How to Report a Data Breach to the ICO: A Step-by-Step UK Guide
Discovering a personal data breach in your organisation is stressful, and the clock starts ticking the moment you become aware of it. Under the UK GDPR and the Data Protection Act 2018, most organisations have just 72 hours to notify the Information Commissioner's Office (ICO). This guide walks you through exactly how to report a data breach to the ICO, what information you'll need, and how to handle the aftermath in a way that protects both your customers and your business.
What Counts as a Personal Data Breach?
A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. In simpler terms: if personal information has been exposed, lost, or accessed by someone who shouldn't have seen it, you're likely dealing with a breach.
The ICO recognises three broad categories of personal data breach:
- Confidentiality breach — unauthorised or accidental disclosure of, or access to, personal data (e.g. an email sent to the wrong recipient).
- Integrity breach — unauthorised or accidental alteration of personal data (e.g. records tampered with by an attacker).
- Availability breach — accidental or unauthorised loss of access to, or destruction of, personal data (e.g. a ransomware attack, or a lost unencrypted laptop).
Common real-world examples include lost USB sticks, stolen laptops, phishing attacks that expose customer databases, misconfigured cloud storage, emails sent to the wrong distribution list, and ransomware incidents.
Do You Have to Report Every Breach?
No. You only need to notify the ICO if the breach is likely to result in a risk to the rights and freedoms of individuals. If the risk is unlikely — for example, if the affected data was strongly encrypted and the decryption key remains secure — you may not need to report it. However, you must still document every breach internally, whether reportable or not.
The 72-Hour Rule: Understanding the Deadline
Article 33 of the UK GDPR requires data controllers to notify the ICO of a reportable personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it. The 72 hours includes weekends and bank holidays.
"Becoming aware" doesn't mean the moment the breach happened — it means the moment you have a reasonable degree of certainty that a security incident has occurred and that it involves personal data. A short investigation period to confirm the facts is acceptable and expected.
If you miss the 72-hour deadline, you can still report, but you must provide reasons for the delay. Late reporting without justification is itself a compliance failure and can attract enforcement action.
Step-by-Step: How to Report a Data Breach to the ICO
Here is the process you should follow from the moment you suspect a breach until your report is submitted.
- Contain the breach. Take immediate action to stop the incident from getting worse — revoke compromised credentials, isolate affected systems, recover lost devices, or take a leaked page offline.
- Assess the risk. Determine what data is involved, how many people are affected, and the likely consequences for those individuals (identity theft, financial loss, distress, physical harm, discrimination).
- Decide if the breach is notifiable. If there is a risk to the rights and freedoms of individuals, you must notify the ICO. If the risk is high, you must also notify the affected individuals directly.
- Gather the required information. The ICO's report form asks specific questions, so collect the facts before you start (see the next section).
- Submit your report to the ICO. Use the ICO's online reporting service at ico.org.uk, or call the ICO helpline on 0303 123 1113 during office hours for urgent cases.
- Notify affected individuals if required. When the risk is high, tell affected people in clear, plain language, and explain what they can do to protect themselves.
- Document everything. Keep a written record of the facts, effects, and remedial action taken — even for breaches you didn't report.
How to Submit the Report
The ICO offers several routes for reporting, depending on the urgency and nature of the incident:
| Reporting Method | When to Use | Availability |
|---|---|---|
| Online self-report form (ico.org.uk) | Most standard breaches | 24/7 |
| ICO helpline (0303 123 1113) | Urgent breaches during office hours | Mon–Fri, 9am–5pm |
| Live chat via ico.org.uk | Quick queries and guidance | Office hours |
| Email or post | Follow-up documentation only | N/A for initial report |
The online form is the most efficient option and creates an automatic audit trail. You will receive a case reference number, which you should quote in all subsequent correspondence.
Information You Need to Include in the Report
Article 33(3) of the UK GDPR sets out the minimum information that must be included. Prepare the following before you open the form:
- Nature of the breach — what happened, when it happened, and when you became aware of it.
- Categories of data — types of personal data involved (names, contact details, financial data, health data, special category data, etc.).
- Categories and approximate number of individuals affected — customers, employees, patients, children, and so on.
- Categories and approximate number of records concerned.
- Likely consequences for the individuals affected.
- Measures taken or proposed to address the breach and mitigate its effects.
- Name and contact details of your Data Protection Officer (DPO) or another contact point.
If You Don't Have All the Information Yet
You don't need to have every detail nailed down before the 72-hour deadline. The ICO explicitly allows you to submit information in phases. Report what you know within 72 hours, flag that the investigation is ongoing, and provide updates as soon as new facts emerge.
When You Must Also Notify Affected Individuals
Under Article 34 of the UK GDPR, you must notify affected individuals directly if the breach is likely to result in a high risk to their rights and freedoms. Examples of high-risk breaches include:
- Leaks of financial details that could enable fraud.
- Exposure of passwords, especially where reuse is likely.
- Disclosure of health, sexuality, religion, or other special category data.
- Breaches involving children or vulnerable individuals.
- Breaches likely to cause significant emotional distress, reputational damage, or physical safety concerns.
Your notification to individuals should be in clear, plain English (no legalese), and must include the nature of the breach, contact details for your DPO, likely consequences, and the measures you've taken. Crucially, you should also give practical advice — for example, telling people to change reused passwords, watch for phishing attempts, or monitor their bank accounts.
What Happens After You Report
Once your report is submitted, the ICO will assess the information provided and may take one of several paths:
- No further action — for lower-severity incidents that have been handled appropriately.
