How to Report a Data Breach to the ICO: A Complete UK Guide
If your organisation has suffered a personal data breach, UK GDPR requires you to act fast. In most cases, you have just 72 hours to report a notifiable breach to the Information Commissioner's Office (ICO). Failing to do so can result in significant fines and reputational damage. This guide walks you through exactly how to report a data breach to the ICO, what qualifies as notifiable, and what to do in the hours after you discover an incident.
What Is a Personal Data Breach Under UK GDPR?
A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. It's not limited to cyberattacks — human error, lost devices, and misdirected emails all count.
Under Article 4(12) of the UK GDPR, a breach falls into one of three categories:
- Confidentiality breach — unauthorised or accidental disclosure of, or access to, personal data.
- Integrity breach — unauthorised or accidental alteration of personal data.
- Availability breach — accidental or unauthorised loss of access to, or destruction of, personal data.
Common examples include ransomware attacks, phishing incidents that expose customer records, laptops or USB sticks lost in transit, emails sent to the wrong recipient with attachments containing personal information, or misconfigured cloud storage exposing files to the public internet.
When Does a Breach Become "Notifiable"?
Not every breach must be reported. Under Article 33 UK GDPR, you must report a breach to the ICO only when it is likely to result in a risk to the rights and freedoms of natural persons. This means considering the potential for physical, material, or non-material damage — such as identity theft, financial loss, damage to reputation, discrimination, or loss of confidentiality.
If the risk is high, you must also notify the individuals affected without undue delay (Article 34). If in doubt, err on the side of reporting — the ICO is clear that under-reporting carries greater risk than over-reporting.
The 72-Hour Rule Explained
The clock starts ticking the moment you become aware of the breach — not when it happened. "Awareness" means having a reasonable degree of certainty that a security incident has occurred and led to personal data being compromised.
You have 72 hours from that point to notify the ICO. This includes weekends and bank holidays. If you can't provide all the information within 72 hours, submit what you have and follow up in phases — the ICO explicitly allows this under Article 33(4).
If you report late, you must explain the reasons for the delay. Legitimate reasons (such as a complex forensic investigation) may be accepted; disorganisation typically will not.
Step-by-Step: How to Report a Data Breach to the ICO
The ICO offers multiple reporting channels depending on the type and severity of the breach. Here's the standard process:
- Contain the breach. Before reporting, take immediate steps to stop the incident spreading. Isolate affected systems, revoke compromised credentials, and secure any physical media.
- Assess the risk. Determine what data was involved, how many people are affected, the likelihood of harm, and the severity of potential consequences.
- Decide if the breach is notifiable. Document your risk assessment even if you decide not to report — the ICO can ask to see this reasoning later.
- Gather the required information. You'll need details of the incident, categories and approximate number of data subjects, categories and approximate number of records, likely consequences, and measures taken or proposed.
- Submit your report. Use the ICO's online reporting tool at ico.org.uk or call their breach helpline on 0303 123 1113 (available 9am–5pm, Monday to Friday).
- Notify affected individuals if required. If the breach is high risk, communicate with data subjects in plain language, describing what happened and what they should do.
- Document everything. Maintain an internal breach register. This is a legal requirement under Article 33(5), regardless of whether the breach was reported.
Choosing the Right Reporting Channel
The ICO provides different pathways based on incident type:
- General personal data breach: Online form via ico.org.uk/report-a-breach.
- Cyber incident: A dedicated cyber-incident form that aligns with National Cyber Security Centre (NCSC) reporting.
- Communications service providers (PECR): Different rules under the Privacy and Electronic Communications Regulations — must be reported within 24 hours.
- Phone reporting: Recommended for urgent or complex incidents where you need immediate guidance.
Information You'll Need to Provide
The ICO's online form is comprehensive. Preparing this information in advance will save critical time during a live incident.
| Category | Details Required |
|---|---|
| Organisation details | Name, ICO registration number, sector, contact details of the DPO or lead contact |
| Breach summary | Date and time of incident, date of awareness, cause, how it was discovered |
| Data affected | Categories of personal data (basic identifiers, financial, health, special category), approximate volume |
| Individuals affected | Categories (customers, employees, patients), approximate number |
| Consequences | Likely impact, whether individuals have been notified |
| Remedial action | Steps taken to contain and mitigate, planned improvements |
| Cross-border element | Whether individuals in other jurisdictions are affected |
What Happens After You Report
Once the ICO receives your notification, they will acknowledge receipt and assign a case reference number. What happens next depends on the severity and nature of the incident.
Possible Outcomes
- No further action. For lower-risk breaches with good containment, the ICO may take no further action and simply file the report.
- Advice and guidance. The ICO may provide recommendations for improving your security posture.
- Formal investigation. Serious breaches trigger a detailed investigation, potentially involving audits, interviews, and requests for documentation.
- Enforcement action. This can range from warnings and reprimands to enforcement notices and monetary penalties of up to £17.5 million or 4% of annual global turnover, whichever is higher.
Cooperating with the ICO
Transparency and cooperation are consistently viewed favourably. The ICO's regulatory action policy makes clear that self-reporting, honest engagement, and demonstrable improvements are mitigating factors. Attempting to conceal or downplay a breach almost always makes the outcome worse.
Notifying Affected Individuals
Where a breach is likely to result in a high risk to individuals' rights and freedoms, you must communicate directly with those affected. This notification must:
- Be written in clear, plain language.
- Describe the nature of the breach.
- Provide the name and contact details of your DPO or relevant contact point.
- Describe the likely consequences.
- Describe measures taken or proposed to address the breach and mitigate possible adverse effects.
You may be exempt from notifying individuals if you've implemented appropriate technical protection measures (such as strong encryption) that render the data unintelligible, if you've taken subsequent steps eliminating the high risk, or if notification would involve disproportionate effort — in which case a public communication is acceptable.
Common Mistakes That Make Breaches Worse
Handling a breach poorly compounds the damage. Watch out for these frequent errors:
- Delaying investigation to "be sure" it's a breach. The 72-hour clock runs on awareness — you don't need certainty about every detail before reporting.
- Reporting without containment. Notify the ICO, but only after taking immediate steps to stop the bleeding.
- Poor internal communication. Staff should know who to escalate to. Many breaches worsen because the person who discovers them doesn't know the process.
- Failing to document non-reportable breaches. All breaches must be logged internally, even those you decide not to report.
- Over-notifying individuals. Sending panic-inducing emails for low-risk breaches erodes trust. Save direct notification for genuinely high-risk situations.
- Sharing sensitive information insecurely during response. Even during incident response, use secure channels. If you need to share internal reference links with your response team, tools like Lunyb let you create trackable, controllable short links so you can monitor access and revoke them once the incident is closed.
Building a Breach Response Plan Before You Need One
The organisations that handle breaches well are those that prepared before anything went wrong. A robust incident response plan should include:
1. Roles and Responsibilities
Identify a breach response lead, DPO, IT/security lead, legal counsel, communications lead, and executive sponsor. Every team member should know their role.
2. Detection and Escalation Procedures
Train all staff — not just IT — to recognise potential breaches and escalate them immediately. Most breaches are first spotted by frontline employees.
3. Assessment Templates
Pre-built risk assessment templates speed up the decision on whether to report and help ensure consistency.
4. Communication Templates
Draft templates for internal alerts, ICO submissions, customer notifications, and press statements. Editing a template under pressure is far easier than writing from scratch.
5. Regular Tabletop Exercises
Simulate breach scenarios at least annually. Include realistic elements — time pressure, incomplete information, media enquiries — so the team practises decision-making, not just process.
6. Vendor and Processor Contracts
Ensure your data processing agreements require processors to notify you "without undue delay" so you can meet your own 72-hour deadline.
Special Considerations for Different Sectors
Some sectors have additional obligations beyond UK GDPR:
- Financial services: May need to notify the FCA under SYSC and operational resilience rules.
- Healthcare: NHS organisations report through the Data Security and Protection Toolkit incident tool, which forwards to the ICO.
- Telecoms and ISPs: Must comply with PECR's 24-hour rule.
- Essential services and digital service providers: Additional obligations under the NIS Regulations, reporting to the relevant competent authority.
- Education: Schools should also consider Department for Education and safeguarding notification requirements.
Reducing the Risk of Future Breaches
Reporting is only part of the picture. The ICO expects organisations to learn from incidents. Practical steps include improving access controls, implementing multi-factor authentication, encrypting personal data at rest and in transit, running regular phishing simulations, reviewing third-party risk, and tightening data retention so you hold less data in the first place.
For organisations that share links containing customer or campaign data, using privacy-conscious tools matters. Solutions like Lunyb provide analytics and link management without unnecessary data collection, and if you're evaluating options, our 2026 URL shortener buyer's guide compares privacy features across leading providers.
Frequently Asked Questions
Do I need to report every data breach to the ICO?
No. You must only report breaches that are likely to result in a risk to the rights and freedoms of individuals. However, you must document every breach internally, including your reasoning for not reporting it. If you're unsure, the ICO recommends reporting.
What if I miss the 72-hour deadline?
Report as soon as you can and provide reasons for the delay. Late reporting is not automatically penalised, but the ICO will assess whether your reasons were justifiable. Genuine complexity of investigation is more acceptable than internal disorganisation.
What are the penalties for failing to report a data breach?
Failing to notify the ICO of a reportable breach can result in fines of up to £8.7 million or 2% of global annual turnover, whichever is higher. Additional penalties may apply for the underlying security failures that caused the breach.
Can I report a breach anonymously?
No — organisations reporting their own breaches must identify themselves. However, individuals who wish to raise a concern about how an organisation is handling their data can contact the ICO's helpline confidentially.
What information does the ICO make public about reported breaches?
The ICO does not routinely publish details of every reported breach. However, they do publish enforcement actions, including monetary penalty notices and reprimands, which typically name the organisation and describe the incident.
Final Thoughts
Reporting a data breach to the ICO is one of the most important obligations under UK GDPR — and one of the most time-sensitive. By understanding what qualifies as notifiable, preparing your response plan in advance, and engaging honestly with the regulator, you can navigate even a serious incident with your reputation and compliance record intact. The organisations that fare best aren't necessarily those that never experience breaches — they're the ones that respond quickly, transparently, and with a clear plan.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Improve Your Phone's Security Score: A Complete 2026 Guide
Your phone's security score reflects how well your device is protected against threats, data leaks, and unauthorized access. This guide walks you through practical, high-impact steps to raise that score on both iOS and Android. Follow these tactics to turn your smartphone into a hardened, privacy-first device.
How to Block Spam Calls and Robocalls on Your Phone (2026 Guide)
Spam calls and robocalls waste time and expose you to fraud. This guide walks through every free and paid method to block them on iPhone, Android, and at the carrier level in 2026.
How to Create a QR Code for Your Business: The Complete 2026 Guide
QR codes bridge physical and digital marketing like nothing else. This complete guide walks you through how to create a QR code for your business, from choosing between static and dynamic types to design, tracking, and printing best practices.
How to Check if Your Password Was Leaked in a Data Breach (2026 Guide)
Worried your credentials are floating around the dark web? Learn how to check if your password was leaked in a data breach using free, trusted tools — and exactly what steps to take next to lock down your accounts.