facebook-pixel

How to Report a Data Breach to the ICO: A Complete UK Guide

L
Lunyb Security Team
··10 min read

Reporting a data breach to the Information Commissioner's Office (ICO) is a legal obligation under the UK GDPR and Data Protection Act 2018. If your organisation suffers a personal data breach that poses a risk to individuals' rights and freedoms, you have just 72 hours to notify the regulator. Getting this process right matters: late or incomplete reporting can lead to significant fines, reputational damage and loss of customer trust.

This guide walks you through exactly how to report a data breach to the ICO, what information you need to gather, the timeline you must follow, and how to handle communications with affected individuals. Whether you're a data protection officer, IT manager or small business owner, you'll finish this article knowing precisely what to do when something goes wrong.

What Counts as a Personal Data Breach Under UK GDPR?

A personal data breach is a security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. It covers far more than hacking incidents.

The ICO recognises three broad categories of breach:

  • Confidentiality breach — unauthorised or accidental disclosure of, or access to, personal data (e.g. an email sent to the wrong recipient).
  • Integrity breach — unauthorised or accidental alteration of personal data (e.g. a database modified by an attacker).
  • Availability breach — accidental or unauthorised loss of access to, or destruction of, personal data (e.g. ransomware encrypting files, or a lost unencrypted laptop).

Common real-world examples include stolen devices, phishing attacks that expose credentials, misdirected post containing customer details, cloud storage buckets left publicly accessible, insider misuse of records, and system outages where backups fail.

When Does a Breach Need to Be Reported?

Not every incident requires ICO notification. You must report a breach if it is likely to result in a risk to the rights and freedoms of individuals. Risk assessment should consider the type of data, volume of records, ease of identification, severity of consequences, and the vulnerability of those affected (for example, children or vulnerable adults).

If the risk is high — such as potential identity theft, financial loss, discrimination, or significant distress — you must also inform the affected individuals directly, without undue delay.

The 72-Hour Rule: Understanding the Reporting Deadline

Article 33 of the UK GDPR requires notifiable breaches to be reported to the ICO within 72 hours of becoming aware of them. The clock starts when you have a reasonable degree of certainty that a security incident has occurred that led to personal data being compromised — not when the breach first happened or when the investigation finishes.

If you cannot provide all details within 72 hours, you can still submit an initial report and follow up with further information in phases. The ICO explicitly allows phased reporting, so there's no excuse for missing the deadline because you're still investigating.

If you report late, you must explain the reasons for the delay. Unjustified late reporting is itself a breach of the regulations and can attract separate enforcement action.

Step-by-Step: How to Report a Data Breach to the ICO

Follow these numbered steps to submit a complete and timely breach notification.

  1. Contain the breach. Before anything else, stop the incident from getting worse. Isolate affected systems, revoke compromised credentials, recall misdirected emails where possible, and secure physical records.
  2. Assess the scope and risk. Document what data was involved, how many individuals are affected, when the breach occurred, and the likely consequences. Use a documented risk assessment framework.
  3. Decide if notification is required. If the breach is unlikely to result in a risk to individuals, you don't need to notify the ICO — but you must still record it internally in your breach log.
  4. Gather the required information. Prepare the facts you'll need for the report (see the checklist below).
  5. Submit the report. Use the ICO's online reporting form at ico.org.uk, or call the breach helpline on 0303 123 1113 for urgent cases outside normal reporting routes.
  6. Notify affected individuals if required. If the risk is high, contact them directly in plain language, explaining what happened and what they should do.
  7. Follow up with the ICO. Provide any additional information as your investigation progresses, and keep the case reference number safe.
  8. Document everything. Keep a full internal record of the breach, your decisions and the remedial actions — even for breaches you didn't report.

Information You Need to Include in Your Report

The ICO's online form asks for structured information. Prepare the following before you start:

  • Your organisation's name, ICO registration number and contact details for the data protection officer or lead contact.
  • A description of the breach, including the date and time it occurred and when you became aware.
  • The categories and approximate number of individuals affected.
  • The categories and approximate number of personal data records concerned.
  • A description of the likely consequences for individuals.
  • The measures taken or proposed to address the breach and mitigate its effects.
  • Whether affected individuals have been (or will be) notified, and the method used.

How to Access the ICO Reporting Form

The ICO provides a dedicated online self-assessment and reporting tool. Navigate to ico.org.uk, go to the "Report a breach" section, and choose "Personal data breach". The tool will first ask screening questions to confirm whether the incident is reportable, then guide you through the full submission.

For telecoms and internet service providers, a separate PECR (Privacy and Electronic Communications Regulations) breach form exists, and the deadline is a strict 24 hours. Financial services firms may also have parallel obligations to the FCA, and NHS organisations to NHS Digital.

Tips for a Smooth Submission

  • Save your progress — the form allows you to return and complete it later with your reference number.
  • Use clear, factual language. Avoid speculation and separate confirmed facts from working hypotheses.
  • Attach supporting documents (such as risk assessments or forensic summaries) where helpful.
  • Nominate a single point of contact for ICO follow-up queries to avoid mixed messages.

Notifying Affected Individuals

When a breach poses a high risk to people's rights and freedoms, you must inform them directly. This is a separate obligation from notifying the ICO and is governed by Article 34 of the UK GDPR.

Your communication to individuals must include:

  • A description of the breach in clear and plain language.
  • The name and contact details of your data protection officer or relevant contact point.
  • The likely consequences of the breach.
  • The measures taken or proposed to mitigate possible adverse effects.
  • Practical steps the individual can take to protect themselves (e.g. changing passwords, monitoring bank statements, enabling multi-factor authentication).

You can avoid direct notification only in limited circumstances — for example, if you've applied strong encryption that renders the data unintelligible, if subsequent measures have eliminated the risk, or if direct contact would involve disproportionate effort (in which case a public communication is required instead).

Penalties for Failing to Report a Breach

The ICO can issue significant fines for failures around breach reporting. These sit in the lower tier of UK GDPR fines, capped at £8.7 million or 2% of annual global turnover, whichever is higher. Failures to secure data in the first place sit in the higher tier, capped at £17.5 million or 4% of turnover.

Beyond fines, the ICO can issue enforcement notices, reprimands, and compulsory audits. Perhaps more damaging in the long term is the reputational impact — breach decisions are published, and the news is often picked up by media.

Common Reasons the ICO Takes Enforcement Action

FailureTypical Consequence
Late or no breach notificationReprimand or lower-tier fine
Inadequate technical security measuresHigher-tier fine, enforcement notice
Failure to notify affected individualsReprimand, lower-tier fine
Poor internal breach recordsAudit, compliance order
Repeat offences or ignoring previous guidanceSubstantial fine, public censure

Building a Breach Response Plan Before You Need It

The organisations that handle breaches well are the ones that prepared in advance. A documented incident response plan should sit alongside your broader information security policies and be tested at least annually.

Key components include:

  1. Detection controls — logging, monitoring and alerting that help you identify breaches quickly.
  2. A designated response team — IT, legal, communications, HR and senior leadership roles pre-assigned.
  3. A triage playbook — decision trees for assessing risk and reportability.
  4. Pre-drafted templates — ICO submission notes, individual notification letters, press holding statements.
  5. Supplier contact list — forensics, legal counsel, PR and cyber insurance.
  6. A breach register — a running internal log of all incidents, reportable or not.

Reducing the attack surface in the first place is equally important. That means staff training, patching, strong access controls, encryption at rest and in transit, and careful management of the links and tools you share online. Using a trusted link management platform like Lunyb helps you avoid exposing raw internal URLs, track suspicious click patterns, and disable compromised links quickly — all small controls that reduce the chance of a reportable incident. For a deeper look at how it compares with alternatives, see our best URL shorteners guide for 2026.

Breaches by Third-Party Processors

If a data processor (such as a cloud provider or marketing agency) suffers a breach involving your data, they must notify you without undue delay. The reporting obligation to the ICO still falls on you as the data controller.

Make sure your contracts clearly define breach notification timelines — ideally 24 hours — so you have time to assess and report within the 72-hour window. Request detailed information about what happened, which of your records were affected, and what remediation steps the processor has taken.

After the Report: What Happens Next?

Once you submit a report, the ICO assigns a case officer who reviews the information. In many cases, no further action is required beyond acknowledging the report and asking you to confirm your remediation steps. For more serious breaches, the ICO may request additional evidence, interview staff, or launch a formal investigation.

You should expect written correspondence and should respond promptly and completely. Maintain a dedicated internal file for all communications. If the ICO proposes enforcement action, you'll have the right to make representations before any final decision.

Frequently Asked Questions

How quickly do I need to report a data breach to the ICO?

You must report notifiable personal data breaches within 72 hours of becoming aware of them. If you can't provide all the information in that window, submit an initial report and update it in phases as your investigation progresses.

Do I need to report every data breach to the ICO?

No. Only breaches that are likely to result in a risk to the rights and freedoms of individuals need to be reported. However, you must still record all breaches internally, including the facts, effects and remedial action, even if they aren't reportable externally.

What happens if I report a breach late?

Late reporting itself breaches the UK GDPR. You must explain the reason for the delay in your submission. Depending on the circumstances, the ICO may issue a reprimand, enforcement notice, or a lower-tier fine of up to £8.7 million or 2% of global turnover.

How do I know whether to notify affected individuals?

You must notify individuals directly when the breach is likely to result in a high risk to their rights and freedoms — for example, where there's a real chance of identity theft, financial loss, or significant distress. If data was strongly encrypted or the risk has otherwise been neutralised, direct notification may not be required.

Can a small business handle a breach report without a lawyer?

Yes. The ICO's online form is designed to be usable without legal support, and the regulator provides extensive guidance. That said, for serious incidents involving large volumes of data, sensitive categories, or potential media interest, specialist legal and forensic advice is strongly recommended.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles