facebook-pixel

How to Report a Data Breach to the ICO: A Complete UK Guide

L
Lunyb Security Team
··9 min read

If your organisation suffers a personal data breach in the UK, you may have a legal duty to report it to the Information Commissioner's Office (ICO) within 72 hours. Failure to do so can result in significant fines, reputational damage, and enforcement action. This guide walks you through exactly how to report a data breach to the ICO, when reporting is required, and what information you need to prepare.

What Is a Personal Data Breach Under UK GDPR?

A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. Under the UK GDPR and the Data Protection Act 2018, breaches are not limited to hacking incidents — they include a wide range of scenarios that many organisations overlook.

Common Examples of Data Breaches

  • An employee losing a laptop, phone, or USB stick containing personal data
  • Sending an email with personal information to the wrong recipient
  • Ransomware or malware attacks that encrypt or exfiltrate personal data
  • Unauthorised access to databases or cloud storage
  • Paper records lost, stolen, or improperly disposed of
  • Website vulnerabilities exposing customer records
  • Accidental publication of personal data on a public webpage

When Must You Report a Breach to the ICO?

You must report a notifiable personal data breach to the ICO within 72 hours of becoming aware of it. The clock starts from the moment you have a reasonable degree of certainty that a security incident has occurred which led to personal data being compromised — not from the moment the breach itself happened.

The 72-Hour Rule Explained

The 72-hour window includes weekends and bank holidays. If you cannot provide all the details within 72 hours, you should still submit an initial report and provide further information in phases as it becomes available. The ICO expressly allows phased notification.

When You Do NOT Need to Report

You are not required to notify the ICO if the breach is unlikely to result in a risk to the rights and freedoms of individuals. For example, if a stolen laptop was fully encrypted with a strong password and no data could be accessed, notification may not be needed — but you must still document your decision and reasoning.

Step-by-Step: How to Report a Data Breach to the ICO

The ICO offers several ways to report a breach depending on your organisation type and the severity of the incident. Here is the process most private-sector organisations should follow.

  1. Contain the breach. Before reporting, take immediate steps to stop the breach from continuing. Disconnect affected systems, revoke compromised credentials, or recover lost devices where possible.
  2. Assess the risk. Determine what personal data was affected, how many individuals are impacted, and what the potential consequences are (financial loss, identity theft, discrimination, reputational damage).
  3. Document everything. Even breaches that don't need reporting must be recorded internally. The ICO can ask to see this log.
  4. Gather the required information. Prepare details about the nature of the breach, categories and approximate numbers of data subjects affected, likely consequences, and measures taken.
  5. Submit the report. Use the ICO's online self-assessment tool or call their breach helpline for urgent incidents.
  6. Notify affected individuals. If the breach is likely to result in a high risk, you must also inform the affected individuals without undue delay.
  7. Follow up. Provide additional information to the ICO as your investigation progresses.

How to Submit the Report

There are three main routes to notify the ICO:

  • Online form: Visit ico.org.uk and use the personal data breach self-assessment and reporting tool. This is the preferred method for most organisations.
  • Telephone helpline: Call the ICO on 0303 123 1113 (Monday to Friday, 9am to 5pm). Use this for urgent or complex incidents.
  • Live chat: Available through the ICO website during business hours.

What Information Do You Need to Provide?

The ICO requires a specific set of information when you notify them of a breach. Preparing this in advance can save critical time during a live incident.

Required InformationDetails to Include
Nature of the breachWhat happened, when, and how it was discovered
Categories of dataNames, addresses, financial details, special category data, etc.
Number of individuals affectedApproximate figures if exact numbers are unknown
Categories of records affectedNumber and type of personal data records
Likely consequencesRisk of financial loss, identity theft, distress, discrimination
Measures takenContainment actions and steps to mitigate harm
Data Protection Officer contactDPO name and contact details if applicable

When to Notify Affected Individuals

Notifying the ICO is only part of your obligation. If a breach is likely to result in a high risk to the rights and freedoms of individuals, you must also inform those individuals directly and without undue delay.

What the Notification Must Include

  • A clear description of the breach in plain language
  • The name and contact details of your DPO or point of contact
  • The likely consequences of the breach
  • Measures taken or proposed to address the breach
  • Advice on steps individuals can take to protect themselves

When You May Be Exempt

You do not have to notify individuals directly if:

  • You have implemented appropriate technical measures (such as strong encryption) that render the data unintelligible to any unauthorised person
  • You have taken subsequent measures to ensure the high risk is no longer likely to materialise
  • It would involve disproportionate effort — in which case a public communication is acceptable

Penalties for Failing to Report a Breach

The ICO has significant enforcement powers. Failure to notify a reportable breach within 72 hours can itself constitute a violation, separate from the underlying breach.

Fines Under UK GDPR

The ICO can issue administrative fines of up to £8.7 million or 2% of global annual turnover (whichever is higher) for breach notification failures. For more serious violations, fines can reach £17.5 million or 4% of global annual turnover.

Other Consequences

  • Enforcement notices requiring specific corrective actions
  • Audits by the ICO
  • Reputational damage and loss of customer trust
  • Civil claims from affected individuals
  • Criminal prosecution for related offences (e.g., unlawful obtaining of personal data)

Best Practices to Prepare for Breach Reporting

The best time to plan for a data breach is before one happens. Organisations that prepare in advance report faster, more accurately, and often receive more lenient treatment from regulators.

1. Create an Incident Response Plan

Document a clear, step-by-step plan that identifies who is responsible for detecting, assessing, containing, and reporting breaches. Include contact details for your DPO, IT security team, legal counsel, and executive stakeholders.

2. Maintain a Breach Register

UK GDPR requires you to document all breaches, even those you don't report. Include the facts, effects, and remedial action taken. This register must be available for inspection by the ICO.

3. Train Your Staff

Most breaches involve human error. Regular training helps employees recognise incidents early and know how to escalate them. Include phishing simulations, secure email practices, and device handling.

4. Use Secure Tools for Sharing Information

When sharing links, files, or communications internally and externally, use tools that provide analytics, expiry, and access controls. For sharing sensitive campaign links or internal documentation, a privacy-focused link management platform like Lunyb can add a layer of visibility over who is clicking what and when, which supports both security monitoring and forensic investigations after an incident.

5. Encrypt Data at Rest and in Transit

Strong encryption significantly reduces the risk profile of a breach and, in many cases, removes the need to notify affected individuals directly. Combine this with strong access controls and multi-factor authentication.

Common Mistakes to Avoid

  • Waiting too long to report. Even if you don't have all the facts, an initial notification within 72 hours is essential.
  • Underestimating the breach. Small incidents can have significant consequences — always assess the risk properly.
  • Failing to document decisions. If you decide not to report, write down why. The ICO expects to see your reasoning.
  • Notifying individuals prematurely. Poorly-worded notifications can cause panic. Prepare clear, factual communications.
  • Not learning from the incident. Conduct a post-incident review and update your policies, controls, and training.

Special Cases: Processors and Third Parties

If you are a data processor (rather than the controller), you must notify the controller without undue delay after becoming aware of a breach. The controller is then responsible for notifying the ICO. Your contracts should clearly define breach notification timelines and responsibilities — typically within 24 to 48 hours to give the controller time to meet their own 72-hour deadline.

What Happens After You Report?

Once you submit a notification, the ICO will review your report and may take several actions:

  1. Acknowledge receipt and assign a case reference
  2. Request further information or clarification
  3. Provide guidance on next steps
  4. Open a formal investigation for serious incidents
  5. Issue enforcement action, monetary penalties, or reprimands where appropriate
  6. Close the case with no further action if satisfied

Cooperating fully, being transparent, and demonstrating that you have taken meaningful remedial steps will typically result in more favourable outcomes.

Further Reading

For more guidance on privacy, security, and online tools, explore these related resources:

Frequently Asked Questions

What is the 72-hour deadline for reporting a data breach to the ICO?

The 72-hour clock starts from the moment you become aware of the breach — meaning when you have a reasonable degree of certainty that a security incident has affected personal data. The deadline includes weekends and bank holidays. If you cannot report within 72 hours, you must explain the delay when you eventually notify the ICO.

Do I need to report every data breach to the ICO?

No. You only need to report breaches that are likely to result in a risk to the rights and freedoms of individuals. However, you must document every breach internally, regardless of whether it is reportable, and be able to justify your decision if the ICO asks.

What happens if I miss the 72-hour deadline?

You should still report the breach as soon as possible and explain the reasons for the delay. Missing the deadline is a separate infringement that can attract fines of up to £8.7 million or 2% of global annual turnover. However, cooperating fully and demonstrating good faith often leads to more lenient outcomes than trying to conceal the breach.

Can I report a breach anonymously?

Organisations that suffer a breach cannot report anonymously — the ICO requires the controller's details as part of statutory notification. However, individuals who wish to report concerns about how an organisation has handled their data can contact the ICO directly, and whistleblowers may have additional protections.

What is the difference between notifying the ICO and notifying affected individuals?

Notifying the ICO is required within 72 hours whenever a breach is likely to result in any risk to individuals. Notifying the individuals themselves is only required when the breach is likely to result in a high risk. Different thresholds, different content, and different timelines apply, so treat them as two distinct obligations.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles