facebook-pixel

How to Report a Data Breach to the ICO: A Complete UK Guide

L
Lunyb Security Team
··10 min read

If your organisation has suffered a personal data breach, UK GDPR requires you to act fast. In most cases, you have just 72 hours to report a notifiable breach to the Information Commissioner's Office (ICO). Failing to do so can result in significant fines and reputational damage. This guide walks you through exactly how to report a data breach to the ICO, what qualifies as notifiable, and what to do in the hours after you discover an incident.

What Is a Personal Data Breach Under UK GDPR?

A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. It's not limited to cyberattacks — human error, lost devices, and misdirected emails all count.

Under Article 4(12) of the UK GDPR, a breach falls into one of three categories:

  • Confidentiality breach — unauthorised or accidental disclosure of, or access to, personal data.
  • Integrity breach — unauthorised or accidental alteration of personal data.
  • Availability breach — accidental or unauthorised loss of access to, or destruction of, personal data.

Common examples include ransomware attacks, phishing incidents that expose customer records, laptops or USB sticks lost in transit, emails sent to the wrong recipient with attachments containing personal information, or misconfigured cloud storage exposing files to the public internet.

When Does a Breach Become "Notifiable"?

Not every breach must be reported. Under Article 33 UK GDPR, you must report a breach to the ICO only when it is likely to result in a risk to the rights and freedoms of natural persons. This means considering the potential for physical, material, or non-material damage — such as identity theft, financial loss, damage to reputation, discrimination, or loss of confidentiality.

If the risk is high, you must also notify the individuals affected without undue delay (Article 34). If in doubt, err on the side of reporting — the ICO is clear that under-reporting carries greater risk than over-reporting.

The 72-Hour Rule Explained

The clock starts ticking the moment you become aware of the breach — not when it happened. "Awareness" means having a reasonable degree of certainty that a security incident has occurred and led to personal data being compromised.

You have 72 hours from that point to notify the ICO. This includes weekends and bank holidays. If you can't provide all the information within 72 hours, submit what you have and follow up in phases — the ICO explicitly allows this under Article 33(4).

If you report late, you must explain the reasons for the delay. Legitimate reasons (such as a complex forensic investigation) may be accepted; disorganisation typically will not.

Step-by-Step: How to Report a Data Breach to the ICO

The ICO offers multiple reporting channels depending on the type and severity of the breach. Here's the standard process:

  1. Contain the breach. Before reporting, take immediate steps to stop the incident spreading. Isolate affected systems, revoke compromised credentials, and secure any physical media.
  2. Assess the risk. Determine what data was involved, how many people are affected, the likelihood of harm, and the severity of potential consequences.
  3. Decide if the breach is notifiable. Document your risk assessment even if you decide not to report — the ICO can ask to see this reasoning later.
  4. Gather the required information. You'll need details of the incident, categories and approximate number of data subjects, categories and approximate number of records, likely consequences, and measures taken or proposed.
  5. Submit your report. Use the ICO's online reporting tool at ico.org.uk or call their breach helpline on 0303 123 1113 (available 9am–5pm, Monday to Friday).
  6. Notify affected individuals if required. If the breach is high risk, communicate with data subjects in plain language, describing what happened and what they should do.
  7. Document everything. Maintain an internal breach register. This is a legal requirement under Article 33(5), regardless of whether the breach was reported.

Choosing the Right Reporting Channel

The ICO provides different pathways based on incident type:

  • General personal data breach: Online form via ico.org.uk/report-a-breach.
  • Cyber incident: A dedicated cyber-incident form that aligns with National Cyber Security Centre (NCSC) reporting.
  • Communications service providers (PECR): Different rules under the Privacy and Electronic Communications Regulations — must be reported within 24 hours.
  • Phone reporting: Recommended for urgent or complex incidents where you need immediate guidance.

Information You'll Need to Provide

The ICO's online form is comprehensive. Preparing this information in advance will save critical time during a live incident.

CategoryDetails Required
Organisation detailsName, ICO registration number, sector, contact details of the DPO or lead contact
Breach summaryDate and time of incident, date of awareness, cause, how it was discovered
Data affectedCategories of personal data (basic identifiers, financial, health, special category), approximate volume
Individuals affectedCategories (customers, employees, patients), approximate number
ConsequencesLikely impact, whether individuals have been notified
Remedial actionSteps taken to contain and mitigate, planned improvements
Cross-border elementWhether individuals in other jurisdictions are affected

What Happens After You Report

Once the ICO receives your notification, they will acknowledge receipt and assign a case reference number. What happens next depends on the severity and nature of the incident.

Possible Outcomes

  • No further action. For lower-risk breaches with good containment, the ICO may take no further action and simply file the report.
  • Advice and guidance. The ICO may provide recommendations for improving your security posture.
  • Formal investigation. Serious breaches trigger a detailed investigation, potentially involving audits, interviews, and requests for documentation.
  • Enforcement action. This can range from warnings and reprimands to enforcement notices and monetary penalties of up to £17.5 million or 4% of annual global turnover, whichever is higher.

Cooperating with the ICO

Transparency and cooperation are consistently viewed favourably. The ICO's regulatory action policy makes clear that self-reporting, honest engagement, and demonstrable improvements are mitigating factors. Attempting to conceal or downplay a breach almost always makes the outcome worse.

Notifying Affected Individuals

Where a breach is likely to result in a high risk to individuals' rights and freedoms, you must communicate directly with those affected. This notification must:

  1. Be written in clear, plain language.
  2. Describe the nature of the breach.
  3. Provide the name and contact details of your DPO or relevant contact point.
  4. Describe the likely consequences.
  5. Describe measures taken or proposed to address the breach and mitigate possible adverse effects.

You may be exempt from notifying individuals if you've implemented appropriate technical protection measures (such as strong encryption) that render the data unintelligible, if you've taken subsequent steps eliminating the high risk, or if notification would involve disproportionate effort — in which case a public communication is acceptable.

Common Mistakes That Make Breaches Worse

Handling a breach poorly compounds the damage. Watch out for these frequent errors:

  • Delaying investigation to "be sure" it's a breach. The 72-hour clock runs on awareness — you don't need certainty about every detail before reporting.
  • Reporting without containment. Notify the ICO, but only after taking immediate steps to stop the bleeding.
  • Poor internal communication. Staff should know who to escalate to. Many breaches worsen because the person who discovers them doesn't know the process.
  • Failing to document non-reportable breaches. All breaches must be logged internally, even those you decide not to report.
  • Over-notifying individuals. Sending panic-inducing emails for low-risk breaches erodes trust. Save direct notification for genuinely high-risk situations.
  • Sharing sensitive information insecurely during response. Even during incident response, use secure channels. If you need to share internal reference links with your response team, tools like Lunyb let you create trackable, controllable short links so you can monitor access and revoke them once the incident is closed.

Building a Breach Response Plan Before You Need One

The organisations that handle breaches well are those that prepared before anything went wrong. A robust incident response plan should include:

1. Roles and Responsibilities

Identify a breach response lead, DPO, IT/security lead, legal counsel, communications lead, and executive sponsor. Every team member should know their role.

2. Detection and Escalation Procedures

Train all staff — not just IT — to recognise potential breaches and escalate them immediately. Most breaches are first spotted by frontline employees.

3. Assessment Templates

Pre-built risk assessment templates speed up the decision on whether to report and help ensure consistency.

4. Communication Templates

Draft templates for internal alerts, ICO submissions, customer notifications, and press statements. Editing a template under pressure is far easier than writing from scratch.

5. Regular Tabletop Exercises

Simulate breach scenarios at least annually. Include realistic elements — time pressure, incomplete information, media enquiries — so the team practises decision-making, not just process.

6. Vendor and Processor Contracts

Ensure your data processing agreements require processors to notify you "without undue delay" so you can meet your own 72-hour deadline.

Special Considerations for Different Sectors

Some sectors have additional obligations beyond UK GDPR:

  • Financial services: May need to notify the FCA under SYSC and operational resilience rules.
  • Healthcare: NHS organisations report through the Data Security and Protection Toolkit incident tool, which forwards to the ICO.
  • Telecoms and ISPs: Must comply with PECR's 24-hour rule.
  • Essential services and digital service providers: Additional obligations under the NIS Regulations, reporting to the relevant competent authority.
  • Education: Schools should also consider Department for Education and safeguarding notification requirements.

Reducing the Risk of Future Breaches

Reporting is only part of the picture. The ICO expects organisations to learn from incidents. Practical steps include improving access controls, implementing multi-factor authentication, encrypting personal data at rest and in transit, running regular phishing simulations, reviewing third-party risk, and tightening data retention so you hold less data in the first place.

For organisations that share links containing customer or campaign data, using privacy-conscious tools matters. Solutions like Lunyb provide analytics and link management without unnecessary data collection, and if you're evaluating options, our 2026 URL shortener buyer's guide compares privacy features across leading providers.

Frequently Asked Questions

Do I need to report every data breach to the ICO?

No. You must only report breaches that are likely to result in a risk to the rights and freedoms of individuals. However, you must document every breach internally, including your reasoning for not reporting it. If you're unsure, the ICO recommends reporting.

What if I miss the 72-hour deadline?

Report as soon as you can and provide reasons for the delay. Late reporting is not automatically penalised, but the ICO will assess whether your reasons were justifiable. Genuine complexity of investigation is more acceptable than internal disorganisation.

What are the penalties for failing to report a data breach?

Failing to notify the ICO of a reportable breach can result in fines of up to £8.7 million or 2% of global annual turnover, whichever is higher. Additional penalties may apply for the underlying security failures that caused the breach.

Can I report a breach anonymously?

No — organisations reporting their own breaches must identify themselves. However, individuals who wish to raise a concern about how an organisation is handling their data can contact the ICO's helpline confidentially.

What information does the ICO make public about reported breaches?

The ICO does not routinely publish details of every reported breach. However, they do publish enforcement actions, including monetary penalty notices and reprimands, which typically name the organisation and describe the incident.

Final Thoughts

Reporting a data breach to the ICO is one of the most important obligations under UK GDPR — and one of the most time-sensitive. By understanding what qualifies as notifiable, preparing your response plan in advance, and engaging honestly with the regulator, you can navigate even a serious incident with your reputation and compliance record intact. The organisations that fare best aren't necessarily those that never experience breaches — they're the ones that respond quickly, transparently, and with a clear plan.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles