Barclaycard complaint
Barclaycard offered £200 ($264) and an apology after a reader's email address was linked to a namesake's credit card account. Barclaycard Website

Barclaycard has blamed 'human error' after a Manchester reader spent more than a year receiving emails, and eventually overdue payment notices, for a credit card account that belonged to someone else. The bank took exactly 13 months from the first complaint to remove the reader's email address from the account.

The reader, identified only by the initials PG, took the problem to The Guardian's consumer column, which published the case on 16 September 2026.

It began with an email announcing that PG's credit card 'application was successful'. PG had not applied for a card and reported the email to Barclaycard straight away. More emails followed, along with repeated calls to customer service, where staff said the problem was a typing mistake rather than fraud and gave assurances that the email address would be deleted.

The address was never deleted, and the most recent emails warned that the latest payment on the account was overdue.

The account belonged to another Barclaycard customer. 'The customer who holds this account has the same name as me but with a slightly different spelling,' PG wrote. With PG's email address attached to that account, every message meant for the cardholder, payment reminders included, went to the wrong person.

PG asked the column to get Barclaycard to remove the address and 'give my namesake a bell.'

How One Barclaycard Mistake Affected Two People

The column pointed out that the cardholder had been exposed too, since a stranger now had the other man's email address and knew he was in debt. It described the mix-up as 'such a small mistake, so easy to fix,' and noted how unnerving the increasingly urgent reminders had been for PG.

Barclaycard blamed 'human error'. It removed PG's email address exactly 13 months after the problem was first reported, apologised for the delay, and offered £200 ($264) for the 'inconvenience'. The published response did not say whether the bank had contacted the cardholder, as PG had asked.

Readers Question Whether Barclaycard Broke Data Protection Rules

Below the column, readers turned to the law. In a comment selected as a Guardian Pick, one argued that a credit card statement sent to the wrong person by mistake 'would normally be considered a personal data breach under the UK GDPR and the Data Protection Act 2018.' The same reader felt £200 was probably adequate but said the breach should still be reported to the Information Commissioner's Office. Another commenter wrote: 'This is surely notifiable to ICO?'

The ICO defines a personal data breach as including the accidental or unauthorised disclosure of personal data. Organisations must report a breach to the regulator within 72 hours of becoming aware of it if it is likely to pose a risk to people's rights and freedoms.

Others focused on the strain. One wrote that 'many of us find this sort of thing distressing,' adding that default notices are worded to cause stress and push people into paying quickly. Another said that for almost 20 years, a man with a very similar email address had meant they received his job offers, invoices, and golf membership reminders, and were even chased by HMRC when it wanted him.

What to Do if You Receive Someone Else's Credit Card Bills

UK data protection law gives people the right to have inaccurate personal data corrected or deleted. The ICO says an organisation has one month to respond, extendable by two months in some cases, and advises putting phone requests in writing.

Since 19 June 2026, the Data (Use and Access) Act 2025 has required every organisation to have a data protection complaints process and to acknowledge complaints within 30 days. If that fails, people can complain to the ICO, which asks for complaints within three months of the last contact with the organisation. The ICO cannot award compensation, but people can claim it directly from an organisation if they have suffered damage because it broke data protection law.

For complaints about financial firms, the Financial Ombudsman Service's compensation guidance says £100 to £300 ($132 to $397) may be fair for repeated small errors, or a larger single mistake, that take reasonable effort to resolve.

Awards of over £750 and up to around £1,500 ($991 to $1,983) may apply where serious disruption is felt over many months, sometimes more than a year.