facebook-pixel

How to Report a Data Breach to the ICO: Step-by-Step UK Guide

L
Lunyb Security Team
··10 min read

If your organisation has suffered a personal data breach, UK GDPR gives you just 72 hours to notify the Information Commissioner's Office (ICO). Miss that window, get the paperwork wrong, or fail to assess the risk properly, and you could face fines of up to £17.5 million or 4% of global turnover. This guide walks you through exactly how to report a data breach to the ICO, when you must do it, what information you need, and what happens next.

What Counts as a Personal Data Breach Under UK GDPR?

A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. It is not limited to hacks or cyberattacks.

Common examples include:

  • An email containing customer records sent to the wrong recipient
  • A lost or stolen laptop, USB stick, or paper file containing personal data
  • Ransomware encrypting a database of employee information
  • A phishing attack that compromises staff login credentials
  • A misconfigured cloud storage bucket exposing records to the public internet
  • Accidental deletion of records with no backup

The ICO defines three breach categories, and your incident may involve more than one:

  • Confidentiality breach – unauthorised or accidental disclosure of, or access to, personal data
  • Integrity breach – unauthorised or accidental alteration of personal data
  • Availability breach – accidental or unauthorised loss of access to, or destruction of, personal data

Do You Actually Have to Report It?

Not every breach needs to go to the ICO. The legal test is whether the breach is likely to result in a risk to the rights and freedoms of individuals. If there is no such risk, you still have to record it internally, but you do not have to notify the regulator.

When Notification to the ICO Is Required

You must report to the ICO if the breach is likely to result in any risk to individuals. Examples of risk include:

  • Discrimination, identity theft, or fraud
  • Financial loss
  • Damage to reputation
  • Loss of confidentiality of data protected by professional secrecy
  • Any other significant economic or social disadvantage

When You Must Also Tell the Affected Individuals

If the breach is likely to result in a high risk to individuals, you must notify them directly, in clear and plain language, without undue delay. Encryption, pseudonymisation, or subsequent measures that make the risk unlikely to materialise can exempt you from this duty — but the ICO will scrutinise that assessment.

When You Don't Need to Report

If the data was strongly encrypted and the key was not compromised, or the breach involved only non-personal data, or the risk to individuals is genuinely negligible, you can log it internally without notifying the ICO. Keep a written risk assessment in case the regulator asks later.

The 72-Hour Clock: When Does It Start?

The 72-hour countdown begins the moment you become aware of a breach — not when it happened, and not when you have finished investigating. Awareness means you have a reasonable degree of certainty that a security incident has occurred that led to personal data being compromised.

A quick alert from an IT monitoring tool is usually not enough on its own; a short internal verification period is acceptable. But once you confirm personal data is involved, the clock is running, weekends and bank holidays included.

If you cannot provide all the information within 72 hours, you can submit a phased notification. Report what you know, flag it as incomplete, and update the ICO as the investigation progresses.

How to Report a Data Breach to the ICO: Step by Step

Step 1: Contain the Breach

Before anything else, stop the bleeding. Isolate affected systems, revoke compromised credentials, recall misdirected emails where possible, and preserve evidence (logs, screenshots, device images). Do not wipe anything you may need for forensic analysis.

Step 2: Assess the Risk

Document what happened, what data categories are involved, how many individuals are affected, and what the likely consequences are. The ICO expects you to consider:

  • The type of breach (confidentiality, integrity, availability)
  • The nature, sensitivity, and volume of personal data
  • Ease of identifying affected individuals from the data
  • Severity of consequences (financial, reputational, physical safety)
  • Special characteristics of the individuals (e.g. children, vulnerable adults)

Step 3: Choose Your Reporting Route

The ICO offers three ways to report, depending on urgency and sector:

  1. Online self-report form at ico.org.uk — the standard route for most organisations
  2. Telephone helpline on 0303 123 1113 (option 3) — available Monday to Friday, 9am–5pm, useful if you need guidance mid-report
  3. Dedicated routes for telecoms providers (PECR breaches), trust service providers (eIDAS), and NIS Regulations breaches, which have separate forms

Step 4: Complete the Online Breach Report Form

The form takes 20–40 minutes if you have your information ready. You will need:

  • Your organisation's name, ICO registration number, and sector
  • Contact details for your Data Protection Officer or breach lead
  • Date and time of the breach and date of discovery
  • A description of what happened and how
  • Categories and approximate number of individuals affected
  • Categories and approximate number of personal data records concerned
  • Likely consequences for individuals
  • Measures taken or proposed to address the breach and mitigate harm
  • Whether, and how, you have notified affected individuals

Step 5: Submit and Save Your Reference Number

On submission you will receive a case reference. Save the PDF confirmation to your breach register. This is your evidence of compliance with the 72-hour deadline.

Step 6: Follow Up With Further Information

If you filed a phased report, update the ICO as soon as you have more detail — typically within 7 days, but always as soon as reasonably possible. The case officer will usually acknowledge within a few working days and may request more information.

Information You Must Record Internally

Even for breaches you do not report, UK GDPR requires you to maintain an internal breach log. The ICO can ask to see this during any investigation or audit. Your record should include:

FieldWhat to Record
Incident ID & dateUnique reference and date/time of discovery
Facts of the breachWhat happened, where, how, who was involved
Data categoriesTypes of personal data (e.g. names, financial, special category)
Affected individualsNumber and categories (customers, staff, children)
Effects & consequencesLikely impact and actual harm identified
Remedial actionsContainment, mitigation, long-term fixes
Decision logWhy you did or did not notify the ICO or individuals

Notifying Affected Individuals

When the risk is high, individuals must be told without undue delay. The notification must be in clear, plain English and include at minimum:

  • A description of the nature of the breach
  • Name and contact details of your DPO or breach contact point
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach and mitigate harm
  • Practical advice individuals can take to protect themselves (e.g. change passwords, monitor bank statements)

Email is usually acceptable, but if contact details are unreliable or large numbers are affected, a public notice on your website combined with a press release may be appropriate.

What Happens After You Report

The ICO triages every report. Most straightforward cases are closed with no further action beyond acknowledging your notification and, sometimes, recommending improvements. More serious cases may lead to:

  • Information Notices requiring you to provide additional evidence
  • Assessment Notices permitting the ICO to carry out an audit
  • Enforcement Notices ordering specific action
  • Monetary Penalty Notices — fines up to £17.5m or 4% of global annual turnover
  • Reprimands — public findings of non-compliance without a financial penalty

In recent years the ICO has leaned more heavily on reprimands for public sector bodies and reserved large fines for cases involving major security failings or egregious disregard for data protection.

Common Mistakes to Avoid

1. Waiting Until You Have All the Answers

The 72-hour deadline is firm. A phased report with partial information is far better than a late one. Submit what you know and update later.

2. Underestimating Risk to Avoid Reporting

The ICO sees many cases where organisations argue a breach was low-risk, only for subsequent harm to emerge. If in doubt, report. Over-reporting is not penalised; under-reporting is.

3. Forgetting Processors Must Tell Controllers

If you are a processor (e.g. a SaaS vendor), you must notify your controller client without undue delay. The controller then has the duty to report to the ICO. Build this into your Data Processing Agreements.

4. Poor Internal Record-Keeping

If the ICO investigates and your breach register is sparse or missing, that itself is a UK GDPR violation. Treat the log as a legal document.

5. Weak Follow-Through on Remediation

The ICO expects you to learn from incidents. Document root cause analysis, policy updates, staff retraining, and technical changes.

Reducing the Risk of Breaches in the First Place

Prevention is cheaper than notification. Core measures that significantly reduce breach risk include encrypting data at rest and in transit, enforcing multi-factor authentication, running regular phishing simulations, applying least-privilege access controls, and keeping an up-to-date asset inventory. Even small operational changes — like using a privacy-respecting link management tool such as Lunyb instead of pasting raw tracking URLs that leak query-string personal data — can shrink your attack surface. You can read our honest review of Lunyb and compare it against alternatives in our 2026 buyer's guide to URL shorteners.

Sector-Specific Reporting Obligations

Alongside UK GDPR, certain sectors have additional reporting duties that may run in parallel:

Sector / RegulationAdditional Report RequiredTimeline
Telecoms & ISPs (PECR)ICO via PECR form24 hours
Financial services (FCA regulated)FCA under Principle 11 / SUP 15Without delay
NHS and health bodiesDSP Toolkit incident reporting72 hours
Essential services (NIS Regs)Competent authority (e.g. NCSC)72 hours
Payment services (PSD2)FCA via Connect4 hours (initial)

FAQ

How long do I have to report a data breach to the ICO?

You have 72 hours from the point you become aware of the breach. This includes weekends and bank holidays. If you cannot gather all the facts in time, submit a phased report with the information you have and update the ICO as your investigation progresses.

What happens if I report a data breach late?

Late notification is itself a UK GDPR infringement and can attract regulatory action, including fines of up to £8.7 million or 2% of global turnover. The ICO will expect a written explanation for the delay. Being transparent about why the deadline was missed, and demonstrating strong remediation, generally results in a more proportionate response.

Do I need to report every data breach to the ICO?

No. You only need to notify the ICO if the breach is likely to result in a risk to the rights and freedoms of individuals. All breaches must still be documented internally, including a written justification for any decision not to report.

Can I report a data breach anonymously as an employee or member of the public?

Yes. The ICO accepts breach concerns from third parties through its "Report a concern" channel. If you believe your personal data has been mishandled, or you are a whistleblower reporting your employer, you can raise this directly with the ICO without going through the organisation first.

Who should sign off on a data breach notification?

Typically your Data Protection Officer leads the process, with sign-off from a senior accountable person such as the CISO, General Counsel, or a board-level director. Make sure your incident response plan names specific roles rather than relying on availability, since the 72-hour clock will not pause for annual leave.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles