How to Report a Data Breach to the ICO: A Step-by-Step UK Guide
If your organisation has suffered a personal data breach in the UK, you may have a legal duty to notify the Information Commissioner's Office (ICO) within 72 hours. Failing to report on time — or reporting poorly — can result in enforcement action and fines of up to £17.5 million or 4% of global annual turnover under the UK GDPR. This guide walks you through exactly how to report a data breach to the ICO, what information you need, and what happens after you submit.
What Counts as a Reportable Data Breach?
A personal data breach is any security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Not every breach needs to be reported to the ICO — only those likely to result in a risk to the rights and freedoms of individuals.
Examples of Reportable Breaches
- A ransomware attack that encrypts customer records
- Loss of an unencrypted laptop containing employee data
- Sending an email with personal data to the wrong recipient (depending on scale and sensitivity)
- Unauthorised access to a customer database
- Accidental publication of a spreadsheet containing names and addresses
- Theft of paper files from an office
Examples of Non-Reportable Breaches
- An encrypted device is lost, but the encryption remains intact and unbroken
- A short internal misdirection of a low-risk email swiftly recalled
- Loss of pseudonymised data where re-identification is genuinely impossible
You must still record every breach internally, even the ones you don't report. The ICO can request your breach log at any time.
The 72-Hour Rule Explained
Under Article 33 of the UK GDPR, you must notify the ICO of a reportable breach "without undue delay and, where feasible, not later than 72 hours after having become aware of it." The clock starts the moment you have a reasonable degree of certainty that a breach has occurred — not when your investigation concludes.
What "Aware" Actually Means
You are considered "aware" when you have reasonable certainty that a security incident has occurred and has led to personal data being compromised. Initial suspicions do not always trigger the clock, but you must investigate promptly. Sitting on a suspicion for days while you "check" is not compliant.
What If You Miss the 72-Hour Window?
You can still report late, but you must justify the delay in your notification. The ICO takes late reporting seriously, but honest, well-reasoned delays with clear evidence of good faith are usually treated more leniently than concealment or negligence.
Step-by-Step: How to Report a Data Breach to the ICO
Follow this process as soon as you have confirmed a reportable breach.
- Contain the breach. Isolate affected systems, revoke compromised credentials, and stop the data leak from continuing.
- Assess the risk. Determine what data was affected, how many people, and the likely impact on them.
- Gather essential facts. Note the date and time of the breach, when you became aware, categories of data involved, and mitigation steps taken.
- Choose your reporting method. Use the ICO's online reporting form or call the breach helpline on 0303 123 1113 (option 3, then option 4) during working hours.
- Complete the notification form. Fill in all sections honestly. If you don't yet know every detail, submit what you have and note that further information will follow.
- Notify affected individuals if required. If the breach is likely to result in a high risk to their rights and freedoms, tell them directly without undue delay.
- Document everything internally. Keep a full record of the incident, your decisions, and communications.
- Follow up with the ICO. Provide additional information within a reasonable timeframe as your investigation progresses.
What Information the ICO Requires
The ICO's breach notification form is comprehensive. Preparing this information in advance dramatically speeds up the process.
| Section | Information Required |
|---|---|
| Your organisation | Name, ICO registration number, sector, size, and contact details of your Data Protection Officer (DPO) or responsible person |
| Breach details | When it happened, when you became aware, cause (cyber attack, human error, theft, etc.), and whether it is ongoing |
| Data affected | Categories of personal data (names, emails, financial, health, special category), volume of records, and number of individuals |
| People affected | Employees, customers, children, vulnerable individuals, or other categories |
| Consequences | Actual and potential harms — financial loss, identity theft, distress, discrimination, or physical harm |
| Mitigation | Steps taken to contain the breach, reduce impact, and prevent recurrence |
| Communication | Whether affected individuals have been notified, how, and what they were told |
How to Submit the Report
The ICO offers three main routes for reporting a breach. Choose the one that fits your situation.
1. Online Self-Assessment and Reporting Tool
Visit ico.org.uk and use the personal data breach reporting tool. It walks you through a self-assessment to confirm whether the breach is reportable, then leads directly to the notification form. This is the preferred method for most organisations because it creates a clear digital audit trail.
2. Telephone Reporting
Call the ICO breach helpline on 0303 123 1113 during working hours (9am–5pm, Monday to Friday). This is useful for very serious or complex breaches where you want immediate guidance. You will usually still need to follow up with a written submission.
3. Written Submission
In rare cases where online reporting is not possible, you can email or post a written report. The ICO strongly prefers the online form because it captures all required information in a standard structure.
When to Notify Affected Individuals
If a breach is likely to result in a high risk to individuals' rights and freedoms, you must tell them directly, in clear and plain language, without undue delay. This is separate from your ICO notification duty.
What to Tell Affected People
- A description of what happened, in plain English
- The name and contact details of your DPO or breach contact
- The likely consequences of the breach for them
- The measures you have taken or propose to take
- Practical advice on how they can protect themselves — such as changing passwords, monitoring bank statements, or being alert to phishing
When You Don't Have to Notify Individuals
You are exempt from directly notifying individuals if:
- The data was encrypted or otherwise made unintelligible to unauthorised parties
- You have taken subsequent measures that ensure the high risk is unlikely to materialise
- Direct communication would involve disproportionate effort — in which case a public communication is sufficient
Common Mistakes to Avoid
Even well-prepared organisations make errors when reporting to the ICO. Watch out for these pitfalls.
Waiting Too Long to Investigate
Some businesses treat the 72 hours as a deadline to start investigating, not to report. In reality, you should have breach response procedures ready to trigger the moment an incident is detected.
Under-Reporting or Downplaying
Trying to minimise the incident to avoid regulatory attention almost always backfires. The ICO cross-references breach reports with complaints from affected individuals, and inconsistencies raise red flags.
Over-Reporting Everything
Reporting every minor incident wastes your time and the ICO's. Use the self-assessment tool and document your reasoning if you decide not to report — this record protects you if questioned later.
Failing to Update the ICO
Your initial notification is rarely the full story. You have an ongoing duty to provide updates as facts emerge. Silence after the initial report can look like negligence.
Not Notifying Individuals When Required
Some organisations report to the ICO but fail to notify the affected people, hoping to avoid reputational damage. This is a separate legal breach and often leads to enforcement action.
What Happens After You Report
Once submitted, the ICO acknowledges receipt and assigns a case reference. What happens next depends on severity.
- Case triage. The ICO reviews your report and decides whether to close it, request more information, or open a formal investigation.
- Information requests. Expect follow-up questions. Respond promptly and honestly.
- Assessment of your response. The ICO looks at your containment, mitigation, and prevention measures. Strong evidence of good practice reduces risk of enforcement.
- Outcome. Possible outcomes range from no further action, to a warning, reprimand, enforcement notice, or in serious cases, a monetary penalty.
Most reported breaches result in no formal action, particularly where the organisation acted responsibly and transparently.
Preventing Future Breaches
Reporting is only half the story — the ICO expects you to learn from every incident. Consider these post-breach improvements:
- Update your incident response plan based on lessons learned
- Retrain staff on data handling, phishing awareness, and secure sharing
- Review access controls and enforce the principle of least privilege
- Enable multi-factor authentication on all business-critical systems
- Deploy encrypted DNS, endpoint encryption, and network segmentation
- Audit third-party processors and their security posture
- Use privacy-conscious tools for common business tasks. For example, when sharing links containing tracking parameters or sensitive slugs, a privacy-respecting shortener like Lunyb can mask the underlying URL structure and reduce accidental data exposure in emails or public documents
If you're evaluating tools that handle link sharing across your organisation, our 2026 buyer's guide to URL shorteners compares privacy features across leading providers.
Special Cases: Processors, Joint Controllers, and Cross-Border Breaches
Reporting responsibilities differ depending on your role in the processing chain.
If You Are a Data Processor
Processors must notify their controller "without undue delay" after becoming aware of a breach. You do not report directly to the ICO — the controller does. Make sure your contracts define notification timelines (often 24–48 hours) so the controller has time to meet its own 72-hour deadline.
Joint Controllers
Joint controllers should agree in advance which party will handle ICO notifications. Duplicate reports cause confusion; missed reports cause enforcement.
Cross-Border Breaches
If your organisation operates across the UK and EU, you may need to notify multiple supervisory authorities. Since Brexit, the UK ICO handles UK breaches, while your EU lead supervisory authority handles EU-related incidents. Coordinate carefully to ensure consistent messaging.
Building a Breach Response Playbook
The organisations that handle breaches best are the ones that rehearse. A written playbook should include:
- Clear roles and responsibilities (DPO, IT lead, legal, communications, executive sponsor)
- Contact details for the ICO, cyber insurers, external counsel, and forensic responders
- Pre-drafted notification templates for individuals and the ICO
- Decision trees for whether a breach is reportable
- Escalation paths and out-of-hours contacts
- An annual tabletop exercise to stress-test the plan
Testing your response before a real incident happens is the single most effective way to hit the 72-hour deadline calmly and completely.
Frequently Asked Questions
Do I have to report every data breach to the ICO?
No. You only need to report breaches likely to result in a risk to individuals' rights and freedoms. However, you must document every breach internally — even the ones you decide not to report — along with your reasoning. The ICO can request this log during an audit or investigation.
What happens if I report a breach late?
Late reports are still accepted, but you must explain the reason for the delay in your notification. The ICO considers factors like the complexity of the incident and your good faith. Persistent lateness or deliberate concealment can lead to enforcement action, including fines.
Can I be fined just for having a data breach?
Not usually. Fines typically follow from failures in your data protection practices — inadequate security, poor response, or failure to notify — rather than from the breach itself. Organisations that respond transparently and demonstrate strong prior safeguards often avoid financial penalties.
Who in my organisation should report the breach?
Your Data Protection Officer (DPO), if you have one, is usually responsible. If not, a senior person with authority over data protection matters — such as an IT director, compliance officer, or company owner — should submit the report. The named contact must be able to answer follow-up questions from the ICO.
How long does the ICO take to respond after I report?
You will typically receive an acknowledgement and case reference within a few working days. Straightforward cases may close within weeks. Complex investigations can take several months, particularly if the ICO needs detailed technical evidence or witness interviews.
Do I need to tell my customers about the breach?
Only if the breach is likely to result in a high risk to their rights and freedoms — for example, if financial data, health information, or login credentials were exposed. In lower-risk cases, notifying the ICO alone is sufficient, though transparent communication often builds long-term trust.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Lock Apps and Photos with Face ID: The Complete 2026 Guide
Learn how to lock apps and photos with Face ID on your iPhone using built-in iOS tools and trusted third-party options. This complete 2026 guide covers step-by-step instructions, hidden albums, notes, troubleshooting, and privacy best practices.
Who Called Me? How to Identify an Unknown Number in 2026
Getting calls from unknown numbers can be unnerving—and sometimes dangerous. This guide covers 8 proven methods to identify unknown callers, spot scams instantly, and protect your phone from unwanted contact in 2026.
How to Shorten a URL: The Complete 2026 Guide
Learn how to shorten a URL with this complete 2026 guide. Discover free tools, custom branded links, mobile methods, API integration, and best practices for safe, effective link sharing.
How to Remove Your Personal Information from Data Brokers (2026 Guide)
Data brokers quietly collect and sell your personal information to marketers, scammers, and anyone willing to pay. This step-by-step 2026 guide shows you how to remove your data from the top brokers, exercise your legal rights, and keep your information off these sites for good.