facebook-pixel

How to Report a Data Breach to the ICO: A Step-by-Step UK Guide

L
Lunyb Security Team
··10 min read

Discovering a personal data breach in your organisation is stressful, and the clock starts ticking the moment you become aware of it. Under the UK GDPR and the Data Protection Act 2018, most organisations have just 72 hours to notify the Information Commissioner's Office (ICO). This guide walks you through exactly how to report a data breach to the ICO, what information you'll need, and how to handle the aftermath in a way that protects both your customers and your business.

What Counts as a Personal Data Breach?

A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. In simpler terms: if personal information has been exposed, lost, or accessed by someone who shouldn't have seen it, you're likely dealing with a breach.

The ICO recognises three broad categories of personal data breach:

  • Confidentiality breach — unauthorised or accidental disclosure of, or access to, personal data (e.g. an email sent to the wrong recipient).
  • Integrity breach — unauthorised or accidental alteration of personal data (e.g. records tampered with by an attacker).
  • Availability breach — accidental or unauthorised loss of access to, or destruction of, personal data (e.g. a ransomware attack, or a lost unencrypted laptop).

Common real-world examples include lost USB sticks, stolen laptops, phishing attacks that expose customer databases, misconfigured cloud storage, emails sent to the wrong distribution list, and ransomware incidents.

Do You Have to Report Every Breach?

No. You only need to notify the ICO if the breach is likely to result in a risk to the rights and freedoms of individuals. If the risk is unlikely — for example, if the affected data was strongly encrypted and the decryption key remains secure — you may not need to report it. However, you must still document every breach internally, whether reportable or not.

The 72-Hour Rule: Understanding the Deadline

Article 33 of the UK GDPR requires data controllers to notify the ICO of a reportable personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it. The 72 hours includes weekends and bank holidays.

"Becoming aware" doesn't mean the moment the breach happened — it means the moment you have a reasonable degree of certainty that a security incident has occurred and that it involves personal data. A short investigation period to confirm the facts is acceptable and expected.

If you miss the 72-hour deadline, you can still report, but you must provide reasons for the delay. Late reporting without justification is itself a compliance failure and can attract enforcement action.

Step-by-Step: How to Report a Data Breach to the ICO

Here is the process you should follow from the moment you suspect a breach until your report is submitted.

  1. Contain the breach. Take immediate action to stop the incident from getting worse — revoke compromised credentials, isolate affected systems, recover lost devices, or take a leaked page offline.
  2. Assess the risk. Determine what data is involved, how many people are affected, and the likely consequences for those individuals (identity theft, financial loss, distress, physical harm, discrimination).
  3. Decide if the breach is notifiable. If there is a risk to the rights and freedoms of individuals, you must notify the ICO. If the risk is high, you must also notify the affected individuals directly.
  4. Gather the required information. The ICO's report form asks specific questions, so collect the facts before you start (see the next section).
  5. Submit your report to the ICO. Use the ICO's online reporting service at ico.org.uk, or call the ICO helpline on 0303 123 1113 during office hours for urgent cases.
  6. Notify affected individuals if required. When the risk is high, tell affected people in clear, plain language, and explain what they can do to protect themselves.
  7. Document everything. Keep a written record of the facts, effects, and remedial action taken — even for breaches you didn't report.

How to Submit the Report

The ICO offers several routes for reporting, depending on the urgency and nature of the incident:

Reporting MethodWhen to UseAvailability
Online self-report form (ico.org.uk)Most standard breaches24/7
ICO helpline (0303 123 1113)Urgent breaches during office hoursMon–Fri, 9am–5pm
Live chat via ico.org.ukQuick queries and guidanceOffice hours
Email or postFollow-up documentation onlyN/A for initial report

The online form is the most efficient option and creates an automatic audit trail. You will receive a case reference number, which you should quote in all subsequent correspondence.

Information You Need to Include in the Report

Article 33(3) of the UK GDPR sets out the minimum information that must be included. Prepare the following before you open the form:

  • Nature of the breach — what happened, when it happened, and when you became aware of it.
  • Categories of data — types of personal data involved (names, contact details, financial data, health data, special category data, etc.).
  • Categories and approximate number of individuals affected — customers, employees, patients, children, and so on.
  • Categories and approximate number of records concerned.
  • Likely consequences for the individuals affected.
  • Measures taken or proposed to address the breach and mitigate its effects.
  • Name and contact details of your Data Protection Officer (DPO) or another contact point.

If You Don't Have All the Information Yet

You don't need to have every detail nailed down before the 72-hour deadline. The ICO explicitly allows you to submit information in phases. Report what you know within 72 hours, flag that the investigation is ongoing, and provide updates as soon as new facts emerge.

When You Must Also Notify Affected Individuals

Under Article 34 of the UK GDPR, you must notify affected individuals directly if the breach is likely to result in a high risk to their rights and freedoms. Examples of high-risk breaches include:

  • Leaks of financial details that could enable fraud.
  • Exposure of passwords, especially where reuse is likely.
  • Disclosure of health, sexuality, religion, or other special category data.
  • Breaches involving children or vulnerable individuals.
  • Breaches likely to cause significant emotional distress, reputational damage, or physical safety concerns.

Your notification to individuals should be in clear, plain English (no legalese), and must include the nature of the breach, contact details for your DPO, likely consequences, and the measures you've taken. Crucially, you should also give practical advice — for example, telling people to change reused passwords, watch for phishing attempts, or monitor their bank accounts.

What Happens After You Report

Once your report is submitted, the ICO will assess the information provided and may take one of several paths:

  • No further action — for lower-severity incidents that have been handled appropriately.
  • Request for more information — if the ICO needs to understand what happened in more depth.
  • Investigation — for serious or systemic issues, the ICO may open a formal investigation.
  • Enforcement action — in the most serious cases, this can include reprimands, enforcement notices, or monetary penalties of up to £17.5 million or 4% of global annual turnover.

Cooperating fully, being transparent, and demonstrating that you have learned from the incident all count strongly in your favour. The ICO's approach is generally to work with organisations that show good faith, not to punish honest mistakes.

How to Reduce the Chance of a Breach in the First Place

Prevention is far cheaper than remediation. A layered approach to data protection typically involves technical, organisational, and cultural safeguards:

  • Encrypt everything at rest and in transit, especially laptops, USB drives, backups, and cloud storage.
  • Enforce multi-factor authentication on all business accounts, particularly email and admin panels.
  • Train staff regularly on phishing, social engineering, and safe handling of personal data.
  • Restrict access to personal data on a need-to-know basis, and audit access logs.
  • Patch and update operating systems, browsers, and third-party software promptly.
  • Vet your suppliers. When you share personal data with third parties — including marketing tools and link-tracking services — make sure they take security and data minimisation seriously. Tools such as Lunyb, a privacy-focused URL shortener, can help you share and track links without exposing your customers' data to opaque tracking ecosystems.
  • Have an incident response plan in place before you need it, including a documented breach reporting workflow.

If your business relies on shortened links for marketing, customer support, or internal communications, review the tools you use. Our 2026 URL shortener buyer's guide and honest review of Lunyb both explain what to look for from a data protection standpoint.

Common Mistakes to Avoid

Even well-meaning organisations trip up when handling a breach. Watch out for these pitfalls:

  • Waiting until you know everything. The 72-hour clock does not pause while you investigate.
  • Downplaying the incident in your report. The ICO can spot inconsistencies quickly, and understating a breach can be treated as a separate compliance failure.
  • Forgetting to notify individuals. Reporting to the ICO does not remove your obligation to tell affected people when the risk is high.
  • No internal record-keeping. You must document all breaches, including those you decided not to report.
  • Blaming a supplier without checking your own controls. As the controller, you're accountable for the personal data even if the incident occurred at a processor.

Special Cases: Processors, Joint Controllers, and Small Organisations

If you are a data processor (for example, an IT provider handling customer data on behalf of a client), you do not report to the ICO yourself. Instead, you must notify the controller without undue delay so they can meet their own 72-hour obligation. Your contract should set out the exact process and timing.

For joint controllers, the arrangement between the parties should set out who takes the lead on breach reporting, though ultimately both remain accountable.

Small organisations and sole traders are subject to the same rules as larger businesses. There is no exemption based on size, though the ICO does take proportionality into account when assessing enforcement.

Frequently Asked Questions

Do I need to report a data breach to the ICO if no one has actually been harmed?

You need to assess the likelihood of risk, not wait for actual harm. If the breach is likely to result in a risk to individuals' rights and freedoms, it must be reported to the ICO within 72 hours, even if no one has yet complained or suffered a loss.

What is the penalty for failing to report a breach on time?

Failure to notify the ICO can result in an administrative fine of up to £8.7 million or 2% of global annual turnover, whichever is higher. In practice, the ICO usually reserves the largest fines for serious, systemic, or dishonest failures. Transparent, cooperative reporting typically results in lighter outcomes.

Can I report a breach anonymously to the ICO?

No. A data controller cannot report anonymously because the ICO needs to know who is accountable. However, if you are an employee or a member of the public who wants to raise a concern about how an organisation has handled personal data, you can contact the ICO's helpline and, in some cases, request confidentiality.

What if the breach happened at a third-party supplier?

You remain responsible as the data controller. Your processor must inform you of any breach without undue delay, and the 72-hour clock for reporting to the ICO starts when you become aware. Make sure your processor contracts include clear breach notification obligations and timelines.

How long should I keep records of data breaches?

The UK GDPR does not set a specific retention period, but records should be kept long enough to demonstrate compliance and allow the ICO to verify your handling of incidents. Most organisations retain breach records for a minimum of three to six years, aligned with their broader accountability documentation.

Final Thoughts

Reporting a data breach to the ICO within 72 hours can feel daunting, but the process is designed to be workable — even for small organisations. The keys are speed, honesty, thorough documentation, and a genuine commitment to putting things right for the people whose data has been affected. Build a simple, rehearsed incident response plan now, before you need it, and the next breach — should it ever come — will be a manageable incident rather than a full-blown crisis.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles