How to Report a Data Breach to the ICO: A Complete UK Guide
If your organisation has suffered a personal data breach, you may be legally required to report it to the Information Commissioner's Office (ICO) within 72 hours of becoming aware of it. Failing to do so can result in significant fines under the UK GDPR and Data Protection Act 2018. This guide walks you through exactly how to report a data breach to the ICO, what information you'll need, and how to handle the process professionally.
What Is a Personal Data Breach Under UK GDPR?
A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. It's not just about hackers stealing data — it covers a wide range of incidents.
Under the UK GDPR, breaches fall into three broad categories:
- Confidentiality breach: Unauthorised or accidental disclosure or access to personal data (e.g. an email sent to the wrong recipient).
- Integrity breach: Unauthorised or accidental alteration of personal data.
- Availability breach: Accidental or unauthorised loss of access to, or destruction of, personal data (e.g. ransomware, lost devices).
Common examples include lost or stolen laptops, misdirected emails containing personal information, ransomware attacks, unauthorised system access, accidental deletion of records without backups, and paper files left on public transport.
Do You Need to Report the Breach to the ICO?
Not every data breach needs to be reported. Under Article 33 of the UK GDPR, you must notify the ICO only when a breach is likely to result in a risk to the rights and freedoms of individuals. If the risk is unlikely, you don't need to report — but you must still document the incident internally.
Factors That Indicate a Reportable Breach
- Type of data involved: Special category data (health, biometric, racial or ethnic origin), financial details, or identity documents typically carry higher risk.
- Volume of records affected: Large-scale breaches are more likely to require reporting.
- Ease of identification: Whether individuals can be readily identified from the exposed data.
- Potential consequences: Risk of identity theft, financial loss, reputational damage, discrimination, or physical harm.
- Vulnerability of affected individuals: Breaches involving children or vulnerable adults raise the risk profile.
When to Notify Affected Individuals
If the breach is likely to result in a high risk to individuals, you must also inform them directly, without undue delay. This is separate from your ICO notification and typically applies to more serious incidents.
The 72-Hour Reporting Deadline Explained
The clock starts ticking the moment you become aware of a breach — not when it happened. "Awareness" means you have a reasonable degree of certainty that a security incident has occurred and that it has led to personal data being compromised.
You have 72 hours from that point to notify the ICO. This includes weekends and public holidays. If you can't provide all the information within 72 hours, you can submit an initial notification and follow up with further details in phases — the ICO permits this.
If you report after 72 hours, you must provide reasons for the delay. The ICO takes late reporting seriously, so document your discovery timeline carefully.
Step-by-Step: How to Report a Data Breach to the ICO
Step 1: Contain the Breach Immediately
Before reporting, take urgent steps to stop the breach and limit the damage. This might involve isolating affected systems, revoking access credentials, recovering lost devices, or asking recipients of misdirected emails to delete them. Document every action taken with timestamps.
Step 2: Assess the Risk
Evaluate whether the breach meets the reporting threshold. Consider what data was involved, how many people are affected, and what real-world harm could result. Your Data Protection Officer (DPO) — if you have one — should lead this assessment.
Step 3: Gather the Required Information
The ICO's online reporting form requires specific details. Prepare the following before you begin:
- Your organisation's name, address, and ICO registration number
- Contact details for your DPO or breach contact person
- Date and time the breach occurred and was discovered
- Description of what happened and how
- Categories and approximate number of individuals affected
- Categories and approximate number of personal data records concerned
- Likely consequences of the breach
- Measures taken or proposed to address the breach and mitigate harm
- Whether you have informed affected individuals
Step 4: Choose Your Reporting Method
The ICO offers several ways to report a breach:
| Method | Best For | Availability |
|---|---|---|
| Online reporting form | Most breaches — fastest option | 24/7 via ico.org.uk |
| Breach helpline (0303 123 1113) | Urgent or complex cases | Mon-Fri, 9am-5pm |
| Written report by post | When digital options aren't available | Standard post to Wycliffe House |
Step 5: Submit Your Report
Complete the ICO's online form at ico.org.uk. Be honest and detailed — vague or misleading reports can trigger deeper investigations. If you don't have all the facts yet, say so, and commit to a timeline for follow-up information.
Step 6: Notify Affected Individuals (If Required)
If the breach poses a high risk, contact affected individuals directly in clear, plain language. Explain what happened, what data was involved, what steps you're taking, and what they can do to protect themselves (e.g. changing passwords, monitoring accounts).
Step 7: Document Everything
Whether reportable or not, you must keep an internal breach register. Include all facts, effects, and remedial actions. The ICO can request this documentation at any time to verify compliance.
What Happens After You Report
Once you've submitted your report, the ICO will acknowledge receipt, usually within a few working days. A case officer may contact you for further information. Depending on the severity, the ICO may:
- Take no further action beyond noting the report
- Provide guidance on how to improve your practices
- Launch a formal investigation
- Issue an enforcement notice or monetary penalty
Fines under the UK GDPR can reach up to £17.5 million or 4% of annual global turnover, whichever is higher. However, most breaches — especially those handled transparently — do not result in fines.
Common Mistakes to Avoid When Reporting
Delaying the Report to "Get More Information"
The ICO explicitly allows phased reporting. Don't wait past 72 hours hoping to submit a complete report — file an initial notification and update it later.
Underestimating the Breach
Downplaying the scale or impact to avoid regulatory attention often backfires. If the ICO later discovers the breach was worse than reported, penalties escalate significantly.
Failing to Notify Individuals
Some organisations report to the ICO but avoid telling affected individuals. If the risk is high, this is a separate legal obligation you cannot skip.
Poor Internal Documentation
Even non-reportable breaches must be logged. Missing records suggest broader compliance failures and can lead to enforcement action.
No Incident Response Plan
Trying to figure out roles and processes during an active breach wastes precious hours. Have a documented plan in place before you need it.
How to Prevent Future Data Breaches
Reporting a breach is reactive — prevention is far better. Practical steps include:
- Staff training: Human error causes most breaches. Regular training on phishing, secure email practices, and data handling dramatically reduces risk.
- Access controls: Apply the principle of least privilege. Employees should only access data they need for their role.
- Encryption: Encrypt personal data at rest and in transit. Encrypted lost devices often don't count as reportable breaches.
- Multi-factor authentication: Enable MFA on all business-critical accounts, including email and cloud storage.
- Secure link sharing: When sharing sensitive resources externally, use trusted link management tools. Services like Lunyb allow you to create trackable, password-protected short links so you can monitor access and revoke links if needed. For more on choosing a shortener that supports secure workflows, see our 2026 buyer's guide to URL shorteners.
- Regular audits: Review your data processing activities, third-party processors, and security controls at least annually.
- Backup and recovery: Maintain tested, offline backups to recover from ransomware or accidental deletion.
Special Considerations for Different Organisation Types
Small Businesses and Sole Traders
The 72-hour rule applies regardless of size. Small businesses often don't have a dedicated DPO, but you still need a named person responsible for data protection. Free resources on the ICO website are tailored to smaller organisations.
Public Sector Bodies
Public authorities must appoint a DPO and typically face heightened scrutiny. Report breaches through your organisation's established procedures and copy in relevant oversight bodies where required.
Data Processors vs Data Controllers
If you're a processor (handling data on behalf of another organisation), you must notify the controller "without undue delay" after becoming aware of a breach. The controller is then responsible for notifying the ICO.
Frequently Asked Questions
What happens if I miss the 72-hour deadline?
You can still report the breach — and you should, immediately. You'll need to explain the reasons for the delay. Late reporting can lead to enforcement action, but failing to report at all is far worse. The ICO values transparency over perfect timing.
Do I need to report a breach if data was encrypted?
Generally, no — if the encryption is strong and the decryption key wasn't compromised, the risk to individuals may be low enough that reporting isn't required. However, you should still document the incident internally and assess the specific circumstances.
Can I be fined for reporting a breach?
Reporting itself doesn't trigger fines. Penalties result from the underlying failures — inadequate security, non-compliance with UK GDPR principles, or failure to report when required. Voluntarily reporting and cooperating with the ICO is generally viewed as a mitigating factor.
What's the difference between reporting to the ICO and notifying individuals?
ICO notification is required when a breach poses any risk to individuals' rights and freedoms. Notifying affected individuals directly is only required when the risk is high. These are two separate legal obligations under UK GDPR Articles 33 and 34.
Do I need to report a phishing attempt that failed?
No. If no personal data was actually accessed, altered, lost, or disclosed, there is no breach to report. However, unsuccessful attacks should still be logged as security incidents and reviewed to strengthen your defences.
Final Thoughts
Reporting a data breach to the ICO can feel daunting, but the process is designed to be manageable when you're prepared. The three keys are: act quickly, be honest, and document everything. Organisations that treat data protection as an ongoing responsibility — rather than a checkbox exercise — handle breaches more effectively and face fewer regulatory consequences.
Invest in prevention: train your staff, secure your systems, and have a written incident response plan ready before you need it. When a breach does happen, you'll be able to respond calmly, meet your legal obligations, and protect the people whose data has been affected.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Shorten a URL: The Complete Step-by-Step Guide (2026)
Learn how to shorten a URL in seconds with this complete step-by-step guide. Covers free tools, custom branded links, click tracking, QR codes, mobile methods, and best practices to keep your links safe and professional.
How to Set Up Link Retargeting: A Complete Step-by-Step Guide
Link retargeting turns every shared URL into an audience-building asset — even links to content you don't own. This step-by-step guide shows you how to install pixels, create retargeting-enabled short links, build custom audiences, and launch high-ROI campaigns.
How to Improve Your Phone's Security Score: A Complete 2026 Guide
Your phone's security score reveals how well-protected your device really is. This complete 2026 guide walks through 10 practical steps — from screen locks and 2FA to permissions, encrypted backups, and monthly audits — to help you raise your score and dramatically reduce your risk of compromise.
Who Called Me? How to Identify an Unknown Number in 2026
Wondering who called you from an unknown number? This complete 2026 guide covers reverse lookup tools, scam-call red flags, and step-by-step methods to identify any caller. Learn how to protect your number and block unwanted calls for good.