How to Report a Data Breach to the ICO: A Complete UK Guide
If your organisation suffers a personal data breach, UK GDPR gives you just 72 hours to notify the Information Commissioner's Office (ICO). Missing that window, or filing an incomplete report, can trigger regulatory scrutiny and hefty fines. This guide walks you through exactly how to report a data breach to the ICO, when you're legally required to do so, and how to prepare so you're never caught off guard.
What Is a Personal Data Breach Under UK GDPR?
A personal data breach is any security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. It's a broader definition than most people expect — it isn't limited to hackers stealing databases.
Common examples include:
- A laptop or unencrypted USB drive containing customer records being lost or stolen
- An employee emailing a spreadsheet of client details to the wrong recipient
- A ransomware attack that encrypts personal data, even if no data is exfiltrated
- Paper files left in a public place or thrown in general waste
- A misconfigured cloud bucket exposing files to the public internet
- Unauthorised access to systems by a current or former employee
Crucially, a breach doesn't have to involve external attackers. Human error accounts for the majority of incidents reported to the ICO each year.
When Do You Have to Report a Breach to the ICO?
You must report a personal data breach to the ICO within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. If you decide not to report, you must document your reasoning.
The 72-Hour Rule Explained
The clock starts the moment you have a reasonable degree of certainty that a security incident has occurred and it has affected personal data. It does not start when the breach itself happened — it starts when you become aware of it. Weekends and bank holidays count.
Risk Threshold: When Reporting Is Mandatory
You need to assess whether the breach poses a risk to individuals. Consider factors such as:
- The type of data involved (special category data like health or biometric info raises risk significantly)
- The volume of records affected
- How easily individuals could be identified
- The severity of potential consequences: identity theft, financial loss, reputational damage, discrimination, or physical harm
- Whether the data was encrypted or otherwise protected
If there's a high risk to individuals, you must also notify the affected data subjects directly, without undue delay.
When You Don't Need to Report
Some incidents genuinely don't need to be reported. For example, if an encrypted device with strong encryption is lost and the encryption key remains secure, the risk to individuals may be negligible. Still, document your decision-making — the ICO can ask to see it.
Step-by-Step: How to Report a Data Breach to the ICO
Here is the process most UK organisations should follow once they detect a breach:
- Contain the incident. Stop the breach from getting worse — disable compromised accounts, isolate affected systems, recall misdirected emails where possible.
- Convene your response team. Bring together your Data Protection Officer (DPO), IT, legal, and communications leads.
- Assess what happened. Determine the nature of the data, the number of individuals affected, and the likely consequences.
- Decide whether to report. Apply the risk threshold. When in doubt, report.
- Gather the required information (detailed below) before you file.
- Submit the notification via the ICO's online reporting portal or by phone.
- Notify affected individuals if the breach poses a high risk to their rights and freedoms.
- Document everything in your internal breach log.
- Cooperate with the ICO if they follow up with questions or an investigation.
- Review and improve your controls to prevent recurrence.
How to Actually Submit the Report
The ICO offers several channels for reporting depending on urgency and the nature of the breach.
Online Reporting Portal
For most breaches, the fastest and preferred method is the ICO's dedicated online form at ico.org.uk. You'll create a case reference and can save progress if you need to gather more information. Submit within 72 hours even if some details are still unclear — you can update later.
Telephone Reporting
For urgent breaches, particularly those involving significant volumes of data or vulnerable individuals, call the ICO helpline on 0303 123 1113 (Monday to Friday, 9am to 5pm). Outside these hours, use the online form and follow up by phone the next working day.
Sector-Specific Reporting
Some breaches must also be reported to other regulators. Financial services firms must notify the FCA. Telecoms and digital service providers may have obligations under PECR or the NIS Regulations. Health data breaches may involve the Department of Health and Social Care. Reporting to the ICO does not automatically fulfil these other duties.
What Information You'll Need for the Report
The ICO's form asks for detailed information. Even if you don't have every answer within 72 hours, submit what you have and provide the rest as "in phases".
| Category | Details Required |
|---|---|
| Organisation details | Legal name, ICO registration number, DPO contact info |
| Nature of breach | Confidentiality, integrity, or availability breach; how it happened |
| Timeline | When the breach occurred, when you became aware, containment actions taken |
| Data categories | Types of personal data affected (names, addresses, financial, special category) |
| Individuals affected | Approximate number and categories (customers, employees, children, etc.) |
| Likely consequences | Risk assessment: identity theft, financial harm, distress |
| Measures taken | Containment, remediation, and preventive steps |
| Notification to individuals | Whether and how affected individuals were told |
Communicating with Affected Individuals
Where the breach is likely to result in a high risk to individuals, you must notify them directly and in plain language.
What to Include in the Notification
- A clear description of what happened
- The name and contact details of your DPO or other contact point
- The likely consequences of the breach
- Measures you've taken or propose to take
- Recommended actions for the individual (change passwords, monitor accounts, watch for phishing)
Delivery Channels
Direct email or letter is standard. Public notices on your website or social media are only acceptable when contacting individuals directly would involve disproportionate effort. When linking to breach information pages, use trustworthy, branded short links — services like Lunyb let you create clean, memorable URLs that recipients are more likely to trust rather than dismissing as phishing. That said, avoid embedding shortened links inside emails to affected individuals; use the full URL to maintain trust.
Penalties for Failing to Report
Failing to notify the ICO when required is itself a breach of UK GDPR. Administrative fines can reach up to £8.7 million or 2% of global annual turnover, whichever is higher — separate from any fine for the underlying breach.
The ICO tends to be more lenient with organisations that:
- Report promptly and transparently
- Demonstrate solid pre-existing security controls
- Cooperate fully during investigations
- Show genuine remediation efforts
Conversely, cover-ups, delayed reporting, and repeat offences attract significantly harsher penalties.
Building a Breach Response Plan Before You Need One
The single biggest predictor of a smooth ICO notification is preparation. Organisations that scramble to figure out the process during an active incident routinely miss the 72-hour window.
Key Components of a Response Plan
- Named response team with clear roles and 24/7 contact details
- Detection and escalation procedures so staff know how to report suspected incidents internally
- Pre-drafted templates for ICO notifications and individual communications
- Decision trees for the risk assessment and reporting threshold
- Internal breach log ready to go from day one
- Regular tabletop exercises to test the plan against realistic scenarios
Staff Training
The frontline of breach detection is your employees. Regular training helps them recognise phishing, follow secure data handling, and report incidents quickly. Encourage a no-blame culture — staff who fear punishment will hide mistakes, and hidden breaches become undetected ones.
Practical Prevention: Reducing the Risk of a Breach
Reporting is the reactive side. Prevention is where you should invest most of your effort.
Technical Controls
- Encrypt personal data at rest and in transit
- Enforce multi-factor authentication on all accounts handling personal data
- Patch systems promptly and run regular vulnerability scans
- Implement least-privilege access and review permissions quarterly
- Use secure link management tools when sharing sensitive resources internally, so you can revoke access if a link leaks
Organisational Controls
- Maintain an up-to-date Record of Processing Activities (ROPA)
- Complete Data Protection Impact Assessments (DPIAs) for high-risk processing
- Vet processors and include GDPR-compliant contract clauses
- Review supplier security posture regularly
For further reading on secure link sharing and trusted URL practices, our 2026 buyer's guide to URL shorteners compares the leading options, and our honest review of Lunyb covers privacy-focused features useful for organisations that share links externally.
Common Mistakes to Avoid
Even well-prepared organisations fall into predictable traps when reporting to the ICO:
- Waiting for full information before submitting. Report what you know within 72 hours and update later.
- Under-reporting the impact to avoid scrutiny. The ICO will find out, and it damages trust.
- Skipping the internal log for incidents you decide not to report. You still need to document the decision.
- Neglecting to notify individuals when the risk is high. This is a separate legal obligation.
- Forgetting sector regulators. ICO reporting doesn't discharge duties to the FCA, Ofcom, or others.
- Not learning from the incident. A post-mortem and improvement plan is essential.
Frequently Asked Questions
Does the 72-hour deadline include weekends?
Yes. The 72-hour window runs continuously from the moment you become aware of the breach, including weekends and public holidays. If you genuinely can't meet the deadline, you can still report late — but you must explain the reasons for delay in your notification.
What happens after I submit a report to the ICO?
The ICO will acknowledge receipt and may request additional information. Most reported breaches don't lead to formal investigations — the ICO focuses enforcement action on the most serious cases involving systemic failures, large volumes of data, or vulnerable individuals. You may receive guidance letters, recommendations, or in serious cases, a formal investigation.
Do I need to report a breach if the data was encrypted?
If the encryption is strong and the decryption key remains secure, the breach may not pose a risk to individuals, in which case reporting isn't required. However, you must document your assessment. If there's any doubt about the strength of encryption or whether keys are compromised, report it.
Can I report a near-miss or suspected breach?
You only need to report actual personal data breaches. Near-misses and unconfirmed suspicions should be logged internally and investigated, but don't require ICO notification unless you confirm a breach occurred. If you're unsure whether an incident is a breach, err on the side of reporting.
What if the breach was caused by a third-party processor?
If you're the data controller, you're still responsible for reporting to the ICO — even when the breach originated with a processor. Your contract with the processor should require them to notify you "without undue delay" so you can meet your own 72-hour obligation. Include details of the processor's role in your notification.
Final Thoughts
Reporting a data breach to the ICO isn't just a legal formality — it's a chance to demonstrate that your organisation takes personal data seriously. Prompt, transparent reporting, combined with genuine remediation, is your best defence against enforcement action and reputational damage. Invest in a well-drilled response plan now, and you'll handle any future incident with confidence rather than panic.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Hide Photos with an Encrypted Photo Vault: Complete Guide
Learn how to hide photos with an encrypted vault to protect your private images from prying eyes. This guide covers app selection, setup steps, common mistakes, and advanced privacy techniques for 2026.
How to Safely Share Your Location with Family: A Complete 2026 Guide
Sharing your location with family shouldn't mean sacrificing privacy. This complete guide compares the safest apps, walks through step-by-step setup, and covers special considerations for kids, elderly parents, and one-time shares — so you get peace of mind without exposing your data.
How to Block Spam Calls and Robocalls on Your Phone: The Complete 2026 Guide
Spam calls and robocalls waste time and put your security at risk. This complete guide covers every practical way to block them on iPhone and Android, plus long-term privacy strategies to keep your number off spammer lists for good.
How to Protect Your Privacy Online in 2026: The Complete Guide
Online privacy in 2026 requires more than a strong password. This complete guide walks you through the tools, habits, and settings that keep your data, identity, and communications safe from trackers, scammers, and data brokers.