facebook-pixel

How to Report a Data Breach to the ICO: A Complete UK Guide

L
Lunyb Security Team
··10 min read

If your organisation has suffered a personal data breach, UK law requires you to act quickly. Under the UK GDPR and the Data Protection Act 2018, most breaches must be reported to the Information Commissioner's Office (ICO) within 72 hours of becoming aware of them. Failing to do so can result in significant fines, reputational damage, and enforcement action.

This guide walks you through exactly how to report a data breach to the ICO, what information you need to prepare, and how to reduce the likelihood of it happening again. Whether you're a data protection officer, a small business owner, or an IT lead, this article will help you respond confidently and lawfully.

What Counts as a Personal Data Breach?

A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. In other words, it's not just about hackers — a lost laptop, an email sent to the wrong recipient, or a misconfigured database can all qualify.

The ICO groups breaches into three broad categories:

  • Confidentiality breach — unauthorised or accidental disclosure of, or access to, personal data.
  • Integrity breach — unauthorised or accidental alteration of personal data.
  • Availability breach — accidental or unauthorised loss of access to, or destruction of, personal data.

Examples of Reportable Breaches

  • Ransomware encrypting customer records
  • An employee emailing a spreadsheet of client data to the wrong distribution list
  • A stolen or lost unencrypted USB stick containing personal data
  • Phishing attacks that compromise staff credentials and expose personal data
  • Cloud storage misconfigured to allow public access

When Must You Report a Data Breach to the ICO?

You must report a notifiable personal data breach to the ICO within 72 hours of becoming aware of it. The clock starts the moment you have a reasonable degree of certainty that a security incident has led to personal data being compromised — not when you first suspect something is wrong.

However, not every breach is notifiable. You only need to report if the breach is likely to result in a risk to the rights and freedoms of individuals. If the risk is unlikely, you still need to document the incident internally, but you don't have to inform the ICO.

Assessing the Risk

When deciding whether to report, consider:

  1. Type of breach — is data lost, exposed, or altered?
  2. Nature and volume of data — does it include special category data (health, ethnicity, biometrics), financial details, or identifiers like National Insurance numbers?
  3. Ease of identification — could individuals be identified from the compromised data?
  4. Severity of consequences — could it lead to identity theft, fraud, discrimination, financial loss, or reputational harm?
  5. Number of individuals affected — larger volumes typically raise risk levels.
  6. Vulnerability of the individuals — children and other vulnerable groups warrant extra caution.

If in doubt, err on the side of reporting. The ICO would rather receive a report that turns out to be low risk than miss a serious one.

How to Report a Data Breach to the ICO: Step-by-Step

Reporting a breach involves gathering evidence, filling in the correct form, and cooperating with any follow-up. Here's the process from start to finish.

Step 1: Contain the Breach

Before you notify anyone, take immediate steps to stop the breach getting worse. That might mean isolating affected systems, revoking compromised credentials, recalling misdirected emails, or blocking exfiltration routes. Preserve logs and evidence — you'll need them later.

Step 2: Assemble Your Facts

The ICO will ask specific questions. Gather the following before you start the report:

  • Date and time the breach occurred and was discovered
  • How the breach was identified
  • Description of the incident and the cause (if known)
  • Categories and approximate number of individuals affected
  • Categories and approximate number of personal data records concerned
  • Likely consequences for those individuals
  • Measures taken or proposed to address the breach and mitigate harm
  • Name and contact details of your Data Protection Officer or lead contact

Step 3: Use the Correct Reporting Channel

There are three main ways to report:

ChannelBest ForAvailability
ICO online reporting formMost standard breach reports24/7 via ico.org.uk
ICO breach helpline (0303 123 1113)Urgent or complex incidents needing guidanceMon–Fri, 9am–5pm
Live chat via ICO websiteQuick questions before formal submissionBusiness hours

For most organisations, the online form is the primary route. It walks you through the required fields and generates a case reference number.

Step 4: Submit the Report Within 72 Hours

If you have all the information ready, submit a complete report. If not, submit what you have and mark it as a phased notification — the ICO allows follow-up information to be provided later, so long as you explain the delay.

Step 5: Notify Affected Individuals (If Required)

If the breach is likely to result in a high risk to individuals' rights and freedoms, you must also inform them directly, without undue delay. The notification should be in clear, plain language and include:

  • The nature of the breach
  • Contact details of your DPO or relevant contact
  • Likely consequences
  • Measures taken or proposed to address the breach
  • Practical steps individuals can take to protect themselves

Step 6: Document Everything

Even if a breach isn't reportable, you must keep an internal breach register. Record the facts, effects, and remedial action taken. The ICO can request this at any time.

What Happens After You Report

Once you submit the report, the ICO will acknowledge receipt and assign a case reference. Depending on severity, they may:

  • Take no further action beyond logging the report
  • Request further information or documentation
  • Provide advice on remedial steps
  • Launch a formal investigation
  • Issue enforcement notices, reprimands, or fines

Cooperation and transparency go a long way. The ICO's guidance repeatedly emphasises that organisations who respond honestly and act swiftly to protect individuals are treated more favourably than those who try to minimise or delay reporting.

