facebook-pixel

How to Report a Data Breach to the ICO: A Step-by-Step UK Guide

L
Lunyb Security Team
··10 min read

If your organisation has suffered a personal data breach in the UK, you may have a legal duty to notify the Information Commissioner's Office (ICO) within 72 hours. Failing to report on time — or reporting poorly — can result in enforcement action and fines of up to £17.5 million or 4% of global annual turnover under the UK GDPR. This guide walks you through exactly how to report a data breach to the ICO, what information you need, and what happens after you submit.

What Counts as a Reportable Data Breach?

A personal data breach is any security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Not every breach needs to be reported to the ICO — only those likely to result in a risk to the rights and freedoms of individuals.

Examples of Reportable Breaches

  • A ransomware attack that encrypts customer records
  • Loss of an unencrypted laptop containing employee data
  • Sending an email with personal data to the wrong recipient (depending on scale and sensitivity)
  • Unauthorised access to a customer database
  • Accidental publication of a spreadsheet containing names and addresses
  • Theft of paper files from an office

Examples of Non-Reportable Breaches

  • An encrypted device is lost, but the encryption remains intact and unbroken
  • A short internal misdirection of a low-risk email swiftly recalled
  • Loss of pseudonymised data where re-identification is genuinely impossible

You must still record every breach internally, even the ones you don't report. The ICO can request your breach log at any time.

The 72-Hour Rule Explained

Under Article 33 of the UK GDPR, you must notify the ICO of a reportable breach "without undue delay and, where feasible, not later than 72 hours after having become aware of it." The clock starts the moment you have a reasonable degree of certainty that a breach has occurred — not when your investigation concludes.

What "Aware" Actually Means

You are considered "aware" when you have reasonable certainty that a security incident has occurred and has led to personal data being compromised. Initial suspicions do not always trigger the clock, but you must investigate promptly. Sitting on a suspicion for days while you "check" is not compliant.

What If You Miss the 72-Hour Window?

You can still report late, but you must justify the delay in your notification. The ICO takes late reporting seriously, but honest, well-reasoned delays with clear evidence of good faith are usually treated more leniently than concealment or negligence.

Step-by-Step: How to Report a Data Breach to the ICO

Follow this process as soon as you have confirmed a reportable breach.

  1. Contain the breach. Isolate affected systems, revoke compromised credentials, and stop the data leak from continuing.
  2. Assess the risk. Determine what data was affected, how many people, and the likely impact on them.
  3. Gather essential facts. Note the date and time of the breach, when you became aware, categories of data involved, and mitigation steps taken.
  4. Choose your reporting method. Use the ICO's online reporting form or call the breach helpline on 0303 123 1113 (option 3, then option 4) during working hours.
  5. Complete the notification form. Fill in all sections honestly. If you don't yet know every detail, submit what you have and note that further information will follow.
  6. Notify affected individuals if required. If the breach is likely to result in a high risk to their rights and freedoms, tell them directly without undue delay.
  7. Document everything internally. Keep a full record of the incident, your decisions, and communications.
  8. Follow up with the ICO. Provide additional information within a reasonable timeframe as your investigation progresses.

What Information the ICO Requires

The ICO's breach notification form is comprehensive. Preparing this information in advance dramatically speeds up the process.

SectionInformation Required
Your organisationName, ICO registration number, sector, size, and contact details of your Data Protection Officer (DPO) or responsible person
Breach detailsWhen it happened, when you became aware, cause (cyber attack, human error, theft, etc.), and whether it is ongoing
Data affectedCategories of personal data (names, emails, financial, health, special category), volume of records, and number of individuals
People affectedEmployees, customers, children, vulnerable individuals, or other categories
ConsequencesActual and potential harms — financial loss, identity theft, distress, discrimination, or physical harm
MitigationSteps taken to contain the breach, reduce impact, and prevent recurrence
CommunicationWhether affected individuals have been notified, how, and what they were told

How to Submit the Report

The ICO offers three main routes for reporting a breach. Choose the one that fits your situation.

1. Online Self-Assessment and Reporting Tool

Visit ico.org.uk and use the personal data breach reporting tool. It walks you through a self-assessment to confirm whether the breach is reportable, then leads directly to the notification form. This is the preferred method for most organisations because it creates a clear digital audit trail.

2. Telephone Reporting

Call the ICO breach helpline on 0303 123 1113 during working hours (9am–5pm, Monday to Friday). This is useful for very serious or complex breaches where you want immediate guidance. You will usually still need to follow up with a written submission.

3. Written Submission

In rare cases where online reporting is not possible, you can email or post a written report. The ICO strongly prefers the online form because it captures all required information in a standard structure.

When to Notify Affected Individuals

If a breach is likely to result in a high risk to individuals' rights and freedoms, you must tell them directly, in clear and plain language, without undue delay. This is separate from your ICO notification duty.

What to Tell Affected People

  • A description of what happened, in plain English
  • The name and contact details of your DPO or breach contact
  • The likely consequences of the breach for them
  • The measures you have taken or propose to take
  • Practical advice on how they can protect themselves — such as changing passwords, monitoring bank statements, or being alert to phishing

When You Don't Have to Notify Individuals

You are exempt from directly notifying individuals if:

  • The data was encrypted or otherwise made unintelligible to unauthorised parties
  • You have taken subsequent measures that ensure the high risk is unlikely to materialise
  • Direct communication would involve disproportionate effort — in which case a public communication is sufficient

Common Mistakes to Avoid

Even well-prepared organisations make errors when reporting to the ICO. Watch out for these pitfalls.

Waiting Too Long to Investigate

Some businesses treat the 72 hours as a deadline to start investigating, not to report. In reality, you should have breach response procedures ready to trigger the moment an incident is detected.

Under-Reporting or Downplaying

Trying to minimise the incident to avoid regulatory attention almost always backfires. The ICO cross-references breach reports with complaints from affected individuals, and inconsistencies raise red flags.

Over-Reporting Everything

Reporting every minor incident wastes your time and the ICO's. Use the self-assessment tool and document your reasoning if you decide not to report — this record protects you if questioned later.

Failing to Update the ICO

Your initial notification is rarely the full story. You have an ongoing duty to provide updates as facts emerge. Silence after the initial report can look like negligence.

Not Notifying Individuals When Required

Some organisations report to the ICO but fail to notify the affected people, hoping to avoid reputational damage. This is a separate legal breach and often leads to enforcement action.

What Happens After You Report

Once submitted, the ICO acknowledges receipt and assigns a case reference. What happens next depends on severity.

  1. Case triage. The ICO reviews your report and decides whether to close it, request more information, or open a formal investigation.
  2. Information requests. Expect follow-up questions. Respond promptly and honestly.
  3. Assessment of your response. The ICO looks at your containment, mitigation, and prevention measures. Strong evidence of good practice reduces risk of enforcement.
  4. Outcome. Possible outcomes range from no further action, to a warning, reprimand, enforcement notice, or in serious cases, a monetary penalty.

Most reported breaches result in no formal action, particularly where the organisation acted responsibly and transparently.

Preventing Future Breaches

Reporting is only half the story — the ICO expects you to learn from every incident. Consider these post-breach improvements:

  • Update your incident response plan based on lessons learned
  • Retrain staff on data handling, phishing awareness, and secure sharing
  • Review access controls and enforce the principle of least privilege
  • Enable multi-factor authentication on all business-critical systems
  • Deploy encrypted DNS, endpoint encryption, and network segmentation
  • Audit third-party processors and their security posture
  • Use privacy-conscious tools for common business tasks. For example, when sharing links containing tracking parameters or sensitive slugs, a privacy-respecting shortener like Lunyb can mask the underlying URL structure and reduce accidental data exposure in emails or public documents

If you're evaluating tools that handle link sharing across your organisation, our 2026 buyer's guide to URL shorteners compares privacy features across leading providers.

Special Cases: Processors, Joint Controllers, and Cross-Border Breaches

Reporting responsibilities differ depending on your role in the processing chain.

If You Are a Data Processor

Processors must notify their controller "without undue delay" after becoming aware of a breach. You do not report directly to the ICO — the controller does. Make sure your contracts define notification timelines (often 24–48 hours) so the controller has time to meet its own 72-hour deadline.

Joint Controllers

Joint controllers should agree in advance which party will handle ICO notifications. Duplicate reports cause confusion; missed reports cause enforcement.

Cross-Border Breaches

If your organisation operates across the UK and EU, you may need to notify multiple supervisory authorities. Since Brexit, the UK ICO handles UK breaches, while your EU lead supervisory authority handles EU-related incidents. Coordinate carefully to ensure consistent messaging.

Building a Breach Response Playbook

The organisations that handle breaches best are the ones that rehearse. A written playbook should include:

  • Clear roles and responsibilities (DPO, IT lead, legal, communications, executive sponsor)
  • Contact details for the ICO, cyber insurers, external counsel, and forensic responders
  • Pre-drafted notification templates for individuals and the ICO
  • Decision trees for whether a breach is reportable
  • Escalation paths and out-of-hours contacts
  • An annual tabletop exercise to stress-test the plan

Testing your response before a real incident happens is the single most effective way to hit the 72-hour deadline calmly and completely.

Frequently Asked Questions

Do I have to report every data breach to the ICO?

No. You only need to report breaches likely to result in a risk to individuals' rights and freedoms. However, you must document every breach internally — even the ones you decide not to report — along with your reasoning. The ICO can request this log during an audit or investigation.

What happens if I report a breach late?

Late reports are still accepted, but you must explain the reason for the delay in your notification. The ICO considers factors like the complexity of the incident and your good faith. Persistent lateness or deliberate concealment can lead to enforcement action, including fines.

Can I be fined just for having a data breach?

Not usually. Fines typically follow from failures in your data protection practices — inadequate security, poor response, or failure to notify — rather than from the breach itself. Organisations that respond transparently and demonstrate strong prior safeguards often avoid financial penalties.

Who in my organisation should report the breach?

Your Data Protection Officer (DPO), if you have one, is usually responsible. If not, a senior person with authority over data protection matters — such as an IT director, compliance officer, or company owner — should submit the report. The named contact must be able to answer follow-up questions from the ICO.

How long does the ICO take to respond after I report?

You will typically receive an acknowledgement and case reference within a few working days. Straightforward cases may close within weeks. Complex investigations can take several months, particularly if the ICO needs detailed technical evidence or witness interviews.

Do I need to tell my customers about the breach?

Only if the breach is likely to result in a high risk to their rights and freedoms — for example, if financial data, health information, or login credentials were exposed. In lower-risk cases, notifying the ICO alone is sufficient, though transparent communication often builds long-term trust.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles