How to Report a Data Breach to the ICO: A UK Step-by-Step Guide
If your organisation has suffered a personal data breach, the clock starts ticking the moment you become aware of it. Under the UK GDPR and the Data Protection Act 2018, you may have as little as 72 hours to notify the Information Commissioner's Office (ICO). Getting this right protects both the individuals affected and your organisation from significant regulatory penalties.
This guide walks you through exactly how to report a data breach to the ICO, what information you'll need, when notification is (and isn't) required, and how to build the internal processes that make the 72-hour deadline achievable.
What Counts as a Personal Data Breach Under UK GDPR?
A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. It is not limited to hackers stealing databases — the definition is much broader.
Examples of reportable breaches include:
- Emails sent to the wrong recipient containing personal data
- Lost or stolen laptops, USB sticks or paper files
- Ransomware attacks that encrypt personal data
- Unauthorised access to systems by employees or third parties
- Misconfigured cloud storage exposing customer records
- Phishing attacks that compromise account credentials
The ICO categorises breaches into three types: confidentiality breaches (unauthorised disclosure), integrity breaches (unauthorised alteration), and availability breaches (accidental or unlawful loss of access or destruction).
When Must You Report a Data Breach to the ICO?
You must notify the ICO within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. "Becoming aware" means having a reasonable degree of certainty that a security incident has occurred that led to personal data being compromised — not merely suspecting one.
Breaches That Do Not Require ICO Notification
Not every incident needs to be reported. If the breach is unlikely to result in a risk to individuals, you do not need to notify the ICO — but you must still document it internally. Examples might include:
- An encrypted device is lost, but the encryption is strong and keys are secure
- An email is sent to the wrong internal colleague who is bound by confidentiality and deletes it immediately
- Data that was already publicly available is inadvertently disclosed again
When You Also Need to Notify Individuals
If the breach is likely to result in a high risk to the rights and freedoms of individuals, you must also notify the affected data subjects "without undue delay." High-risk indicators include exposure of financial information, health data, login credentials, or data that could lead to identity theft or discrimination.
Step-by-Step: How to Report a Data Breach to the ICO
Here is the practical process to follow once you become aware of a breach.
Step 1: Contain and Assess the Breach
- Stop the breach from continuing (isolate systems, recall emails, revoke access).
- Identify what personal data was involved and how many people are affected.
- Determine the likely consequences for individuals.
- Record the time you became aware — this starts your 72-hour clock.
Step 2: Decide Whether Notification Is Required
Conduct a formal risk assessment. Document your reasoning either way. If you decide notification is not required, keep detailed records — the ICO can request this documentation during audits or complaints.
Step 3: Gather the Required Information
Before you begin the notification, collect:
- A description of the nature of the breach
- Categories and approximate number of data subjects affected
- Categories and approximate number of personal data records affected
- Name and contact details of your Data Protection Officer (DPO) or another contact point
- Likely consequences of the breach
- Measures taken or proposed to address the breach and mitigate harm
Step 4: Submit the Report to the ICO
There are three ways to report a personal data breach to the ICO:
- Online reporting tool — available on the ICO website (ico.org.uk) and the preferred method for most organisations.
- Telephone — call the ICO's dedicated breach helpline on 0303 123 1113 (option 3), open Monday to Friday, 9am to 5pm. Use this route for urgent or complex cases outside office hours where you can leave details.
- Communications provider breaches — if you are a telecoms or ISP provider, use the dedicated PECR breach form, which has different requirements under the Privacy and Electronic Communications Regulations.
Step 5: Follow Up With Additional Information
If you don't have all the details within 72 hours, you can still submit an initial notification and provide the remaining information "in phases" without undue further delay. State clearly in your submission what is still under investigation.
Step 6: Notify Affected Individuals if Required
If the breach is high-risk, contact affected individuals in clear, plain language. Include:
- The nature of the breach
- Contact details for further information
- Likely consequences
- Measures taken to address it
- Recommendations for what individuals can do to protect themselves
What Information Does the ICO Ask For?
The ICO's online form is structured and asks specific questions. Below is a summary of the key sections.
| Section | What You'll Need to Provide |
|---|---|
| Your organisation | Name, address, sector, ICO registration number, DPO contact details |
| Breach details | Date and time of breach, when you became aware, how it was discovered |
| Nature of breach | Confidentiality, integrity or availability — and the cause (cyber attack, human error, etc.) |
| Data involved | Categories of data (names, addresses, financial, special category, etc.) and number of records |
| Data subjects | Number and categories affected (customers, employees, children, vulnerable individuals) |
| Consequences | Likely impact on individuals and your risk assessment |
| Remedial actions | What you have done, are doing, and plan to do to contain and mitigate the breach |
| Communication | Whether and how you have or will notify affected individuals |
Penalties for Failing to Report a Breach
Failure to notify the ICO when required is itself a breach of the UK GDPR. The maximum administrative fine is £8.7 million or 2% of global annual turnover, whichever is higher. In severe cases involving underlying failings, fines can reach £17.5 million or 4% of turnover.
However, the ICO has stated repeatedly that it prefers a collaborative, proportionate approach. Organisations that report promptly, cooperate transparently and demonstrate genuine remediation typically receive far more lenient outcomes than those that delay or attempt to conceal breaches.
Recent Enforcement Examples
Recent ICO enforcement actions have consistently emphasised three aggravating factors: late notification, inadequate technical measures (particularly around encryption and access controls), and poor communication with affected individuals. Organisations that ticked all three boxes have faced the largest penalties.
Building an Internal Breach Response Plan
Meeting the 72-hour deadline is nearly impossible without a documented, rehearsed plan. Every organisation processing personal data should have one.
Essential Elements of a Breach Response Plan
- Clear reporting channels — every employee should know who to contact when they spot a potential breach.
- Named responders — a DPO or designated lead, plus deputies for cover.
- Assessment criteria — a decision tree for evaluating risk to rights and freedoms.
- Notification templates — pre-drafted communications for the ICO and data subjects.
- Third-party contacts — legal, forensic, PR and cyber insurance providers on standby.
- Rehearsal schedule — tabletop exercises at least annually.
Reducing Breach Risk in the First Place
Prevention is always cheaper than remediation. Baseline controls should include multi-factor authentication, endpoint encryption, staff phishing training, least-privilege access, encrypted DNS resolution, regular patching and secure backups. Marketing and communications teams should also audit the tools they use to share links and campaigns externally — secure link management platforms such as Lunyb allow you to control, revoke and monitor shortened URLs so a leaked or misdirected link doesn't turn into a wider data exposure incident. For a broader review of link tools and their security features, see our 2026 URL shortener buyer's guide.
Common Mistakes When Reporting to the ICO
Even well-meaning organisations trip up on the same issues. Watch for these:
- Starting the clock too late — the 72 hours runs from awareness, not from completing your investigation.
- