facebook-pixel

How to Report a Data Breach to the ICO: A Complete UK Guide

L
Lunyb Security Team
··10 min read

If your organisation has suffered a personal data breach, you may have a legal duty to notify the Information Commissioner's Office (ICO) within 72 hours. Getting this process right protects data subjects, limits regulatory risk, and demonstrates accountability under the UK GDPR and Data Protection Act 2018.

This guide walks UK-based controllers and processors through exactly how to report a data breach to the ICO — from the initial assessment through to the follow-up notification and internal record-keeping.

What Counts as a Personal Data Breach?

A personal data breach is any security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. It is not limited to hacks or cyberattacks — human error and physical loss also qualify.

Under the UK GDPR (Article 4(12)), breaches fall into three overlapping categories:

  • Confidentiality breach — unauthorised or accidental disclosure of, or access to, personal data (for example, an email sent to the wrong recipient).
  • Integrity breach — unauthorised or accidental alteration of personal data.
  • Availability breach — accidental or unauthorised loss of access to, or destruction of, personal data (for example, ransomware locking a database).

Common Examples of Reportable Breaches

  • A laptop or unencrypted USB stick containing customer records is lost or stolen.
  • A phishing attack compromises an employee mailbox containing personal data.
  • Ransomware encrypts a system that stores client information.
  • A misconfigured cloud storage bucket exposes data to the public internet.
  • Personal data is emailed to the wrong recipient with no way to recall it.
  • Paper files containing personal data are disposed of without shredding.

When Must You Report a Data Breach to the ICO?

You must notify the ICO within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals. If the breach is unlikely to pose such a risk, you do not need to notify — but you must still document it internally.

Assessing the Risk

The ICO expects controllers to make a considered judgement using factors such as:

  1. The type of breach (confidentiality, integrity or availability).
  2. The nature, sensitivity and volume of personal data involved.
  3. Ease of identification of the individuals affected.
  4. Severity of consequences (financial loss, identity theft, discrimination, distress, reputational damage).
  5. Special characteristics of the individuals (for example, vulnerable adults or children).
  6. The number of individuals affected.

If in doubt, err on the side of reporting. The ICO would rather receive a notification that turns out to be borderline than have a serious breach go unreported.

When to Notify Data Subjects as Well

If the breach is likely to result in a high risk to the rights and freedoms of individuals, you must also notify affected data subjects without undue delay. This is a higher threshold than notifying the ICO and typically applies to incidents involving financial data, health records, credentials or large-scale exposure.

The 72-Hour Clock: How It Works

The 72-hour countdown starts when you become aware of the breach — meaning you have a reasonable degree of certainty that a security incident occurred and that it involves personal data. It does not start when the incident itself happened, nor when it is fully investigated.

Importantly, the 72 hours include weekends and public holidays. If you cannot provide full details within this window, you can submit a partial (initial) report and follow up in phases as more information becomes available.

Step-by-Step: How to Report a Data Breach to the ICO

Step 1: Contain the Breach

Before notifying anyone externally, take immediate action to stop the breach from continuing or worsening. This might mean revoking compromised credentials, isolating affected systems, recalling misdirected emails, or physically securing lost devices where possible.

Step 2: Convene Your Incident Response Team

Bring together the roles you need to assess and manage the breach. Typically this includes your Data Protection Officer (DPO), IT/security lead, legal counsel, communications, and a senior decision-maker who can authorise notifications.

Step 3: Gather the Facts

Document what you know so far. The ICO's online form asks for:

  • What happened, when it happened, and when you became aware.
  • Categories and approximate number of individuals affected.
  • Categories and approximate number of personal data records concerned.
  • Likely consequences of the breach.
  • Measures taken or proposed to address it and mitigate harm.
  • Contact details of your DPO or a suitable point of contact.

Step 4: Assess Whether It's Reportable

Apply the risk assessment from earlier. Record your reasoning in your breach log — even if you decide not to notify. Documenting the decision-making process is a key part of GDPR accountability.

Step 5: Submit the Notification

You can report a breach to the ICO through several channels:

  • Online — use the ICO's personal data breach reporting form on ico.org.uk (recommended and the fastest option).
  • Telephone — call the ICO's breach helpline on 0303 123 1113 (Monday to Friday, 9am–5pm) for urgent guidance.
  • Post — the ICO's postal address is: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.

For non-cyber breaches (for example, a misdirected email), use the standard breach report form. For cyber incidents, use the dedicated cyber breach form, which asks additional questions about the nature of the attack.

Step 6: Notify Affected Individuals (If Required)

If the breach is high risk, communicate with affected individuals in clear, plain language. Your notification should describe the nature of the breach, likely consequences, and the steps you are taking, along with practical advice they can follow (such as changing passwords or monitoring statements).

Step 7: Follow Up With the ICO

If your initial report was partial, you must provide the remaining details in phases without undue further delay. Update the ICO as your investigation reveals new information about scope, cause or affected individuals.

Step 8: Record the Breach Internally

Every personal data breach — whether reported or not — must be logged in your internal breach register. Record the facts, effects, and remedial action taken. The ICO can request this record at any time.

What Information Does the ICO Ask For?

The table below summarises the core information required in a typical ICO notification.

