. Current research can provide important findings and practical insights here, helping companies to shape the management of customer relationships following a data breach and to recover from security incidents.