facebook-pixel

How to Report a Data Breach to the ICO: A UK Compliance Guide

L
Lunyb Security Team
··10 min read

Suffering a personal data breach is stressful, but under UK GDPR your reporting obligations to the Information Commissioner's Office (ICO) begin the moment you become aware of it. This guide walks you through exactly how to report a data breach to the ICO, what counts as a notifiable incident, and how to protect your organisation from regulatory penalties.

What Is a Personal Data Breach Under UK GDPR?

A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. This definition, taken from Article 4(12) of the UK GDPR, is deliberately broad and covers far more than just cyber attacks.

In practice, a breach can include:

  • A lost or stolen laptop, phone, or USB stick containing personal data
  • An email sent to the wrong recipient with personal information in it
  • Ransomware encrypting customer records
  • A misconfigured cloud storage bucket exposing files to the public internet
  • An employee accessing records they have no legitimate reason to view
  • Paper files left on a train or thrown in a public bin

The ICO distinguishes between three categories: confidentiality breaches (unauthorised disclosure), integrity breaches (unauthorised alteration), and availability breaches (loss of access, including through ransomware or accidental deletion). A single incident can fall into more than one category.

When Must You Report a Data Breach to the ICO?

You must notify the ICO within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals. The 72-hour clock starts ticking the moment you have a reasonable degree of certainty that a breach has occurred, not when your investigation concludes.

The Risk Threshold Explained

Not every breach is notifiable. The test is whether the breach is likely to result in a risk to individuals' rights and freedoms. The ICO expects you to consider:

  • The type of breach (confidentiality, integrity, or availability)
  • The nature, sensitivity, and volume of personal data involved
  • How easily individuals could be identified
  • The severity of consequences (financial loss, identity theft, reputational damage, discrimination, physical harm)
  • Whether affected individuals include children or vulnerable people
  • The number of individuals affected

If the breach is unlikely to result in a risk, you don't need to notify the ICO, but you must still document it internally. If the breach is likely to result in a high risk, you must also notify the affected individuals directly without undue delay.

Examples of Notifiable vs Non-Notifiable Breaches

ScenarioNotify ICO?Notify Individuals?
Encrypted laptop lost, strong password protection, key not compromisedUsually noNo
Unencrypted spreadsheet with 500 customer names and addresses emailed to wrong recipientYesDepends on risk
Ransomware attack encrypting patient health recordsYesYes (high risk)
Employee sends an internal memo to one wrong colleague, no sensitive dataNoNo
Public exposure of a database containing passwords or financial detailsYesYes (high risk)

Step-by-Step: How to Report a Data Breach to the ICO

Follow these seven steps to meet your UK GDPR obligations properly.

  1. Contain the breach. Before doing anything else, stop the ongoing harm. Isolate affected systems, revoke compromised credentials, recall misdirected emails where possible, and secure any lost physical media.
  2. Assess the scope. Identify what personal data was involved, how many individuals are affected, what categories of data (including any special category data), and the likely consequences.
  3. Decide whether it's notifiable. Apply the risk threshold test. Document your reasoning either way. The ICO expects you to be able to justify a decision not to report.
  4. Gather the required information. Prepare the details you'll need: nature of the breach, categories and approximate number of data subjects and records, likely consequences, and mitigation measures taken or proposed.
  5. Submit your report to the ICO within 72 hours. Use the ICO's online reporting form at ico.org.uk, or call their breach helpline on 0303 123 1113 (option 3) during working hours.
  6. Notify affected individuals if required. If the breach is likely to result in a high risk, communicate directly with those affected in clear, plain language, explaining what happened and what they can do.
  7. Document everything. Maintain a breach register covering every incident, whether notifiable or not, including facts, effects, and remedial actions.

Using the ICO's Online Breach Reporting Form

The ICO strongly prefers online reporting for non-urgent submissions. The form is structured to capture the exact information Article 33 of the UK GDPR requires.

Information You'll Need Ready

  • Your organisation details: registered name, ICO registration number, contact person, and DPO details if you have one
  • Breach summary: when it happened, when you became aware, and how you discovered it
  • Nature of the breach: confidentiality, integrity, availability, or a combination
  • Data categories affected: basic personal identifiers, financial, health, criminal offence data, children's data, etc.
  • Approximate numbers: data subjects affected and records involved
  • Likely consequences for individuals
  • Measures taken to address the breach and mitigate harm
  • Whether individuals have been notified and how

What If You Don't Have All the Facts Within 72 Hours?

Article 33(4) allows for phased notification. If a full investigation isn't possible in time, submit what you know within 72 hours and mark the report as preliminary. You can then update the ICO in stages as more information emerges. Do not delay the initial report waiting for complete information.

If you report later than 72 hours, you must provide reasons for the delay. The ICO takes late reports seriously but is generally more lenient when you can demonstrate a good-faith reason and clear evidence of when awareness occurred.

Notifying Affected Individuals

When the breach is likely to result in a high risk to individuals, you must communicate directly with them without undue delay. This is separate from your ICO notification.

What Your Communication Must Include

  • A clear, plain-language description of what happened
  • Name and contact details of your DPO or another contact point
  • The likely consequences of the breach
  • The measures you've taken or propose to take
  • Practical steps individuals can take to protect themselves (e.g., change passwords, monitor bank statements, watch for phishing)

Direct communication usually means email, letter, or SMS. Public notices (press releases, website banners) are only acceptable when direct contact would involve disproportionate effort, such as when contact details for affected individuals are unavailable.

When You Don't Need to Notify Individuals

You're exempt from notifying individuals if:

  • You had appropriate technical protections in place (such as strong encryption) that made the data unintelligible to unauthorised parties
  • You've taken subsequent measures that ensure the high risk is no longer likely to materialise
  • Direct notification would involve disproportionate effort (public communication is required instead)

Penalties for Failing to Report

Failing to notify the ICO of a notifiable breach can attract administrative fines of up to £8.7 million or 2% of global annual turnover, whichever is higher. Serious infringements of UK GDPR generally can lead to fines of up to £17.5 million or 4% of turnover.

In practice, the ICO uses fines proportionately. Organisations that report promptly, cooperate fully, and demonstrate mature security practices are treated far more favourably than those that conceal breaches or respond poorly. British Airways and Marriott both received multi-million-pound fines partly because of the scale and sensitivity of the data involved, but their cooperation reduced the final penalties significantly from initial proposed amounts.

Building a Breach Response Plan Before You Need One

The 72-hour clock is unforgiving. Organisations that rehearse breach response ahead of time consistently outperform those improvising under pressure.

Key Elements of a Response Plan

  1. Named response team with clear roles: incident lead, DPO, IT/security, legal, communications, and executive sponsor
  2. Detection and escalation procedures so staff know how to report suspected breaches quickly
  3. Pre-drafted templates for ICO notification, individual communications, and internal updates
  4. Contact list including ICO helpline, external legal counsel, forensic investigators, and cyber insurers
  5. Decision framework for the risk threshold assessment
  6. Documentation register ready to populate
  7. Annual tabletop exercises to test the plan against realistic scenarios

Reducing Breach Risk in Everyday Operations

Prevention remains cheaper than remediation. Common measures include enforced multi-factor authentication, encrypted devices and backups, staff phishing training, least-privilege access controls, and careful handling of any tools that touch personal data or user tracking. Even something as routine as choosing a link management service matters: platforms like Lunyb that emphasise privacy-respecting analytics help reduce the volume of personal data you accumulate in the first place, and our 2026 URL shortener comparison outlines how different providers handle data protection responsibilities.

What Happens After You Report

Once the ICO receives your report, a case officer will typically acknowledge it within a few days. Depending on severity, they may:

  • Take no further action beyond logging the incident
  • Request additional information or clarification
  • Open a formal investigation
  • Issue guidance, warnings, or reprimands
  • In serious cases, pursue enforcement action or fines

Cooperate promptly with any requests. Keep your incident documentation complete and accessible. If the ICO opens an investigation, consider engaging specialist data protection legal counsel early.

Special Considerations for Processors

If you're a data processor rather than a controller, your obligation is different. Under Article 33(2), you must notify the controller without undue delay after becoming aware of a breach. The controller then decides whether to report to the ICO. Your contract should specify notification timeframes, typically 24 to 48 hours to give the controller enough time to meet their own 72-hour deadline.

Frequently Asked Questions

How long do I have to report a data breach to the ICO?

You must report notifiable breaches to the ICO within 72 hours of becoming aware of them. If you can't provide full details in time, submit a preliminary report and follow up in phases. Late reports must be accompanied by an explanation for the delay.

Do I need to report every data breach?

No. You only need to notify the ICO of breaches that are likely to result in a risk to individuals' rights and freedoms. Low-risk incidents (like a misdirected internal email with no sensitive data) don't require ICO notification, but you must still record them in your internal breach register.

What's the difference between notifying the ICO and notifying individuals?

ICO notification is required for any breach likely to cause risk to individuals. Direct notification to affected individuals is only required when the breach is likely to result in a high risk. High-risk breaches typically involve sensitive data, financial information, or credentials that could enable further harm.

Can I be fined for reporting a breach?

The ICO does not fine organisations simply for reporting. Fines are typically issued for the underlying failures that caused the breach (such as inadequate security) or for failing to report when required. Prompt, honest reporting is generally viewed as a mitigating factor when the ICO assesses enforcement action.

What if I discover the breach happened months ago?

The 72-hour clock starts when you become aware of the breach, not when it originally occurred. Historic breaches discovered today should still be reported within 72 hours of discovery. Be prepared to explain why the breach wasn't detected sooner and what improvements you're making to detection capabilities.

Do I need a Data Protection Officer to handle breach reporting?

A DPO is only mandatory for public authorities and certain large-scale processing operations. However, even organisations without a formal DPO must designate someone responsible for data protection compliance, including breach response. Many smaller organisations retain external DPO services or specialist consultants for this purpose.

Final Thoughts

Reporting a data breach to the ICO is not optional under UK GDPR, and the 72-hour window means preparation matters more than reaction. Build your response plan now, document your risk assessment reasoning for every incident, and treat transparency as an asset rather than a liability. Organisations that report promptly and demonstrate accountability consistently fare better with regulators, customers, and the courts.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles