facebook-pixel

How to Report a Data Breach to the ICO: A Step-by-Step UK Guide

L
Lunyb Security Team
··10 min read

If your organisation has suffered a personal data breach, UK GDPR gives you just 72 hours to notify the Information Commissioner's Office (ICO). Miss that window without a valid reason and you risk regulatory action, reputational damage and fines of up to £17.5 million or 4% of global annual turnover. This guide walks you through exactly how to report a data breach to the ICO, when reporting is required, and what to do before and after you submit the notification.

What Counts as a Personal Data Breach Under UK GDPR?

A personal data breach is any security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. It is not limited to malicious cyberattacks.

The ICO recognises three broad categories of breach:

  • Confidentiality breach – unauthorised or accidental disclosure of, or access to, personal data (for example, emailing a spreadsheet of customer records to the wrong recipient).
  • Integrity breach – unauthorised or accidental alteration of personal data (for example, a database record being changed by someone who shouldn't have access).
  • Availability breach – accidental or unauthorised loss of access to, or destruction of, personal data (for example, a ransomware attack that encrypts payroll files).

Everyday examples of reportable incidents include lost or stolen laptops holding unencrypted client data, phishing attacks that compromise staff mailboxes, misdirected post, cloud storage buckets left publicly accessible, and shortened tracking links exposing sensitive query strings. Even a filing cabinet being left unlocked overnight can qualify if personal data was exposed.

Do You Actually Need to Report the Breach?

Not every breach must be reported to the ICO. The legal test under Article 33 of the UK GDPR is whether the breach is likely to result in a risk to the rights and freedoms of individuals. If there is no risk, you must still document it internally, but you do not need to notify the regulator.

The Risk Assessment

When assessing risk, consider:

  1. The type of breach – confidentiality, integrity or availability.
  2. The nature and sensitivity of the data – special category data (health, ethnicity, sexuality) or financial information carries higher risk.
  3. Volume of records – a breach affecting thousands is generally more serious than one affecting a handful.
  4. Ease of identifying individuals – encrypted or pseudonymised data may reduce risk.
  5. Severity of consequences – could this lead to identity theft, financial loss, discrimination, distress or physical harm?
  6. Special characteristics of individuals – children and vulnerable adults require extra caution.

When You Must Notify Data Subjects Too

If the breach is likely to result in a high risk to individuals, Article 34 also requires you to notify the affected people directly, in clear and plain language, without undue delay. This is a higher threshold than ICO notification.

The 72-Hour Deadline Explained

You must report a notifiable breach to the ICO within 72 hours of becoming aware of it. "Becoming aware" means having a reasonable degree of certainty that a security incident has occurred and that personal data was compromised — not the moment an alert first pings.

The clock runs continuously, including weekends and bank holidays. If you miss the deadline, you can still report, but you must explain the reasons for the delay in your notification. The ICO treats unexplained lateness as an aggravating factor.

Phased Reporting Is Allowed

If you don't have all the facts within 72 hours, submit what you know and mark the report as incomplete. You can then provide further information in phases as your investigation progresses. This is far better than staying silent while you wait for a full picture.

Step-by-Step: How to Report a Data Breach to the ICO

The ICO offers two main routes for reporting: an online self-service form and a dedicated helpline. For most organisations, the online report is the fastest and most auditable option.

Step 1: Contain and Assess

Before you touch the ICO form, take immediate steps to stop the breach spreading. Revoke compromised credentials, isolate affected systems, recall misdirected emails using your mail server's recall function, and secure any physical documents. Document every action with timestamps — you'll need this evidence later.

Step 2: Gather Your Facts

The ICO form asks for specific information. Prepare the following before you start:

  • Your organisation's name, ICO registration number and sector.
  • Contact details of your Data Protection Officer or breach lead.
  • Date and time the breach occurred and was discovered.
  • A clear description of what happened.
  • Categories and approximate number of individuals affected.
  • Categories and approximate number of records affected.
  • Likely consequences for individuals.
  • Measures taken or proposed to address the breach and mitigate harm.

Step 3: Access the ICO Reporting Tool

Go to ico.org.uk and navigate to "Report a breach." Select "Personal data breach" and choose whether you're reporting as a controller or processor. The online form guides you through each section with contextual help.

Step 4: Call the Helpline if Urgent

If the breach is severe or you need immediate guidance, call the ICO's dedicated data breach helpline on 0303 123 1113 (Monday to Friday, 9am–5pm). Outside these hours, use the online form.

Step 5: Submit and Save the Reference

After submission, the ICO issues a case reference number. Save this, along with a PDF copy of the submitted form, in your breach register. You'll need it for all future correspondence.

Step 6: Follow Up with Additional Information

If you filed a phased report, submit updates as new facts emerge. The ICO may also contact you requesting further evidence, such as forensic reports, staff training records or your data protection impact assessments.

Notifying Affected Individuals

When individual notification is required, your message must include:

  1. A clear, plain-language description of the breach.
  2. The name and contact details of your DPO or a contact point.
  3. The likely consequences of the breach.
  4. The measures you have taken or propose to take, including steps to mitigate possible adverse effects.

Avoid legalese and burying the message. Email is common, but for large-scale breaches, a prominent website notice or press release may also be needed. Never use the notification as a marketing opportunity.

ICO Reporting Thresholds at a Glance

Scenario Notify ICO? Notify Individuals? Log Internally?
No risk to rights and freedoms No No Yes
Risk to rights and freedoms Yes, within 72 hours No (unless high risk) Yes
High risk to rights and freedoms Yes, within 72 hours Yes, without undue delay Yes
Encrypted data lost, keys secure Usually no No Yes
Processor notifies controller Controller decides Controller decides Both parties

Responsibilities: Controllers vs Processors

The primary duty to notify the ICO rests with the data controller. Processors — such as cloud hosts, payroll providers or marketing platforms — must notify their controller "without undue delay" once they become aware of a breach. Well-drafted contracts should specify exact timeframes, often 24 hours, to give the controller time to meet its own 72-hour obligation.

If you rely on third-party tools for anything that touches personal data — including link management, analytics or email — check their breach notification clauses. Providers like Lunyb that handle click data and shortened URLs should have documented incident response procedures you can reference in your own risk assessments. You can read more about how Lunyb operates in this honest review of the platform.

Building an Internal Breach Register

Article 33(5) of UK GDPR requires you to document all personal data breaches, regardless of whether they meet the reporting threshold. Your breach register should record:

  • Date and time of discovery and occurrence.
  • Description of the incident and root cause.
  • Data categories and volumes affected.
  • Risk assessment and reasoning for reporting decision.
  • Actions taken to contain, remediate and prevent recurrence.
  • Communications sent to the ICO and affected individuals.

The ICO can request this register at any time during an audit or investigation. A well-maintained log demonstrates accountability, which is itself a core UK GDPR principle.

Common Mistakes to Avoid

1. Over-Reporting Trivial Incidents

Reporting every minor mishap wastes ICO resources and dilutes your credibility. Use the risk-based test and document decisions not to report.

2. Under-Reporting to Avoid Attention

The opposite mistake is worse. If the ICO learns about a notifiable breach from a whistle-blower, journalist or affected individual before you report it, the penalty is far harsher.

3. Missing the Clock Start

Awareness begins when you have reasonable certainty, not when your board signs off the response plan. Train your IT and support teams to escalate suspected incidents immediately.

4. Vague Notifications to Individuals

"We experienced a security incident" is not enough. Be specific about what data was affected and what individuals should do — such as changing passwords, monitoring bank statements or being alert to phishing.

5. Failing to Learn from the Breach

The ICO expects post-incident reviews. Update your policies, patch the vulnerability, retrain staff and, where appropriate, run tabletop exercises to test the improvements.

Preventing Breaches in the First Place

Prevention will always be cheaper than response. Focus on the fundamentals:

  • Access control – enforce least privilege and multi-factor authentication on every account.
  • Encryption – encrypt data at rest and in transit; encrypted lost devices often fall outside notification requirements.
  • Staff training – phishing and misdirected emails cause the majority of UK breaches; regular training measurably reduces both.
  • Patch management – apply security updates promptly, especially to internet-facing systems.
  • Vendor due diligence – audit processors and require contractual breach commitments.
  • Data minimisation – you cannot lose data you never collected. Review retention schedules regularly.

For teams that share links externally — in marketing campaigns, support tickets or internal communications — using a shortener with granular access controls and audit logs reduces the chance of a URL exposing sensitive parameters. If you're comparing providers, our 2026 buyer's guide to URL shorteners covers the security features worth prioritising.

What Happens After You Report?

Once the ICO receives your notification, a case officer assesses the severity. Possible outcomes include:

  • No further action – for well-handled, lower-risk breaches.
  • Advisory letter – recommendations to improve your controls.
  • Formal investigation – detailed inquiry into your practices.
  • Enforcement notice – requiring specific corrective action.
  • Monetary penalty – fines up to £17.5 million or 4% of worldwide turnover.

Cooperation, transparency and evidence of a mature data protection programme all weigh in your favour. The ICO has repeatedly said it rewards organisations that self-report promptly and act decisively.

Frequently Asked Questions

What is the deadline to report a data breach to the ICO?

You must report a notifiable personal data breach to the ICO within 72 hours of becoming aware of it. If you miss this deadline, you can still report but must provide reasons for the delay. The clock includes weekends and public holidays.

What happens if I don't report a data breach?

Failing to report a notifiable breach can result in fines of up to £8.7 million or 2% of global annual turnover, whichever is higher, under UK GDPR. Fines for the underlying breach itself can reach £17.5 million or 4% of turnover. The ICO also considers non-reporting an aggravating factor when calculating penalties.

Do I need to report a breach if the data was encrypted?

Generally, if personal data was strongly encrypted and the decryption keys remain secure, the risk to individuals may be low enough that ICO notification is not required. You must still document the incident internally and assess the specific circumstances, because encryption alone doesn't guarantee no risk.

Who is responsible for reporting — the controller or the processor?

The data controller has the legal duty to notify the ICO. Processors must inform the controller "without undue delay" after becoming aware of a breach. Contracts between controllers and processors should set a specific timeframe, typically 24 hours, so the controller can meet its own 72-hour obligation.

Can I update my breach report after submission?

Yes. UK GDPR explicitly allows phased reporting. Submit what you know within 72 hours and clearly mark the report as incomplete. As your investigation uncovers more information, provide updates to the ICO using your original case reference number. This is far preferable to delaying the initial notification.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles