The Data Protection Act is a law, so someone who breaches it has acted illegally. Ergo it may be a criminal offence. For example, call centres cold calling without permissions, selling on personal data without permission, failing to secure personal data - all can be punished with significant fines.
Without knowing what the breach was, it's impossible to really answer your question. In fact first question is to determine whether it genuinely is a breach, that may not always be clear cut.
Similarly harassment, it depends on the nature and extent of the activity as to whether it meets the legal definition of harassment. "Harrassment" is illegal, but whether your experience meets that definition of "harrassment" may be subjective, in some cases.