facebook-pixel

How to Report a Data Breach to the ICO: A Complete UK Guide

L
Lunyb Security Team
··10 min read

If your organisation has suffered a personal data breach, UK GDPR requires you to notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware — or risk fines of up to £17.5 million or 4% of global annual turnover. This guide walks you through exactly how to report a data breach to the ICO, what information you need, and how to stay compliant.

What Is a Personal Data Breach Under UK GDPR?

A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. In short, it's any event that compromises the confidentiality, integrity, or availability of personal information you hold.

Under UK GDPR and the Data Protection Act 2018, breaches fall into three broad categories:

  • Confidentiality breach — unauthorised or accidental disclosure of personal data (e.g. an email sent to the wrong recipient).
  • Integrity breach — unauthorised or accidental alteration of personal data.
  • Availability breach — accidental or unauthorised loss of access to, or destruction of, personal data (e.g. ransomware).

Examples of Reportable Breaches

  • A laptop containing customer records is stolen from an employee's car.
  • A phishing attack results in staff credentials being compromised.
  • An employee accidentally emails a spreadsheet of client data to the wrong distribution list.
  • A ransomware attack encrypts patient records at a healthcare provider.
  • A misconfigured cloud storage bucket exposes user data publicly.

Do You Actually Need to Report the Breach?

Not every breach requires notification. You must report a personal data breach to the ICO unless it is unlikely to result in a risk to the rights and freedoms of individuals. If in doubt, err on the side of reporting.

When You MUST Notify the ICO

Notification is required when the breach is likely to result in a risk to individuals — including risks such as:

  1. Discrimination or damage to reputation
  2. Financial loss or identity theft
  3. Loss of confidentiality of data protected by professional secrecy
  4. Any significant economic or social disadvantage

When You Must Also Notify Affected Individuals

If the breach is likely to result in a high risk to individuals' rights and freedoms, you must also inform those affected without undue delay. This threshold is higher than the ICO notification threshold.

When You Don't Need to Report

  • The data was strongly encrypted and the decryption key remains secure.
  • The incident had no realistic risk to individuals (e.g. an internal email misdirect that was immediately deleted).
  • You've taken subsequent measures that ensure the high risk is no longer likely to materialise.

Even if you decide not to report, you must document the breach internally, including the reasoning behind your decision.

The 72-Hour Rule Explained

The clock starts when you become aware of the breach — not when it happened. "Awareness" means you have a reasonable degree of certainty that a security incident has occurred that led to personal data being compromised.

You have 72 hours from that moment to notify the ICO. If you miss this deadline, you must provide reasons for the delay when you do submit your report. Late reporting is not automatically a breach of the law, but repeated or unjustified delays can lead to enforcement action.

Phased Reporting Is Allowed

You don't need all the facts to submit an initial report. The ICO explicitly permits phased notification: submit what you know within 72 hours, then supplement with further information as your investigation progresses.

How to Report a Data Breach to the ICO: Step-by-Step

Step 1: Contain and Assess the Breach

Before reporting, take immediate action to contain the incident. This might include revoking compromised credentials, isolating affected systems, recovering lost devices, or requesting recall of misdirected emails. Then assess the scope: what data, how many people, and what likely harm.

Step 2: Gather the Required Information

The ICO will ask for details including:

  • Your organisation's name and contact details
  • Details of your Data Protection Officer (if you have one)
  • A description of the breach: what happened, when, and how you discovered it
  • The categories and approximate number of individuals affected
  • The categories and approximate number of personal data records concerned
  • The likely consequences of the breach
  • Measures taken or proposed to address the breach and mitigate harm

Step 3: Choose Your Reporting Method

There are three ways to notify the ICO:

  1. Online reporting tool — the fastest route, available on the ICO website at ico.org.uk. This is the recommended method for most breaches.
  2. Telephone helpline — call 0303 123 1113 (Monday to Friday, 9am–5pm). Useful for urgent or high-severity incidents where you want to speak to a caseworker directly.
  3. Post — send a written report to the ICO's Wilmslow office. This is rarely appropriate given the 72-hour deadline.

Step 4: Submit Your Report

Complete the ICO's Personal Data Breach Notification Form. Be honest and thorough — the ICO looks favourably on organisations that demonstrate transparency and cooperation. You'll receive a case reference number after submission.

Step 5: Notify Affected Individuals (If Required)

If the breach poses a high risk, contact affected individuals directly. Your communication should be in clear, plain language and include:

  • A description of the breach
  • Contact details of your DPO or a point of contact
  • Likely consequences
  • Measures taken to address the breach
  • Practical advice on how they can protect themselves (e.g. resetting passwords, monitoring bank accounts)

Step 6: Document Everything

Whether or not you notify the ICO, you must maintain an internal breach register documenting:

  • The facts of the breach
  • Its effects
  • Remedial action taken
  • Your decision-making rationale (particularly if you chose not to report)

ICO Reporting Timeline at a Glance

TimeframeAction RequiredApplies To
Immediately upon awarenessContain breach, begin internal investigationAll breaches
Within 72 hoursNotify the ICOBreaches likely to result in risk to individuals
Without undue delayNotify affected individualsBreaches likely to result in high risk
OngoingProvide follow-up information to ICOWhere full details unavailable at initial notification
PermanentlyDocument in internal breach registerAll breaches (reported or not)

What Happens After You Report?