Common Mistakes to Avoid

Reporting a breach is stressful, and many organisations make avoidable errors. Watch out for the following:

1. Waiting Too Long to Report

Some organisations spend the first 72 hours investigating rather than reporting. The ICO expects a report even if the investigation is ongoing — you can update the details later.

2. Under-Reporting the Impact

Downplaying the number of affected records or the sensitivity of the data can lead to accusations of misleading the regulator. Be honest about the worst-case scenario.

3. Failing to Inform Individuals

If the risk is high, individuals must be told directly. Relying on a press release or a website notice is often insufficient.

4. Not Learning From the Incident

A breach is a chance to strengthen your defences. Post-incident reviews, staff training, and updated policies should be a standard part of your response.

Fines and Penalties for Non-Compliance

The UK GDPR gives the ICO the power to issue substantial fines. For failing to report a notifiable breach, penalties can reach:

  • Up to £8.7 million or 2% of global annual turnover, whichever is higher, for administrative breaches (such as failing to notify).
  • Up to £17.5 million or 4% of global annual turnover, whichever is higher, for more serious infringements of data subjects' rights.

Beyond fines, organisations face reputational harm, loss of customer trust, and potential civil claims from affected individuals.

Preventing the Next Breach

Prevention is far cheaper than reporting. A robust data protection programme should include:

Technical Controls

  • Full-disk encryption on laptops and mobile devices
  • Multi-factor authentication on all business accounts
  • Regular patching and vulnerability scanning
  • Endpoint detection and response tools
  • Secure link management for sensitive URLs — services like Lunyb allow you to create short, trackable links with expiry dates and access controls, reducing the risk of orphaned links leaking sensitive data

Organisational Controls

  • Documented data protection policies and procedures
  • Regular staff training on phishing, social engineering, and data handling
  • Clear incident response and breach notification playbooks
  • Data minimisation — only collect what you need
  • Regular data protection impact assessments (DPIAs) for high-risk processing

Supplier and Third-Party Management

Many breaches originate with processors and suppliers. Ensure your contracts include breach notification clauses, and audit key vendors periodically. If a processor suffers a breach, they must notify you without undue delay so you can meet your own 72-hour deadline.

Building an Incident Response Plan

An incident response plan turns panic into procedure. At minimum, your plan should cover:

  1. Detection and reporting — how staff report suspected incidents internally
  2. Triage and containment — who assesses severity and takes immediate action
  3. Investigation — forensic steps to identify scope and cause
  4. Notification — decision framework for informing the ICO, individuals, and other regulators
  5. Recovery — restoring systems and data securely
  6. Post-incident review — root cause analysis and lessons learned

Test the plan at least annually with tabletop exercises. A plan that only exists on paper will fail under real pressure.

Further Reading

If you're building out your privacy and security stack, you may also find these resources useful:

Frequently Asked Questions

Do I have to report every data breach to the ICO?

No. You only need to report breaches that are likely to result in a risk to the rights and freedoms of individuals. Low-risk incidents still need to be recorded in your internal breach register, but they don't have to be reported to the ICO. If you're unsure, the safest approach is to report.

What happens if I miss the 72-hour deadline?

You can still report, but you must explain the reasons for the delay. The ICO takes late notification seriously and may consider it an aggravating factor when deciding on enforcement action. It's better to submit a partial report on time than a complete report late.

Do I need to tell affected individuals about the breach?

Only if the breach is likely to result in a high risk to their rights and freedoms. In those cases, you must inform them directly, in clear language, without undue delay. If notifying individuals would involve disproportionate effort, a public communication may be acceptable.

Can I be fined for a data breach even if I report it correctly?

Yes, but reporting promptly and cooperating with the ICO significantly reduces the likelihood and size of any fine. Fines are typically reserved for cases involving negligence, repeated failures, or serious harm to individuals. Transparent, well-handled responses often result in advice or reprimands rather than financial penalties.

What should a small business do if it can't afford a Data Protection Officer?

Only certain organisations are legally required to appoint a DPO. Small businesses can nominate a data protection lead instead, use external consultants, or rely on the ICO's free small business helpline and self-assessment tools. What matters is that someone is clearly accountable for data protection within your organisation.

Final Thoughts

Reporting a data breach to the ICO is not just a legal obligation — it's an opportunity to demonstrate accountability and rebuild trust. By preparing in advance, acting quickly, and being transparent, you can turn a difficult moment into evidence of a mature, well-run organisation.

The most important takeaways: know what counts as a breach, understand your 72-hour deadline, gather the right information, use the ICO's online reporting form, and always document your response. Combine that with strong preventive controls and regular staff training, and you'll be well placed to protect both your customers and your business.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles