How to Report a Data Breach to the ICO: A Complete UK Guide
If your organisation has suffered a personal data breach, you may be legally required to notify the Information Commissioner's Office (ICO) within 72 hours. This guide explains exactly how to report a data breach to the ICO, when notification is mandatory under UK GDPR, and what information you need to prepare before you file.
What Is a Personal Data Breach Under UK GDPR?
A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. This definition, drawn directly from Article 4(12) of the UK GDPR, is broader than many organisations realise.
Common examples include:
- A lost or stolen laptop containing customer records
- Ransomware encrypting a database with employee information
- An email containing personal data sent to the wrong recipient
- A misconfigured cloud storage bucket exposing files to the public internet
- An employee accessing records they had no business need to view
- A phishing attack that compromised login credentials
Crucially, a breach isn't just about hackers. Accidental loss, human error, and internal misuse all count. The moment you become aware that personal data has been compromised, the regulatory clock starts ticking.
When Must You Report a Data Breach to the ICO?
Under Article 33 of the UK GDPR, data controllers must notify the ICO of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals.
The Risk Threshold Test
Not every breach requires notification. You must assess the likelihood and severity of harm to affected individuals. Consider factors such as:
- Type of data: Special category data (health, biometric, political opinions) or financial details raise the risk significantly.
- Volume: A breach affecting 50,000 records is inherently riskier than one affecting five.
- Identifiability: Is the data easily linked to individuals, or is it pseudonymised?
- Consequences: Could the breach lead to identity theft, financial loss, discrimination, reputational damage, or physical harm?
- Vulnerability of individuals: Children, patients, and vulnerable adults require heightened protection.
Notification Requirements at a Glance
| Risk Level | Notify ICO? | Notify Individuals? | Document Internally? |
|---|---|---|---|
| No risk to rights and freedoms | No | No | Yes |
| Risk to rights and freedoms | Yes (within 72 hours) | Only if high risk | Yes |
| High risk to rights and freedoms | Yes (within 72 hours) | Yes, without undue delay | Yes |
Even if you decide not to notify the ICO, you must keep an internal record of every breach, including the facts, effects, and remedial action taken. The ICO can request this record at any time.
The 72-Hour Deadline Explained
The 72-hour window begins when you become "aware" of the breach, not when the incident first occurred. Awareness means you have a reasonable degree of certainty that a security incident has led to personal data being compromised.
The clock includes weekends and bank holidays. If you cannot provide all the information at once, the UK GDPR allows for phased reporting: you can submit an initial notification with the details you have and follow up with additional information as your investigation progresses.
If you miss the 72-hour deadline, you must still report the breach but you'll need to explain the reasons for the delay. Late reporting is a factor the ICO considers when deciding whether to take enforcement action.
How to Report a Data Breach to the ICO: Step-by-Step
Step 1: Contain the Breach
Before you file anything, take immediate action to stop the breach getting worse. Isolate affected systems, revoke compromised credentials, recall misdirected emails where possible, and preserve evidence for forensic analysis.
Step 2: Assemble Your Breach Response Team
Bring together your Data Protection Officer (DPO), IT security lead, legal counsel, and a senior decision-maker. If you use external DPO services or a solicitor, contact them within the first few hours.
Step 3: Assess the Risk
Document what happened, what data is affected, how many people are involved, and what the likely consequences are. This assessment determines whether notification is required.
Step 4: Gather the Required Information
The ICO's breach notification form asks for specific details. Prepare the following before you start filing:
- The nature of the breach (confidentiality, integrity, availability)
- Categories and approximate number of data subjects affected
- Categories and approximate number of records affected
- Name and contact details of your DPO or breach contact
- Likely consequences of the breach
- Measures taken or proposed to address the breach and mitigate harm
- When the breach occurred and when you became aware of it
Step 5: Submit the Notification
You have several ways to report:
- Online: Use the ICO's personal data breach reporting form at ico.org.uk. This is the fastest and most reliable method.
- Phone: Call the ICO helpline on 0303 123 1113 (Monday to Friday, 9am to 5pm). Recommended for urgent, complex, or high-risk breaches.
- Post: Only appropriate for follow-up or supplementary information, not for meeting the 72-hour deadline.
Step 6: Notify Affected Individuals (If Required)
Where a breach is likely to result in a high risk to individuals' rights and freedoms, you must communicate the breach to those individuals without undue delay. The notice must be in clear, plain language and must include:
- The nature of the breach
- Contact details of your DPO or breach contact point
- Likely consequences
- Measures taken or proposed
- Practical advice on how they can protect themselves
Step 7: Document Everything
Maintain a complete breach register showing the incident, your risk assessment, decisions made, timelines, communications, and remedial measures. This is a legal requirement and your first line of defence in any subsequent ICO investigation.
What Happens After You Report?
Once you've submitted a breach notification, the ICO will acknowledge receipt and assign a case reference. Depending on the severity, one of several outcomes is possible:
- No further action: For lower-risk breaches with proportionate response, the ICO may simply close the case.
- Advice and guidance: The ICO may issue recommendations for improving your data protection practices.
- Formal investigation: For serious or systemic breaches, the ICO may open a full investigation, request additional evidence, and interview relevant staff.
- Enforcement action: In the most serious cases, the ICO can issue reprimands, enforcement notices, or monetary penalties of up to £17.5 million or 4% of global annual turnover, whichever is higher.
Common Mistakes to Avoid When Reporting
1. Waiting Until You Have All the Facts
Don't delay the initial notification because your investigation isn't complete. File what you know within 72 hours and update the ICO as more information becomes available.
2. Underestimating the Risk
Organisations sometimes convince themselves a breach is "minor" to avoid reporting. If in doubt, report. The ICO takes a much dimmer view of unreported breaches discovered later than of over-cautious notifications.
3. Failing to Notify Individuals
Reporting to the ICO does not remove your separate obligation to inform affected individuals when the risk is high. These are two distinct duties.
4. Poor Internal Record-Keeping
Even non-reportable breaches must be logged. Missing breach registers are one of the first things ICO investigators ask for.
5. Sharing Sensitive Breach Details Insecurely
When coordinating with legal counsel, forensic teams, or affected partners, use encrypted channels. Sending breach summaries or evidence through unsecured links is itself a data protection failure. Where you need to share links to incident documentation or portals, use a privacy-conscious link management service like Lunyb to create controlled, trackable URLs rather than exposing raw file paths.
Reporting Requirements for Data Processors
If you're a data processor (rather than a controller), your obligations are different. You must notify the data controller without undue delay after becoming aware of a personal data breach. The controller then decides whether to notify the ICO.
Your contract with the controller (the Article 28 data processing agreement) should specify exactly how and when you notify them. Many controllers require notification within 24 hours or less, giving them time to make their own 72-hour deadline.
Special Cases: Sector-Specific Reporting
Some organisations have additional reporting obligations beyond the ICO:
| Sector | Additional Regulator | Framework |
|---|---|---|
| Financial services | FCA and PRA | SYSC and operational resilience rules |
| Telecoms and digital infrastructure | Ofcom / ICO | PECR and NIS Regulations |
| Health and social care | NHS Digital / CQC | Data Security and Protection Toolkit |
| Essential services | Competent authority under NIS | NIS Regulations 2018 |
| Payment services | FCA | PSD2 major incident reporting |
A single incident may trigger multiple reporting obligations to different regulators, each with its own timeframe. Map your reporting duties in advance as part of your incident response plan.
How to Prepare Before a Breach Happens
The best time to prepare for a data breach is long before one occurs. Organisations that respond well share several characteristics:
- Documented incident response plan: A written playbook covering detection, containment, assessment, notification, and recovery.
- Clear roles and escalation paths: Everyone knows who decides what and who to call at 2am on a Sunday.
- Pre-drafted communication templates: Skeleton notifications to the ICO, affected individuals, and internal stakeholders.
- Regular tabletop exercises: Simulated breaches to test the plan under realistic pressure.
- Data mapping: Knowing where personal data lives, so you can quickly assess scope during an incident.
- Security controls: Encryption, access controls, logging, and network segmentation to reduce both the likelihood and impact of breaches.
For businesses that share links containing customer or partner data during incident response, consider how those links themselves are managed. Using privacy-first tools to shorten and track sensitive URLs prevents accidental exposure and provides an audit trail. Our guide to the best URL shorteners covers options that support enterprise privacy needs.
Frequently Asked Questions
What is the 72-hour rule for data breaches in the UK?
Under Article 33 of the UK GDPR, data controllers must report a notifiable personal data breach to the ICO within 72 hours of becoming aware of it. The clock starts when you have a reasonable degree of certainty that a security incident has affected personal data, and it includes weekends and public holidays.
What happens if I don't report a data breach to the ICO?
Failing to report a notifiable breach is a separate infringement of the UK GDPR and can attract fines of up to £8.7 million or 2% of global annual turnover. If the underlying breach also involved wider compliance failures, higher fines of up to £17.5 million or 4% of turnover may apply. Non-reporting also damages regulatory trust and typically leads to more intrusive investigation.
Do I need to report a breach if the data was encrypted?
If personal data was protected by strong encryption and the decryption keys were not compromised, the breach may be unlikely to result in a risk to individuals, meaning ICO notification may not be required. However, you must still document the incident internally and assess each case on its facts. Encryption does not automatically remove the reporting obligation.
Can I report a data breach anonymously to the ICO?
Organisations reporting their own breaches cannot do so anonymously; the ICO needs to identify the controller. However, if you're an individual reporting concerns about how an organisation has handled a breach, or blowing the whistle on data protection failings, the ICO does accept confidential reports through its dedicated channels.
How long does the ICO take to respond to a breach notification?
The ICO typically acknowledges breach notifications within a few working days. The subsequent handling depends on severity: many cases are closed within weeks with advice, while serious investigations can take months or even more than a year. Maintaining prompt, transparent communication with the ICO throughout is essential.
Final Thoughts
Reporting a data breach to the ICO is not just a legal box-ticking exercise. It's a signal to regulators, customers, and the wider market that your organisation takes personal data seriously and responds responsibly when things go wrong. The organisations that fare best are those that prepare in advance, respond quickly, communicate honestly, and learn from every incident.
If you're building or reviewing your incident response process, start by mapping your data, documenting your notification workflow, and training your team. The 72-hour deadline is tight but manageable when you know exactly what to do.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Block Spam Calls and Robocalls on Your Phone (2026 Guide)
Spam calls and robocalls waste time and often lead to phishing scams. This comprehensive 2026 guide shows exactly how to block them on iPhone and Android using built-in tools, carrier services, apps, and smarter privacy habits.
How to Delete Yourself from People Search Sites: The Complete 2026 Guide
Your home address, phone number, and family details are probably one Google search away. This step-by-step guide shows you exactly how to delete yourself from people search sites like Spokeo, Whitepages, and BeenVerified—and how to keep your data from coming back.
How to Do a Reverse Image Search to Find Your Photos Online
Learn how to do a reverse image search to find your photos online using Google Images, TinEye, Yandex, and mobile tools. This step-by-step 2026 guide covers desktop, mobile, ongoing monitoring, and what to do when you find your image stolen.
How to Use UTM Parameters with Short Links: A Complete Guide
UTM parameters make marketing analytics powerful, but raw tagged URLs are long and unwieldy. Learn how to combine UTM parameters with short links for clean, trackable, professional campaign URLs—complete with naming conventions, examples, and common pitfalls to avoid.