facebook-pixel

How to Report a Data Breach to the ICO: A Complete UK Guide

L
Lunyb Security Team
··10 min read

If your organisation has suffered a personal data breach, you may be legally required to notify the Information Commissioner's Office (ICO) within 72 hours. This guide explains exactly how to report a data breach to the ICO, when notification is mandatory under UK GDPR, and what information you need to prepare before you file.

What Is a Personal Data Breach Under UK GDPR?

A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. This definition, drawn directly from Article 4(12) of the UK GDPR, is broader than many organisations realise.

Common examples include:

  • A lost or stolen laptop containing customer records
  • Ransomware encrypting a database with employee information
  • An email containing personal data sent to the wrong recipient
  • A misconfigured cloud storage bucket exposing files to the public internet
  • An employee accessing records they had no business need to view
  • A phishing attack that compromised login credentials

Crucially, a breach isn't just about hackers. Accidental loss, human error, and internal misuse all count. The moment you become aware that personal data has been compromised, the regulatory clock starts ticking.

When Must You Report a Data Breach to the ICO?

Under Article 33 of the UK GDPR, data controllers must notify the ICO of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals.

The Risk Threshold Test

Not every breach requires notification. You must assess the likelihood and severity of harm to affected individuals. Consider factors such as:

  • Type of data: Special category data (health, biometric, political opinions) or financial details raise the risk significantly.
  • Volume: A breach affecting 50,000 records is inherently riskier than one affecting five.
  • Identifiability: Is the data easily linked to individuals, or is it pseudonymised?
  • Consequences: Could the breach lead to identity theft, financial loss, discrimination, reputational damage, or physical harm?
  • Vulnerability of individuals: Children, patients, and vulnerable adults require heightened protection.

Notification Requirements at a Glance

Risk LevelNotify ICO?Notify Individuals?Document Internally?
No risk to rights and freedomsNoNoYes
Risk to rights and freedomsYes (within 72 hours)Only if high riskYes
High risk to rights and freedomsYes (within 72 hours)Yes, without undue delayYes

Even if you decide not to notify the ICO, you must keep an internal record of every breach, including the facts, effects, and remedial action taken. The ICO can request this record at any time.

The 72-Hour Deadline Explained

The 72-hour window begins when you become "aware" of the breach, not when the incident first occurred. Awareness means you have a reasonable degree of certainty that a security incident has led to personal data being compromised.

The clock includes weekends and bank holidays. If you cannot provide all the information at once, the UK GDPR allows for phased reporting: you can submit an initial notification with the details you have and follow up with additional information as your investigation progresses.

If you miss the 72-hour deadline, you must still report the breach but you'll need to explain the reasons for the delay. Late reporting is a factor the ICO considers when deciding whether to take enforcement action.

How to Report a Data Breach to the ICO: Step-by-Step

Step 1: Contain the Breach

Before you file anything, take immediate action to stop the breach getting worse. Isolate affected systems, revoke compromised credentials, recall misdirected emails where possible, and preserve evidence for forensic analysis.

Step 2: Assemble Your Breach Response Team

Bring together your Data Protection Officer (DPO), IT security lead, legal counsel, and a senior decision-maker. If you use external DPO services or a solicitor, contact them within the first few hours.

Step 3: Assess the Risk

Document what happened, what data is affected, how many people are involved, and what the likely consequences are. This assessment determines whether notification is required.

Step 4: Gather the Required Information

The ICO's breach notification form asks for specific details. Prepare the following before you start filing:

  1. The nature of the breach (confidentiality, integrity, availability)
  2. Categories and approximate number of data subjects affected
  3. Categories and approximate number of records affected
  4. Name and contact details of your DPO or breach contact
  5. Likely consequences of the breach
  6. Measures taken or proposed to address the breach and mitigate harm
  7. When the breach occurred and when you became aware of it

Step 5: Submit the Notification

You have several ways to report:

  • Online: Use the ICO's personal data breach reporting form at ico.org.uk. This is the fastest and most reliable method.
  • Phone: Call the ICO helpline on 0303 123 1113 (Monday to Friday, 9am to 5pm). Recommended for urgent, complex, or high-risk breaches.
  • Post: Only appropriate for follow-up or supplementary information, not for meeting the 72-hour deadline.

Step 6: Notify Affected Individuals (If Required)

Where a breach is likely to result in a high risk to individuals' rights and freedoms, you must communicate the breach to those individuals without undue delay. The notice must be in clear, plain language and must include:

  • The nature of the breach
  • Contact details of your DPO or breach contact point
  • Likely consequences
  • Measures taken or proposed
  • Practical advice on how they can protect themselves

Step 7: Document Everything

Maintain a complete breach register showing the incident, your risk assessment, decisions made, timelines, communications, and remedial measures. This is a legal requirement and your first line of defence in any subsequent ICO investigation.

What Happens After You Report?

Once you've submitted a breach notification, the ICO will acknowledge receipt and assign a case reference. Depending on the severity, one of several outcomes is possible:

  • No further action: For lower-risk breaches with proportionate response, the ICO may simply close the case.
  • Advice and guidance: The ICO may issue recommendations for improving your data protection practices.
  • Formal investigation: For serious or systemic breaches, the ICO may open a full investigation, request additional evidence, and interview relevant staff.
  • Enforcement action: In the most serious cases, the ICO can issue reprimands, enforcement notices, or monetary penalties of up to £17.5 million or 4% of global annual turnover, whichever is higher.

Common Mistakes to Avoid When Reporting

1. Waiting Until You Have All the Facts

Don't delay the initial notification because your investigation isn't complete. File what you know within 72 hours and update the ICO as more information becomes available.

2. Underestimating the Risk

Organisations sometimes convince themselves a breach is "minor" to avoid reporting. If in doubt, report. The ICO takes a much dimmer view of unreported breaches discovered later than of over-cautious notifications.

3. Failing to Notify Individuals

Reporting to the ICO does not remove your separate obligation to inform affected individuals when the risk is high. These are two distinct duties.

4. Poor Internal Record-Keeping

Even non-reportable breaches must be logged. Missing breach registers are one of the first things ICO investigators ask for.

5. Sharing Sensitive Breach Details Insecurely

When coordinating with legal counsel, forensic teams, or affected partners, use encrypted channels. Sending breach summaries or evidence through unsecured links is itself a data protection failure. Where you need to share links to incident documentation or portals, use a privacy-conscious link management service like Lunyb to create controlled, trackable URLs rather than exposing raw file paths.

Reporting Requirements for Data Processors

If you're a data processor (rather than a controller), your obligations are different. You must notify the data controller without undue delay after becoming aware of a personal data breach. The controller then decides whether to notify the ICO.

Your contract with the controller (the Article 28 data processing agreement) should specify exactly how and when you notify them. Many controllers require notification within 24 hours or less, giving them time to make their own 72-hour deadline.

Special Cases: Sector-Specific Reporting

Some organisations have additional reporting obligations beyond the ICO:

SectorAdditional RegulatorFramework
Financial servicesFCA and PRASYSC and operational resilience rules
Telecoms and digital infrastructureOfcom / ICOPECR and NIS Regulations
Health and social careNHS Digital / CQCData Security and Protection Toolkit
Essential servicesCompetent authority under NISNIS Regulations 2018
Payment servicesFCAPSD2 major incident reporting

A single incident may trigger multiple reporting obligations to different regulators, each with its own timeframe. Map your reporting duties in advance as part of your incident response plan.

How to Prepare Before a Breach Happens

The best time to prepare for a data breach is long before one occurs. Organisations that respond well share several characteristics:

  1. Documented incident response plan: A written playbook covering detection, containment, assessment, notification, and recovery.
  2. Clear roles and escalation paths: Everyone knows who decides what and who to call at 2am on a Sunday.
  3. Pre-drafted communication templates: Skeleton notifications to the ICO, affected individuals, and internal stakeholders.
  4. Regular tabletop exercises: Simulated breaches to test the plan under realistic pressure.
  5. Data mapping: Knowing where personal data lives, so you can quickly assess scope during an incident.
  6. Security controls: Encryption, access controls, logging, and network segmentation to reduce both the likelihood and impact of breaches.

For businesses that share links containing customer or partner data during incident response, consider how those links themselves are managed. Using privacy-first tools to shorten and track sensitive URLs prevents accidental exposure and provides an audit trail. Our guide to the best URL shorteners covers options that support enterprise privacy needs.

Frequently Asked Questions

What is the 72-hour rule for data breaches in the UK?

Under Article 33 of the UK GDPR, data controllers must report a notifiable personal data breach to the ICO within 72 hours of becoming aware of it. The clock starts when you have a reasonable degree of certainty that a security incident has affected personal data, and it includes weekends and public holidays.

What happens if I don't report a data breach to the ICO?

Failing to report a notifiable breach is a separate infringement of the UK GDPR and can attract fines of up to £8.7 million or 2% of global annual turnover. If the underlying breach also involved wider compliance failures, higher fines of up to £17.5 million or 4% of turnover may apply. Non-reporting also damages regulatory trust and typically leads to more intrusive investigation.

Do I need to report a breach if the data was encrypted?

If personal data was protected by strong encryption and the decryption keys were not compromised, the breach may be unlikely to result in a risk to individuals, meaning ICO notification may not be required. However, you must still document the incident internally and assess each case on its facts. Encryption does not automatically remove the reporting obligation.

Can I report a data breach anonymously to the ICO?

Organisations reporting their own breaches cannot do so anonymously; the ICO needs to identify the controller. However, if you're an individual reporting concerns about how an organisation has handled a breach, or blowing the whistle on data protection failings, the ICO does accept confidential reports through its dedicated channels.

How long does the ICO take to respond to a breach notification?

The ICO typically acknowledges breach notifications within a few working days. The subsequent handling depends on severity: many cases are closed within weeks with advice, while serious investigations can take months or even more than a year. Maintaining prompt, transparent communication with the ICO throughout is essential.

Final Thoughts

Reporting a data breach to the ICO is not just a legal box-ticking exercise. It's a signal to regulators, customers, and the wider market that your organisation takes personal data seriously and responds responsibly when things go wrong. The organisations that fare best are those that prepare in advance, respond quickly, communicate honestly, and learn from every incident.

If you're building or reviewing your incident response process, start by mapping your data, documenting your notification workflow, and training your team. The 72-hour deadline is tight but manageable when you know exactly what to do.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles