How to Report a Data Breach to the ICO: A Complete UK Guide
If your organisation suffers a personal data breach in the UK, you may have a legal duty to notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of it. Getting this process right is critical: a mishandled notification can lead to enforcement action, reputational damage and fines of up to £17.5 million or 4% of global annual turnover under the UK GDPR.
This comprehensive guide walks you through exactly how to report a data breach to the ICO, when reporting is required, what information you need to gather, and how to manage the aftermath. Whether you are a Data Protection Officer, an IT manager, or a small business owner, this article will help you respond confidently and compliantly.
What Is a Personal Data Breach Under UK GDPR?
A personal data breach is a security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. It is not limited to cyberattacks — it also covers human error, lost devices, misdirected emails and physical theft.
The UK GDPR and the Data Protection Act 2018 place the reporting obligation on the data controller. Processors must notify the controller without undue delay, but they do not report directly to the ICO themselves.
Common Examples of Reportable Breaches
- Ransomware attacks that encrypt customer records
- Lost or stolen laptops, USB drives or paper files containing personal data
- Emails sent to the wrong recipient containing sensitive information
- Unauthorised staff access to HR or medical records
- Cloud storage misconfiguration exposing customer data
- Phishing attacks that compromise employee credentials
When Must You Report a Data Breach to the ICO?
You must report a notifiable breach to the ICO within 72 hours of becoming aware of it. A breach is notifiable when it is likely to result in a risk to the rights and freedoms of individuals — for example, discrimination, financial loss, identity theft, damage to reputation, or loss of confidentiality.
Not every breach needs reporting. If the personal data was properly encrypted and the decryption key remains secure, or if the incident is contained with no realistic risk to individuals, you may not need to notify the ICO. However, you must still document the incident internally.
The 72-Hour Clock: When Does It Start?
The 72-hour countdown begins from the moment you become aware that a personal data breach has occurred — not from when the breach itself happened. "Awareness" means having a reasonable degree of certainty that a security incident has led to personal data being compromised.
If you cannot provide all information within 72 hours, you can submit an initial report and follow up with additional details in phases. The ICO expects you to explain any delay.
High-Risk Breaches: Notifying Individuals
If a breach is likely to result in a high risk to individuals' rights and freedoms, you must also notify the affected data subjects without undue delay. This is separate from your ICO notification and uses plain language to explain the nature of the breach, likely consequences, and the measures being taken.
Step-by-Step: How to Report a Data Breach to the ICO
Follow these steps as soon as you become aware of a potential breach. Speed and accuracy are equally important.
- Contain the breach. Take immediate steps to stop the incident spreading — disconnect affected systems, revoke compromised credentials, or recall misdirected emails where possible.
- Assess the risk. Determine what personal data is involved, how many individuals are affected, the potential consequences, and whether the breach is likely to result in risk to those individuals.
- Document everything. Record the facts, timeline, decisions made and reasoning — even for breaches you decide not to report. The ICO can request this documentation.
- Decide whether to notify. If there is a likelihood of risk, prepare to notify the ICO. If risk is high, also prepare communications for affected individuals.
- Submit the report to the ICO. Use the ICO's online reporting service or call the breach helpline for urgent cases.
- Notify affected individuals if the breach poses a high risk to them.
- Follow up. Provide supplementary information to the ICO if not all details were available initially, and implement measures to prevent recurrence.
How to Submit the Report
The ICO offers several reporting channels:
- Online form: The primary route via the ICO's website (ico.org.uk/for-organisations/report-a-breach) — recommended for most cases.
- Telephone: Call the ICO's personal data breach helpline on 0303 123 1113, option 3, during business hours for urgent guidance.
- Post: Written notification is accepted but slower and generally not recommended for time-critical reports.
What Information Does the ICO Require?
Under Article 33(3) of the UK GDPR, your breach notification must include specific details. Preparing this information in advance — as part of your incident response plan — will save critical time.
| Required Information | Description |
|---|---|
| Nature of the breach | What happened, including categories and approximate number of individuals and records affected |
| Contact details | Name and contact information of your Data Protection Officer or breach contact point |
| Likely consequences | A description of the potential impact on affected individuals |
| Measures taken | Actions taken or proposed to address the breach and mitigate adverse effects |
| Timeline | When the breach occurred, when you became aware, and any delay explanation |
| Data categories | Types of personal data involved (e.g., names, addresses, financial data, health data) |
Special Category Data
If the breach involves special category data (health, biometric, racial or ethnic origin, religious beliefs, sexual orientation, trade union membership, political opinions) or criminal offence data, the risk assessment is almost always elevated and notification will typically be required.
Penalties for Failing to Report a Data Breach
Non-compliance with breach reporting obligations carries significant consequences. The ICO has a range of enforcement powers and does not hesitate to use them.
Financial Penalties
The ICO can impose two tiers of fines under the UK GDPR:
- Standard maximum: Up to £8.7 million or 2% of global annual turnover (whichever is higher) — applies to breach notification failures.
- Higher maximum: Up to £17.5 million or 4% of global annual turnover — applies to more serious infringements such as breaches of data subject rights or unlawful processing.
Other Enforcement Actions
Beyond fines, the ICO can issue reprimands, enforcement notices requiring specific action, and audit notices. Serious cases may attract public attention, causing reputational damage that often exceeds the financial penalty.
Preparing Your Organisation Before a Breach Happens
The best time to plan your ICO breach response is before an incident occurs. Organisations that treat breach response as an afterthought consistently miss the 72-hour deadline.
Build an Incident Response Plan
Your plan should identify roles, escalation paths and decision-makers. Include templates for internal notifications, ICO submissions and communications to affected individuals. Test the plan through tabletop exercises at least annually.
Maintain a Breach Register
Under Article 33(5), you must document all personal data breaches — reportable or not — including facts, effects and remedial action. This register is the first thing the ICO will request during any investigation.
Reduce Your Attack Surface
Prevention remains cheaper than response. Practical measures include:
- Encrypting personal data at rest and in transit
- Enforcing multi-factor authentication on all business-critical accounts
- Providing regular staff training on phishing and data handling
- Reviewing third-party processor contracts and security posture
- Using privacy-respecting tools for marketing links — for example, when tracking campaign clicks, services like Lunyb allow you to shorten and monitor URLs without exposing unnecessary personal data
- Segmenting networks so that a single compromise does not expose everything
Common Mistakes When Reporting to the ICO
Even well-intentioned organisations make avoidable errors during breach reporting. Awareness of these pitfalls can save you time and enforcement risk.
Waiting for Complete Information
Many organisations delay notification hoping to submit a "perfect" report. The UK GDPR explicitly allows phased reporting — submit what you know within 72 hours and update the ICO afterwards.
Underestimating the Risk
Risk assessments should be conservative and documented. When in doubt, err on the side of reporting. The ICO views organisations that under-report far more critically than those that over-report.
Poor Internal Communication
Delays often occur because staff who first discover a breach do not know how to escalate. A clear internal reporting line — from any employee to the DPO within hours, not days — is essential.
Neglecting Data Subject Notifications
Reporting to the ICO is only half the story for high-risk breaches. Failing to inform affected individuals promptly is itself a separate infringement.
What Happens After You Report?
Once your notification is submitted, the ICO reviews the information and decides whether further action is required. Most reports do not lead to formal investigation, particularly when the organisation has responded well.
The ICO may respond in several ways:
- Acknowledgement only — no further action if the response was proportionate and effective.
- Request for further information — additional details about the incident or your controls.
- Formal investigation — for serious breaches or where systemic failures are suspected.
- Enforcement action — reprimands, notices or fines in the most serious cases.
Cooperation, transparency and evidence of prompt remedial action significantly influence the ICO's approach. Organisations that demonstrate genuine accountability are treated more favourably than those that appear defensive or evasive.
Related Reading
If you are reviewing your digital tools and privacy posture as part of your breach preparation, you may find these guides useful:
- Best URL Shorteners Reviewed and Compared: 2026 Buyer's Guide
- Is Lunyb Legit? An Honest Review of the URL Shortener in 2026
- Rebrandly Review 2026: Is It Worth the Price?
Frequently Asked Questions
Do I need to report every data breach to the ICO?
No. You only need to report breaches that are likely to result in a risk to the rights and freedoms of individuals. However, you must document all breaches internally, including those you decide not to report, and be able to justify your decision if the ICO asks.
What if I discover the breach happened weeks ago?
The 72-hour clock starts when you become aware of the breach, not when it occurred. Report as soon as you have sufficient certainty and be prepared to explain any delay in detection. Weak detection capability itself may be a compliance concern the ICO will consider.
Can I report a data breach anonymously?
No. The ICO requires organisation and contact details for the reporting party, typically the Data Protection Officer or a designated breach contact. Individuals concerned about how an organisation has handled their data can make a separate complaint to the ICO.
What happens if I miss the 72-hour deadline?
You should still report the breach as soon as possible and explain the delay. Late reporting is an infringement in itself, but the ICO considers the reasons and any mitigating factors. Deliberate concealment is treated far more seriously than a genuine delay.
Does the ICO fine every organisation that reports a breach?
No. The vast majority of breach reports do not result in fines. The ICO focuses enforcement on cases involving negligence, systemic failures, or breaches of large scale and sensitivity. Prompt, transparent reporting with effective remediation is usually met with an acknowledgement and no further action.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Remove Your Personal Information from Data Brokers: Complete 2026 Guide
Data brokers sell your personal information to anyone willing to pay, exposing you to identity theft, stalking, and scams. This comprehensive guide shows you exactly how to remove your data from the top brokers, protect your privacy long-term, and leverage your legal rights.
How to Protect Your Privacy Online in 2026: The Complete Guide
Online privacy in 2026 requires more than a strong password. This complete guide walks you through the tools, habits, and settings that keep your data, identity, and browsing activity truly private.
Who Called Me? How to Identify an Unknown Number in 2026
Missed a call from a number you don't recognize? This complete 2026 guide covers 8 proven methods to identify unknown callers, from reverse phone lookups and Google searches to messaging apps and carrier spam filters. Learn how to spot scams and block unwanted callers for good.
How to Shorten a URL: Complete Guide for 2026
Learn how to shorten a URL step by step in 2026. This complete guide covers the best tools, custom aliases, branded domains, analytics, security tips, and common mistakes to avoid when creating short links.