Once the ICO receives your notification, a caseworker will review it. The outcome depends on the severity and circumstances.

Possible Outcomes

  • No further action — the ICO acknowledges the report and closes the case. This is common for well-handled, lower-impact breaches.
  • Request for further information — the ICO may ask follow-up questions to understand the incident better.
  • Formal investigation — reserved for serious breaches or where systemic failures are suspected.
  • Regulatory action — could include a reprimand, enforcement notice, or monetary penalty.

Potential Penalties

The ICO can issue fines up to £17.5 million or 4% of total worldwide annual turnover, whichever is higher. In practice, fines of this magnitude are rare and typically reserved for large organisations with serious, systemic failings. Most reports result in guidance rather than penalties.

Common Mistakes When Reporting a Data Breach

1. Delaying Because You Don't Have All the Facts

Many organisations miss the 72-hour deadline because they're still investigating. Remember: phased reporting is allowed. Submit what you know and update later.

2. Under-reporting the Scope

Being vague or minimising the impact can backfire if the ICO later discovers the breach was larger than reported. Transparency builds trust with the regulator.

3. Failing to Notify Individuals

Reporting to the ICO doesn't automatically satisfy your obligation to inform affected individuals when high risk is present. These are two separate duties.

4. Poor Internal Documentation

If the ICO later audits you, missing or incomplete breach records are themselves a compliance failure. Keep detailed logs of every incident, even minor ones.

5. No Incident Response Plan

Trying to figure out reporting procedures in the middle of a crisis wastes precious hours. Have a documented plan ready before you need it.

How to Prevent Data Breaches

Prevention is always better than reporting. Consider these fundamental safeguards:

  • Encrypt sensitive data at rest and in transit — encrypted data breaches often don't require notification.
  • Enforce multi-factor authentication across all business-critical accounts.
  • Train staff regularly on phishing, social engineering, and secure data handling.
  • Restrict access to personal data on a strict need-to-know basis.
  • Use secure link-sharing tools when distributing URLs containing sensitive parameters. A privacy-focused shortener like Lunyb can help mask tracking parameters and reduce accidental exposure of query-string data. For a deeper look, see our honest Lunyb review.
  • Patch and update systems promptly to close known vulnerabilities.
  • Run regular security audits and tabletop breach-response exercises.

For marketing teams handling customer-facing links, choosing a compliant URL management platform matters. Our 2026 buyer's guide to URL shorteners and Rebrandly review compare privacy and security features across leading providers.

Building an Incident Response Plan

A solid incident response plan should include the following elements:

  1. Detection procedures — how breaches are identified and escalated.
  2. Response team — named individuals responsible for containment, communications, legal advice, and ICO liaison.
  3. Assessment criteria — a framework for judging risk levels and reporting thresholds.
  4. Communication templates — pre-approved wording for internal alerts, ICO notifications, and public statements.
  5. Recovery steps — how systems are restored and services resumed.
  6. Post-incident review — lessons learned and improvements to controls.

Frequently Asked Questions

What is the deadline to report a data breach to the ICO?

You must notify the ICO within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to individuals' rights and freedoms. If you miss the deadline, you can still report but must explain the delay.

Do I need to report every data breach to the ICO?

No. You only need to report breaches likely to result in a risk to individuals. Minor incidents — such as an internal email sent in error and immediately recalled with no data exposure — typically don't require notification, but you must still document them internally.

What information does the ICO need in a breach report?

The ICO requires a description of the breach, categories and approximate numbers of individuals and records affected, likely consequences, measures taken to address the breach, and contact details for your organisation and DPO. If you don't have all the facts within 72 hours, submit what you know and update later.

Can I be fined for reporting a data breach?

The ICO does not fine organisations simply for reporting. Penalties are levied for the underlying failures that caused the breach — such as poor security practices or systemic non-compliance. Reporting transparently and cooperating with the ICO typically reduces the risk of enforcement action.

What's the difference between notifying the ICO and notifying affected individuals?

You must notify the ICO within 72 hours if the breach poses any risk to individuals. You must also notify the affected individuals directly — but only when the breach poses a high risk to their rights and freedoms. The threshold for individual notification is higher, and the wording of the communication must help individuals protect themselves.

Does encrypted data still count as a breach?

If personal data is exposed but was strongly encrypted and the decryption key remains secure and uncompromised, the breach is unlikely to pose a risk to individuals. In this case, ICO notification may not be required — but you must still record the incident internally.

Final Thoughts

Reporting a data breach to the ICO can feel daunting, but with clear procedures, prompt action, and honest communication, it's entirely manageable. The 72-hour rule exists to protect individuals — and demonstrating that your organisation takes that responsibility seriously is the best defence against regulatory action.

Prepare your incident response plan now, train your teams, and treat every near-miss as an opportunity to strengthen your data protection posture. When a real breach occurs, you'll be ready.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles