How to Report a Data Breach to the ICO: A Complete UK Guide
If your organisation has suffered a personal data breach, you may have a legal duty to notify the Information Commissioner's Office (ICO) within 72 hours. Getting this process right protects data subjects, limits regulatory risk, and demonstrates accountability under the UK GDPR and Data Protection Act 2018.
This guide walks UK-based controllers and processors through exactly how to report a data breach to the ICO — from the initial assessment through to the follow-up notification and internal record-keeping.
What Counts as a Personal Data Breach?
A personal data breach is any security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. It is not limited to hacks or cyberattacks — human error and physical loss also qualify.
Under the UK GDPR (Article 4(12)), breaches fall into three overlapping categories:
- Confidentiality breach — unauthorised or accidental disclosure of, or access to, personal data (for example, an email sent to the wrong recipient).
- Integrity breach — unauthorised or accidental alteration of personal data.
- Availability breach — accidental or unauthorised loss of access to, or destruction of, personal data (for example, ransomware locking a database).
Common Examples of Reportable Breaches
- A laptop or unencrypted USB stick containing customer records is lost or stolen.
- A phishing attack compromises an employee mailbox containing personal data.
- Ransomware encrypts a system that stores client information.
- A misconfigured cloud storage bucket exposes data to the public internet.
- Personal data is emailed to the wrong recipient with no way to recall it.
- Paper files containing personal data are disposed of without shredding.
When Must You Report a Data Breach to the ICO?
You must notify the ICO within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals. If the breach is unlikely to pose such a risk, you do not need to notify — but you must still document it internally.
Assessing the Risk
The ICO expects controllers to make a considered judgement using factors such as:
- The type of breach (confidentiality, integrity or availability).
- The nature, sensitivity and volume of personal data involved.
- Ease of identification of the individuals affected.
- Severity of consequences (financial loss, identity theft, discrimination, distress, reputational damage).
- Special characteristics of the individuals (for example, vulnerable adults or children).
- The number of individuals affected.
If in doubt, err on the side of reporting. The ICO would rather receive a notification that turns out to be borderline than have a serious breach go unreported.
When to Notify Data Subjects as Well
If the breach is likely to result in a high risk to the rights and freedoms of individuals, you must also notify affected data subjects without undue delay. This is a higher threshold than notifying the ICO and typically applies to incidents involving financial data, health records, credentials or large-scale exposure.
The 72-Hour Clock: How It Works
The 72-hour countdown starts when you become aware of the breach — meaning you have a reasonable degree of certainty that a security incident occurred and that it involves personal data. It does not start when the incident itself happened, nor when it is fully investigated.
Importantly, the 72 hours include weekends and public holidays. If you cannot provide full details within this window, you can submit a partial (initial) report and follow up in phases as more information becomes available.
Step-by-Step: How to Report a Data Breach to the ICO
Step 1: Contain the Breach
Before notifying anyone externally, take immediate action to stop the breach from continuing or worsening. This might mean revoking compromised credentials, isolating affected systems, recalling misdirected emails, or physically securing lost devices where possible.
Step 2: Convene Your Incident Response Team
Bring together the roles you need to assess and manage the breach. Typically this includes your Data Protection Officer (DPO), IT/security lead, legal counsel, communications, and a senior decision-maker who can authorise notifications.
Step 3: Gather the Facts
Document what you know so far. The ICO's online form asks for:
- What happened, when it happened, and when you became aware.
- Categories and approximate number of individuals affected.
- Categories and approximate number of personal data records concerned.
- Likely consequences of the breach.
- Measures taken or proposed to address it and mitigate harm.
- Contact details of your DPO or a suitable point of contact.
Step 4: Assess Whether It's Reportable
Apply the risk assessment from earlier. Record your reasoning in your breach log — even if you decide not to notify. Documenting the decision-making process is a key part of GDPR accountability.
Step 5: Submit the Notification
You can report a breach to the ICO through several channels:
- Online — use the ICO's personal data breach reporting form on ico.org.uk (recommended and the fastest option).
- Telephone — call the ICO's breach helpline on 0303 123 1113 (Monday to Friday, 9am–5pm) for urgent guidance.
- Post — the ICO's postal address is: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
For non-cyber breaches (for example, a misdirected email), use the standard breach report form. For cyber incidents, use the dedicated cyber breach form, which asks additional questions about the nature of the attack.
Step 6: Notify Affected Individuals (If Required)
If the breach is high risk, communicate with affected individuals in clear, plain language. Your notification should describe the nature of the breach, likely consequences, and the steps you are taking, along with practical advice they can follow (such as changing passwords or monitoring statements).
Step 7: Follow Up With the ICO
If your initial report was partial, you must provide the remaining details in phases without undue further delay. Update the ICO as your investigation reveals new information about scope, cause or affected individuals.
Step 8: Record the Breach Internally
Every personal data breach — whether reported or not — must be logged in your internal breach register. Record the facts, effects, and remedial action taken. The ICO can request this record at any time.
What Information Does the ICO Ask For?
The table below summarises the core information required in a typical ICO notification.
| Category | Details Required |
|---|---|
| Organisation details | Name, address, sector, ICO registration number, DPO contact |
| Incident overview | Date and time of breach, date and time of discovery, how it was discovered |
| Nature of the breach | Confidentiality, integrity or availability; cause (e.g. phishing, human error, ransomware) |
| Data affected | Categories of personal data (contact details, financial data, health data, etc.), volume of records |
| Individuals affected | Categories (customers, employees, children, vulnerable adults), approximate number |
| Consequences | Likely impact on individuals — financial loss, distress, identity theft, discrimination |
| Mitigation | Steps taken to contain the breach and reduce harm |
| Data subject notification | Whether individuals have been informed, and if not, why |
What Happens After You Report?
Once you submit your notification, the ICO will acknowledge receipt and assign a case reference. An officer may contact you for further information, particularly if the breach is large, complex or affects vulnerable individuals.
Possible outcomes include:
- No further action — the ICO logs the report and takes no formal steps, often for well-managed, low-impact breaches.
- Advisory follow-up — the ICO recommends improvements to your controls or documentation.
- Formal investigation — for serious or systemic issues, the ICO can request evidence, conduct audits, and require remedial action.
- Enforcement — in severe cases, the ICO can issue enforcement notices, reprimands, or monetary penalties of up to £17.5 million or 4% of global annual turnover, whichever is higher.
Late or Missed Notifications
If you miss the 72-hour deadline, you must still notify the ICO — but explain the reasons for the delay. Failure to notify a reportable breach at all is itself a breach of the UK GDPR and can attract a separate fine.
The ICO tends to be pragmatic where controllers act in good faith, cooperate transparently and can demonstrate genuine efforts to investigate. It is much less forgiving where organisations attempt to conceal, minimise or delay reporting.
Special Cases: Processors, Joint Controllers and Cross-Border Breaches
Processors
If you are a processor (for example, a SaaS vendor), you must notify the controller without undue delay after becoming aware of a breach. The controller — not the processor — is responsible for notifying the ICO.
Joint Controllers
Joint controllers should have already agreed which party leads on breach notification in their arrangement under Article 26 UK GDPR. If not, both parties may need to notify to be safe.
Cross-Border Breaches
Following Brexit, the ICO no longer acts as a lead supervisory authority under the EU one-stop-shop mechanism. If your breach affects EU data subjects, you may also need to notify an EU supervisory authority — typically the one in the member state where your EU representative is based, or where affected individuals are located.
Preventing the Next Breach
A breach notification is only the beginning. The ICO expects organisations to learn from incidents and strengthen their controls. Practical steps include:
- Conduct a full root-cause analysis and document the findings.
- Update your risk register and Data Protection Impact Assessments (DPIAs).
- Refresh staff training, particularly around phishing and secure data handling.
- Review technical controls: encryption at rest and in transit, multi-factor authentication, access reviews, and encrypted DNS.
- Test your incident response plan through tabletop exercises at least annually.
- Audit third-party processors and update contracts to reflect lessons learned.
Reducing the surface area for phishing and credential theft is particularly important. Many breaches begin with a suspicious link — so equipping staff with tools that make link inspection easier matters. Trusted link-management services like Lunyb allow teams to shorten, brand and monitor URLs safely, while offering link previews that help recipients verify destinations before clicking. You can read more in our honest review of Lunyb or compare options in our 2026 URL shorteners buyer's guide.
Common Mistakes to Avoid
- Waiting for full facts before notifying. A partial report is acceptable and expected — do not miss the 72-hour deadline chasing certainty.
- Under-reporting the scope. If you later discover the breach is larger than reported, update the ICO promptly.
- Failing to log non-reportable breaches. Every breach must be documented internally, even if it does not meet the notification threshold.
- Not notifying individuals. A high-risk breach requires direct communication with affected people, not just the regulator.
- No incident response plan. Building the plan during a live incident wastes precious hours.
Frequently Asked Questions
How long do I have to report a data breach to the ICO?
You have 72 hours from the moment you become aware of a personal data breach that is likely to result in a risk to individuals' rights and freedoms. The clock includes weekends and bank holidays. If you cannot report within 72 hours, you must still notify and explain the delay.
What if I'm not sure whether the breach is serious enough to report?
If in doubt, notify. The ICO would rather assess a borderline case than discover an unreported serious breach later. Document your risk assessment in your breach register either way, so you can justify your decision if questioned.
Can I be fined for reporting a breach?
You are not fined simply for reporting. Penalties arise when the ICO finds that the underlying failure — inadequate security, poor governance, or delayed notification — breached the UK GDPR. Transparent, timely reporting typically works in your favour during any subsequent investigation.
Do I have to tell my customers about the breach?
Only if the breach is likely to result in a high risk to their rights and freedoms. In that case you must notify affected individuals directly, in clear language, without undue delay. For lower-risk breaches, ICO notification alone may be sufficient.
What if the breach happened at my supplier or processor?
The controller remains responsible for notifying the ICO, even when the breach originates with a processor. Your processor should inform you without undue delay under the terms of your Article 28 contract, giving you the information you need to meet the 72-hour deadline.
Final Thoughts
Reporting a data breach to the ICO is not just a compliance exercise — it is an opportunity to demonstrate accountability, maintain public trust, and improve your security posture. The organisations that handle breaches best are those that prepare in advance: a documented incident response plan, a trained team, a well-maintained breach register and clear escalation paths.
Treat every incident as a learning opportunity. Refine your controls, tighten your supplier oversight, and invest in the tools and training your staff need to spot threats before they turn into notifications.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Report a Scam Phone Number: A Complete Global Guide
Scam calls and texts cost consumers billions each year, but reporting them is easier than you think. This complete guide shows you exactly how to report a scam number to your carrier, national regulators, and messaging apps worldwide.
How to Hide Photos with an Encrypted Photo Vault: A Complete 2026 Guide
Learn how to hide photos with an encrypted photo vault in 2026. This step-by-step guide covers choosing a zero-knowledge app, setting up strong encryption, and avoiding common mistakes that leak private images.
How to Safely Share Your Location with Family: A Complete 2026 Guide
Sharing your location with loved ones is convenient, but the wrong setup can leak your movements to advertisers and worse. This guide covers the safest tools, step-by-step setup for iPhone and Android, and privacy settings to lock down before you share.
How to Password Protect a Short Link: A Complete 2026 Guide
Password-protecting a short link keeps confidential content safe even if the URL is forwarded or leaked. This 2026 guide walks through every step, compares the top shorteners that support the feature, and shares best practices for secure sharing.