- Request for more information — if the ICO needs to understand what happened in more depth.
- Investigation — for serious or systemic issues, the ICO may open a formal investigation.
- Enforcement action — in the most serious cases, this can include reprimands, enforcement notices, or monetary penalties of up to £17.5 million or 4% of global annual turnover.
Cooperating fully, being transparent, and demonstrating that you have learned from the incident all count strongly in your favour. The ICO's approach is generally to work with organisations that show good faith, not to punish honest mistakes.
How to Reduce the Chance of a Breach in the First Place
Prevention is far cheaper than remediation. A layered approach to data protection typically involves technical, organisational, and cultural safeguards:
- Encrypt everything at rest and in transit, especially laptops, USB drives, backups, and cloud storage.
- Enforce multi-factor authentication on all business accounts, particularly email and admin panels.
- Train staff regularly on phishing, social engineering, and safe handling of personal data.
- Restrict access to personal data on a need-to-know basis, and audit access logs.
- Patch and update operating systems, browsers, and third-party software promptly.
- Vet your suppliers. When you share personal data with third parties — including marketing tools and link-tracking services — make sure they take security and data minimisation seriously. Tools such as Lunyb, a privacy-focused URL shortener, can help you share and track links without exposing your customers' data to opaque tracking ecosystems.
- Have an incident response plan in place before you need it, including a documented breach reporting workflow.
If your business relies on shortened links for marketing, customer support, or internal communications, review the tools you use. Our 2026 URL shortener buyer's guide and honest review of Lunyb both explain what to look for from a data protection standpoint.
Common Mistakes to Avoid
Even well-meaning organisations trip up when handling a breach. Watch out for these pitfalls:
- Waiting until you know everything. The 72-hour clock does not pause while you investigate.
- Downplaying the incident in your report. The ICO can spot inconsistencies quickly, and understating a breach can be treated as a separate compliance failure.
- Forgetting to notify individuals. Reporting to the ICO does not remove your obligation to tell affected people when the risk is high.
- No internal record-keeping. You must document all breaches, including those you decided not to report.
- Blaming a supplier without checking your own controls. As the controller, you're accountable for the personal data even if the incident occurred at a processor.
Special Cases: Processors, Joint Controllers, and Small Organisations
If you are a data processor (for example, an IT provider handling customer data on behalf of a client), you do not report to the ICO yourself. Instead, you must notify the controller without undue delay so they can meet their own 72-hour obligation. Your contract should set out the exact process and timing.
For joint controllers, the arrangement between the parties should set out who takes the lead on breach reporting, though ultimately both remain accountable.
Small organisations and sole traders are subject to the same rules as larger businesses. There is no exemption based on size, though the ICO does take proportionality into account when assessing enforcement.
Frequently Asked Questions
Do I need to report a data breach to the ICO if no one has actually been harmed?
You need to assess the likelihood of risk, not wait for actual harm. If the breach is likely to result in a risk to individuals' rights and freedoms, it must be reported to the ICO within 72 hours, even if no one has yet complained or suffered a loss.
What is the penalty for failing to report a breach on time?
Failure to notify the ICO can result in an administrative fine of up to £8.7 million or 2% of global annual turnover, whichever is higher. In practice, the ICO usually reserves the largest fines for serious, systemic, or dishonest failures. Transparent, cooperative reporting typically results in lighter outcomes.
Can I report a breach anonymously to the ICO?
No. A data controller cannot report anonymously because the ICO needs to know who is accountable. However, if you are an employee or a member of the public who wants to raise a concern about how an organisation has handled personal data, you can contact the ICO's helpline and, in some cases, request confidentiality.
What if the breach happened at a third-party supplier?
You remain responsible as the data controller. Your processor must inform you of any breach without undue delay, and the 72-hour clock for reporting to the ICO starts when you become aware. Make sure your processor contracts include clear breach notification obligations and timelines.
How long should I keep records of data breaches?
The UK GDPR does not set a specific retention period, but records should be kept long enough to demonstrate compliance and allow the ICO to verify your handling of incidents. Most organisations retain breach records for a minimum of three to six years, aligned with their broader accountability documentation.
Final Thoughts
Reporting a data breach to the ICO within 72 hours can feel daunting, but the process is designed to be workable — even for small organisations. The keys are speed, honesty, thorough documentation, and a genuine commitment to putting things right for the people whose data has been affected. Build a simple, rehearsed incident response plan now, before you need it, and the next breach — should it ever come — will be a manageable incident rather than a full-blown crisis.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Erase Your Browsing History Completely: The 2026 Guide
Clearing your browser history only removes the surface layer. This complete 2026 guide shows you how to erase browsing history from browsers, cloud sync, DNS caches, and network logs — and how to prevent it from being recorded in the first place.
How to Use UTM Parameters with Short Links: A Complete Guide
UTM parameters turn any link into a trackable data source, and short links make those tags compact and shareable. This guide covers UTM structure, naming conventions, real-world examples, and advanced tactics for measuring campaign performance across every channel.
How to Do a Reverse Image Search to Find Your Photos Online
Learn how to do a reverse image search to find your photos online using Google Lens, Yandex, TinEye, and more. Discover where your images are being used, protect your identity from catfishing, and take action against unauthorized use with this complete 2026 guide.
What Is a URL Shortener and Why Use One in 2026
A URL shortener turns long, messy web addresses into clean, trackable links. Discover how they work, why marketers rely on them, and how to choose the right one for your needs in 2026.