How to Report a Data Breach to the ICO: A Complete UK Guide
If your organisation suffers a personal data breach in the UK, the Information Commissioner's Office (ICO) must, in most cases, be notified within 72 hours. Missing this deadline or reporting incorrectly can result in fines of up to £17.5 million or 4% of global annual turnover. This guide walks you through exactly how to report a data breach to the ICO, what information you need, and how to handle the aftermath.
What Is a Personal Data Breach Under UK GDPR?
A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. It is not limited to hacking — it includes human error, lost devices, stolen paperwork, and misdirected emails.
Under the UK GDPR and the Data Protection Act 2018, there are three broad categories of breach:
- Confidentiality breach — unauthorised or accidental disclosure of, or access to, personal data.
- Integrity breach — unauthorised or accidental alteration of personal data.
- Availability breach — accidental or unauthorised loss of access to, or destruction of, personal data.
Examples of Reportable Breaches
- A ransomware attack encrypting a customer database.
- An employee emailing a spreadsheet of client details to the wrong recipient.
- A stolen laptop containing unencrypted HR records.
- Paper files left on a train.
- A phishing attack that harvests staff login credentials.
When Do You Need to Report a Data Breach to the ICO?
You must report a personal data breach to the ICO within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. The 72-hour clock starts when you become aware of the breach — not when it happened.
The Risk Threshold
Not every breach is notifiable. You should assess whether the breach is likely to cause harm such as:
- Financial loss or fraud
- Identity theft
- Damage to reputation
- Loss of confidentiality of data subject to professional secrecy
- Physical harm or discrimination
- Any significant economic or social disadvantage
If the risk is high, you also need to inform the affected individuals directly, in clear and plain language, without undue delay.
Quick Decision Table
| Scenario | Report to ICO? | Notify Individuals? |
|---|---|---|
| Encrypted laptop lost, strong encryption, key not compromised | No (document internally) | No |
| Unencrypted USB with customer data lost | Yes | Likely yes |
| Ransomware locking personal data | Yes | Depends on risk |
| Email sent to wrong internal colleague, recalled immediately | Usually no | No |
| Bulk email exposing recipients in "To" field | Yes | Yes, if sensitive |
| Public disclosure of health, financial, or children's data | Yes | Yes |
How to Report a Data Breach to the ICO: Step-by-Step
Follow this seven-step process to submit a compliant breach notification within the 72-hour window.
- Contain the breach. Isolate affected systems, revoke compromised credentials, recall misdirected emails, and stop any ongoing data loss.
- Assess the scope. Identify what data was affected, how many individuals are impacted, and what categories of personal data are involved (name, address, financial, special category, etc.).
- Evaluate the risk. Determine the likelihood and severity of harm to individuals using a documented risk assessment.
- Document everything. Under Article 33(5) of UK GDPR, you must keep a record of all breaches — even those you do not report externally.
- Report to the ICO. Use the ICO's online reporting tool at ico.org.uk, or call the breach helpline on 0303 123 1113 (option 3) during business hours.
- Notify affected individuals if the breach poses a high risk to their rights and freedoms.
- Follow up. Provide additional information to the ICO as the investigation continues, and implement remedial actions.
The ICO Online Reporting Tool
The ICO's Personal Data Breach Reporting tool is the fastest and preferred route. It guides you through a structured questionnaire and generates a case reference. You can save progress and return to it, which is useful when facts are still emerging within the 72-hour window.
What Information Do You Need to Include?
Article 33(3) of the UK GDPR sets out the minimum content of a breach notification. Have this information ready before you start the report:
1. Nature of the Breach
- What happened and when
- How you became aware of it
- Whether the breach is ongoing or contained
- The categories and approximate number of data subjects concerned
- The categories and approximate number of personal data records concerned
2. Contact Details
- Name and contact details of your Data Protection Officer (DPO) or another point of contact
3. Likely Consequences
- A description of the potential harm or impact on individuals
4. Measures Taken or Proposed
- Actions taken to address the breach
- Measures to mitigate possible adverse effects
- Steps to prevent recurrence
If you do not have all the information within 72 hours, submit an initial report and provide further details in phases. The ICO explicitly allows phased reporting.
What Happens After You Report?
Once you submit a breach notification, the ICO will:
- Acknowledge receipt and issue a case reference number.
- Assess the severity of the incident and your response.
- Contact you for further information if needed.
- Decide whether to take regulatory action, which can range from no further action to enforcement notices or monetary penalties.
Most breaches result in no formal enforcement, provided the organisation responded promptly, transparently, and took reasonable steps to prevent recurrence. The ICO tends to penalise systemic failings, cover-ups, and repeated breaches far more harshly than isolated incidents handled well.
Notifying Affected Individuals
If a breach is likely to result in a high risk to the rights and freedoms of individuals, you must inform them directly. The notification must be in clear, plain language and include:
- The nature of the breach
- Contact details of your DPO or point of contact
- Likely consequences of the breach
- Measures taken or proposed to address it
- Recommendations on how affected individuals can protect themselves (e.g. changing passwords, monitoring bank statements)
You can avoid direct notification if you have implemented protection measures such as strong encryption that render the data unintelligible, or if direct notification would involve disproportionate effort (in which case a public communication is acceptable).
Common Mistakes to Avoid
Even well-prepared organisations trip up on these:
- Waiting for full information. Report within 72 hours even if the picture is incomplete. Late reports must be justified.
- Under-reporting scope. Be honest about the number of records — the ICO will find out and downplaying makes things worse.
- Failing to document non-notifiable breaches. You still need an internal record.
- Not training staff. Employees are often the first to spot a breach; they must know how to escalate immediately.
- Ignoring processors. If you are a data processor, you must notify the controller "without undue delay" — the controller then decides whether to report to the ICO.
- Poor link hygiene in breach comms. Sending affected individuals lengthy, suspicious-looking URLs can trigger phishing worries. Use a trusted, branded short link service like Lunyb to create clean, verifiable URLs in breach notifications.
Penalties for Non-Compliance
Failing to report a notifiable breach — or failing to keep proper records — can attract administrative fines of up to £8.7 million or 2% of global annual turnover, whichever is higher. More serious infringements of the UK GDPR itself carry fines of up to £17.5 million or 4% of turnover.
Beyond fines, poor breach handling causes reputational damage, class-action-style compensation claims, contractual penalties, and loss of customer trust. The reputational cost frequently exceeds any regulatory fine.
Preparing Before a Breach Happens
The best time to prepare a breach response is before you need it. Every UK organisation processing personal data should have:
An Incident Response Plan
A written plan identifying roles, escalation paths, decision-makers, communication templates, and external contacts (legal counsel, forensic investigators, PR advisors).
A Breach Register
A log of all incidents — notifiable or not — with the facts, decisions, risk assessments, and outcomes. This satisfies Article 33(5) and is invaluable if the ICO ever audits you.
Regular Training
All staff should know what a personal data breach looks like and how to report it internally within hours, not days.
Technical Safeguards
Encryption at rest and in transit, multi-factor authentication, least-privilege access, and monitored logging reduce both the likelihood and severity of breaches. For organisations sharing sensitive links or files, using tools that provide audit trails and access controls — such as trackable short links from Lunyb or similar privacy-focused link management platforms discussed in our 2026 URL shortener buyer's guide — can add a helpful layer of visibility.
Special Cases: Processors, Joint Controllers, and Cross-Border Breaches
If You Are a Data Processor
Processors do not report directly to the ICO. Instead, you must notify the controller "without undue delay" after becoming aware. Your contract should specify timelines — ideally 24 hours or less — to allow the controller to meet the 72-hour deadline.
Joint Controllers
Agree in advance which party leads on breach notification. Both remain legally accountable, but coordinated communication avoids conflicting reports.
Cross-Border Breaches
If the breach affects individuals in the EU as well as the UK, you may need to report to both the ICO and an EU lead supervisory authority. The UK is no longer part of the EU one-stop-shop mechanism, so parallel reporting is often required.
FAQ
How long do I have to report a data breach to the ICO?
You have 72 hours from the moment you become aware of the breach. If you cannot provide all details within that window, submit an initial report and follow up with additional information in phases. Late reports must be accompanied by a reasoned justification for the delay.
Do I need to report every data breach?
No. You only need to report breaches that are likely to result in a risk to the rights and freedoms of individuals. However, you must document every breach internally, including your risk assessment and the reasons for not reporting, to comply with Article 33(5) of the UK GDPR.
What is the fine for not reporting a data breach?
Failure to notify a reportable breach can result in a fine of up to £8.7 million or 2% of global annual turnover, whichever is higher. Underlying data protection failings that caused the breach may attract higher fines of up to £17.5 million or 4% of turnover.
Can I report a breach anonymously or on behalf of someone else?
Organisations reporting their own breaches must provide contact details — anonymous reporting is not permitted for controllers. However, individuals who suspect their data has been mishandled by an organisation can raise a concern with the ICO separately using the public complaints route on ico.org.uk.
What if I discover the breach happened months ago?
The 72-hour clock starts when you become aware, not when the breach occurred. Report as soon as you have reasonable certainty a breach has taken place. Historic breaches must still be reported if they meet the risk threshold, and you should explain the delay in discovery in your notification.
Final Thoughts
Reporting a data breach to the ICO is not just a legal box-ticking exercise — it is a test of your organisation's maturity, transparency, and respect for the individuals whose data you hold. Organisations that respond quickly, honestly, and constructively rarely face the harshest penalties. Those that delay, minimise, or conceal almost always regret it.
Prepare in advance, document thoroughly, and treat the 72-hour deadline as a floor rather than a ceiling. Your customers, employees, and regulators will all thank you for it.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Block Trackers on Your Phone: The Complete 2026 Guide
Mobile trackers follow you across apps, websites, and even into your home network. This step-by-step guide shows exactly how to block trackers on your iPhone or Android in 2026 — using built-in settings, private DNS, and better browsers, without any technical background.
How to Report a Scam Phone Number: A Complete Global Guide
Scam calls and texts are a global epidemic, but reporting them is faster and more impactful than most people realize. This guide walks you through exactly how to report a scam number to authorities, carriers, and messaging platforms worldwide.
How to Protect Your Privacy Online in 2026: The Complete Guide
Online privacy in 2026 requires more than good intentions. This step-by-step guide walks you through hardening your browser, accounts, network, devices, and shared links — with practical tools and habits you can implement this week.
How to Erase Your Browsing History Completely: The 2026 Guide
Clearing browser history only wipes the surface layer. This 2026 guide shows how to erase your browsing history completely — across browsers, devices, DNS caches, router logs, and cloud accounts — with a step-by-step checklist you can reuse.