CategoryDetails Required
Organisation detailsName, address, sector, ICO registration number, DPO contact
Incident overviewDate and time of breach, date and time of discovery, how it was discovered
Nature of the breachConfidentiality, integrity or availability; cause (e.g. phishing, human error, ransomware)
Data affectedCategories of personal data (contact details, financial data, health data, etc.), volume of records
Individuals affectedCategories (customers, employees, children, vulnerable adults), approximate number
ConsequencesLikely impact on individuals — financial loss, distress, identity theft, discrimination
MitigationSteps taken to contain the breach and reduce harm
Data subject notificationWhether individuals have been informed, and if not, why

What Happens After You Report?

Once you submit your notification, the ICO will acknowledge receipt and assign a case reference. An officer may contact you for further information, particularly if the breach is large, complex or affects vulnerable individuals.

Possible outcomes include:

  • No further action — the ICO logs the report and takes no formal steps, often for well-managed, low-impact breaches.
  • Advisory follow-up — the ICO recommends improvements to your controls or documentation.
  • Formal investigation — for serious or systemic issues, the ICO can request evidence, conduct audits, and require remedial action.
  • Enforcement — in severe cases, the ICO can issue enforcement notices, reprimands, or monetary penalties of up to £17.5 million or 4% of global annual turnover, whichever is higher.

Late or Missed Notifications

If you miss the 72-hour deadline, you must still notify the ICO — but explain the reasons for the delay. Failure to notify a reportable breach at all is itself a breach of the UK GDPR and can attract a separate fine.

The ICO tends to be pragmatic where controllers act in good faith, cooperate transparently and can demonstrate genuine efforts to investigate. It is much less forgiving where organisations attempt to conceal, minimise or delay reporting.

Special Cases: Processors, Joint Controllers and Cross-Border Breaches

Processors

If you are a processor (for example, a SaaS vendor), you must notify the controller without undue delay after becoming aware of a breach. The controller — not the processor — is responsible for notifying the ICO.

Joint Controllers

Joint controllers should have already agreed which party leads on breach notification in their arrangement under Article 26 UK GDPR. If not, both parties may need to notify to be safe.

Cross-Border Breaches

Following Brexit, the ICO no longer acts as a lead supervisory authority under the EU one-stop-shop mechanism. If your breach affects EU data subjects, you may also need to notify an EU supervisory authority — typically the one in the member state where your EU representative is based, or where affected individuals are located.

Preventing the Next Breach

A breach notification is only the beginning. The ICO expects organisations to learn from incidents and strengthen their controls. Practical steps include:

  1. Conduct a full root-cause analysis and document the findings.
  2. Update your risk register and Data Protection Impact Assessments (DPIAs).
  3. Refresh staff training, particularly around phishing and secure data handling.
  4. Review technical controls: encryption at rest and in transit, multi-factor authentication, access reviews, and encrypted DNS.
  5. Test your incident response plan through tabletop exercises at least annually.
  6. Audit third-party processors and update contracts to reflect lessons learned.

Reducing the surface area for phishing and credential theft is particularly important. Many breaches begin with a suspicious link — so equipping staff with tools that make link inspection easier matters. Trusted link-management services like Lunyb allow teams to shorten, brand and monitor URLs safely, while offering link previews that help recipients verify destinations before clicking. You can read more in our honest review of Lunyb or compare options in our 2026 URL shorteners buyer's guide.

Common Mistakes to Avoid

  • Waiting for full facts before notifying. A partial report is acceptable and expected — do not miss the 72-hour deadline chasing certainty.
  • Under-reporting the scope. If you later discover the breach is larger than reported, update the ICO promptly.
  • Failing to log non-reportable breaches. Every breach must be documented internally, even if it does not meet the notification threshold.
  • Not notifying individuals. A high-risk breach requires direct communication with affected people, not just the regulator.
  • No incident response plan. Building the plan during a live incident wastes precious hours.

Frequently Asked Questions

How long do I have to report a data breach to the ICO?

You have 72 hours from the moment you become aware of a personal data breach that is likely to result in a risk to individuals' rights and freedoms. The clock includes weekends and bank holidays. If you cannot report within 72 hours, you must still notify and explain the delay.

What if I'm not sure whether the breach is serious enough to report?

If in doubt, notify. The ICO would rather assess a borderline case than discover an unreported serious breach later. Document your risk assessment in your breach register either way, so you can justify your decision if questioned.

Can I be fined for reporting a breach?

You are not fined simply for reporting. Penalties arise when the ICO finds that the underlying failure — inadequate security, poor governance, or delayed notification — breached the UK GDPR. Transparent, timely reporting typically works in your favour during any subsequent investigation.

Do I have to tell my customers about the breach?

Only if the breach is likely to result in a high risk to their rights and freedoms. In that case you must notify affected individuals directly, in clear language, without undue delay. For lower-risk breaches, ICO notification alone may be sufficient.

What if the breach happened at my supplier or processor?

The controller remains responsible for notifying the ICO, even when the breach originates with a processor. Your processor should inform you without undue delay under the terms of your Article 28 contract, giving you the information you need to meet the 72-hour deadline.

Final Thoughts

Reporting a data breach to the ICO is not just a compliance exercise — it is an opportunity to demonstrate accountability, maintain public trust, and improve your security posture. The organisations that handle breaches best are those that prepare in advance: a documented incident response plan, a trained team, a well-maintained breach register and clear escalation paths.

Treat every incident as a learning opportunity. Refine your controls, tighten your supplier oversight, and invest in the tools and training your staff need to spot threats before they turn into notifications.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles