How to Report a Data Breach to the ICO: A UK Compliance Guide
Suffering a personal data breach is stressful, but under UK GDPR your reporting obligations to the Information Commissioner's Office (ICO) begin the moment you become aware of it. This guide walks you through exactly how to report a data breach to the ICO, what counts as a notifiable incident, and how to protect your organisation from regulatory penalties.
What Is a Personal Data Breach Under UK GDPR?
A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. This definition, taken from Article 4(12) of the UK GDPR, is deliberately broad and covers far more than just cyber attacks.
In practice, a breach can include:
- A lost or stolen laptop, phone, or USB stick containing personal data
- An email sent to the wrong recipient with personal information in it
- Ransomware encrypting customer records
- A misconfigured cloud storage bucket exposing files to the public internet
- An employee accessing records they have no legitimate reason to view
- Paper files left on a train or thrown in a public bin
The ICO distinguishes between three categories: confidentiality breaches (unauthorised disclosure), integrity breaches (unauthorised alteration), and availability breaches (loss of access, including through ransomware or accidental deletion). A single incident can fall into more than one category.
When Must You Report a Data Breach to the ICO?
You must notify the ICO within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals. The 72-hour clock starts ticking the moment you have a reasonable degree of certainty that a breach has occurred, not when your investigation concludes.
The Risk Threshold Explained
Not every breach is notifiable. The test is whether the breach is likely to result in a risk to individuals' rights and freedoms. The ICO expects you to consider:
- The type of breach (confidentiality, integrity, or availability)
- The nature, sensitivity, and volume of personal data involved
- How easily individuals could be identified
- The severity of consequences (financial loss, identity theft, reputational damage, discrimination, physical harm)
- Whether affected individuals include children or vulnerable people
- The number of individuals affected
If the breach is unlikely to result in a risk, you don't need to notify the ICO, but you must still document it internally. If the breach is likely to result in a high risk, you must also notify the affected individuals directly without undue delay.
Examples of Notifiable vs Non-Notifiable Breaches
| Scenario | Notify ICO? | Notify Individuals? |
|---|---|---|
| Encrypted laptop lost, strong password protection, key not compromised | Usually no | No |
| Unencrypted spreadsheet with 500 customer names and addresses emailed to wrong recipient | Yes | Depends on risk |
| Ransomware attack encrypting patient health records | Yes | Yes (high risk) |
| Employee sends an internal memo to one wrong colleague, no sensitive data | No | No |
| Public exposure of a database containing passwords or financial details | Yes | Yes (high risk) |
Step-by-Step: How to Report a Data Breach to the ICO
Follow these seven steps to meet your UK GDPR obligations properly.
- Contain the breach. Before doing anything else, stop the ongoing harm. Isolate affected systems, revoke compromised credentials, recall misdirected emails where possible, and secure any lost physical media.
- Assess the scope. Identify what personal data was involved, how many individuals are affected, what categories of data (including any special category data), and the likely consequences.
- Decide whether it's notifiable. Apply the risk threshold test. Document your reasoning either way. The ICO expects you to be able to justify a decision not to report.
- Gather the required information. Prepare the details you'll need: nature of the breach, categories and approximate number of data subjects and records, likely consequences, and mitigation measures taken or proposed.
- Submit your report to the ICO within 72 hours. Use the ICO's online reporting form at ico.org.uk, or call their breach helpline on 0303 123 1113 (option 3) during working hours.
- Notify affected individuals if required. If the breach is likely to result in a high risk, communicate directly with those affected in clear, plain language, explaining what happened and what they can do.
- Document everything. Maintain a breach register covering every incident, whether notifiable or not, including facts, effects, and remedial actions.
Using the ICO's Online Breach Reporting Form
The ICO strongly prefers online reporting for non-urgent submissions. The form is structured to capture the exact information Article 33 of the UK GDPR requires.
Information You'll Need Ready
- Your organisation details: registered name, ICO registration number, contact person, and DPO details if you have one
- Breach summary: when it happened, when you became aware, and how you discovered it
- Nature of the breach: confidentiality, integrity, availability, or a combination
- Data categories affected: basic personal identifiers, financial, health, criminal offence data, children's data, etc.
- Approximate numbers: data subjects affected and records involved
- Likely consequences for individuals
- Measures taken to address the breach and mitigate harm
- Whether individuals have been notified and how
What If You Don't Have All the Facts Within 72 Hours?
Article 33(4) allows for phased notification. If a full investigation isn't possible in time, submit what you know within 72 hours and mark the report as preliminary. You can then update the ICO in stages as more information emerges. Do not delay the initial report waiting for complete information.
If you report later than 72 hours, you must provide reasons for the delay. The ICO takes late reports seriously but is generally more lenient when you can demonstrate a good-faith reason and clear evidence of when awareness occurred.
Notifying Affected Individuals
When the breach is likely to result in a high risk to individuals, you must communicate directly with them without undue delay. This is separate from your ICO notification.
What Your Communication Must Include
- A clear, plain-language description of what happened
- Name and contact details of your DPO or another contact point
- The likely consequences of the breach
- The measures you've taken or propose to take
- Practical steps individuals can take to protect themselves (e.g., change passwords, monitor bank statements, watch for phishing)
Direct communication usually means email, letter, or SMS. Public notices (press releases, website banners) are only acceptable when direct contact would involve disproportionate effort, such as when contact details for affected individuals are unavailable.
When You Don't Need to Notify Individuals
You're exempt from notifying individuals if:
- You had appropriate technical protections in place (such as strong encryption) that made the data unintelligible to unauthorised parties
- You've taken subsequent measures that ensure the high risk is no longer likely to materialise
- Direct notification would involve disproportionate effort (public communication is required instead)
Penalties for Failing to Report
Failing to notify the ICO of a notifiable breach can attract administrative fines of up to £8.7 million or 2% of global annual turnover, whichever is higher. Serious infringements of UK GDPR generally can lead to fines of up to £17.5 million or 4% of turnover.
In practice, the ICO uses fines proportionately. Organisations that report promptly, cooperate fully, and demonstrate mature security practices are treated far more favourably than those that conceal breaches or respond poorly. British Airways and Marriott both received multi-million-pound fines partly because of the scale and sensitivity of the data involved, but their cooperation reduced the final penalties significantly from initial proposed amounts.
Building a Breach Response Plan Before You Need One
The 72-hour clock is unforgiving. Organisations that rehearse breach response ahead of time consistently outperform those improvising under pressure.
Key Elements of a Response Plan
- Named response team with clear roles: incident lead, DPO, IT/security, legal, communications, and executive sponsor
- Detection and escalation procedures so staff know how to report suspected breaches quickly
- Pre-drafted templates for ICO notification, individual communications, and internal updates
- Contact list including ICO helpline, external legal counsel, forensic investigators, and cyber insurers
- Decision framework for the risk threshold assessment
- Documentation register ready to populate
- Annual tabletop exercises to test the plan against realistic scenarios
Reducing Breach Risk in Everyday Operations
Prevention remains cheaper than remediation. Common measures include enforced multi-factor authentication, encrypted devices and backups, staff phishing training, least-privilege access controls, and careful handling of any tools that touch personal data or user tracking. Even something as routine as choosing a link management service matters: platforms like Lunyb that emphasise privacy-respecting analytics help reduce the volume of personal data you accumulate in the first place, and our 2026 URL shortener comparison outlines how different providers handle data protection responsibilities.
What Happens After You Report
Once the ICO receives your report, a case officer will typically acknowledge it within a few days. Depending on severity, they may:
- Take no further action beyond logging the incident
- Request additional information or clarification
- Open a formal investigation
- Issue guidance, warnings, or reprimands
- In serious cases, pursue enforcement action or fines
Cooperate promptly with any requests. Keep your incident documentation complete and accessible. If the ICO opens an investigation, consider engaging specialist data protection legal counsel early.
Special Considerations for Processors
If you're a data processor rather than a controller, your obligation is different. Under Article 33(2), you must notify the controller without undue delay after becoming aware of a breach. The controller then decides whether to report to the ICO. Your contract should specify notification timeframes, typically 24 to 48 hours to give the controller enough time to meet their own 72-hour deadline.
Frequently Asked Questions
How long do I have to report a data breach to the ICO?
You must report notifiable breaches to the ICO within 72 hours of becoming aware of them. If you can't provide full details in time, submit a preliminary report and follow up in phases. Late reports must be accompanied by an explanation for the delay.
Do I need to report every data breach?
No. You only need to notify the ICO of breaches that are likely to result in a risk to individuals' rights and freedoms. Low-risk incidents (like a misdirected internal email with no sensitive data) don't require ICO notification, but you must still record them in your internal breach register.
What's the difference between notifying the ICO and notifying individuals?
ICO notification is required for any breach likely to cause risk to individuals. Direct notification to affected individuals is only required when the breach is likely to result in a high risk. High-risk breaches typically involve sensitive data, financial information, or credentials that could enable further harm.
Can I be fined for reporting a breach?
The ICO does not fine organisations simply for reporting. Fines are typically issued for the underlying failures that caused the breach (such as inadequate security) or for failing to report when required. Prompt, honest reporting is generally viewed as a mitigating factor when the ICO assesses enforcement action.
What if I discover the breach happened months ago?
The 72-hour clock starts when you become aware of the breach, not when it originally occurred. Historic breaches discovered today should still be reported within 72 hours of discovery. Be prepared to explain why the breach wasn't detected sooner and what improvements you're making to detection capabilities.
Do I need a Data Protection Officer to handle breach reporting?
A DPO is only mandatory for public authorities and certain large-scale processing operations. However, even organisations without a formal DPO must designate someone responsible for data protection compliance, including breach response. Many smaller organisations retain external DPO services or specialist consultants for this purpose.
Final Thoughts
Reporting a data breach to the ICO is not optional under UK GDPR, and the 72-hour window means preparation matters more than reaction. Build your response plan now, document your risk assessment reasoning for every incident, and treat transparency as an asset rather than a liability. Organisations that report promptly and demonstrate accountability consistently fare better with regulators, customers, and the courts.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Block Trackers on Your Phone: The Complete 2026 Guide
Trackers follow you across apps, websites, and networks — but you can shut most of them down in under an hour. This complete 2026 guide walks through iOS and Android settings, private browsers, encrypted DNS, and app-level fixes to block trackers on your phone.
How to Create a Link in Bio Page in 2026: Complete Step-by-Step Guide
A link in bio page turns your single social profile URL into a hub for everything you offer. This step-by-step guide covers tools, design, analytics, and promotion so you can launch a high-converting bio page in under 30 minutes.
How to Do a Reverse Image Search to Find Your Photos Online
Learn how to run a reverse image search across Google, TinEye, and Yandex to find where your photos appear online. This step-by-step guide covers desktop and mobile methods, what to do when you find misuse, and how to protect your images going forward.
How to Create Branded Short Links: A Complete Step-by-Step Guide
Branded short links boost trust, click-through rates, and brand recall. This step-by-step guide shows exactly how to create them — from choosing a custom domain to launching your first link — plus best practices, tool comparisons, and advanced tips.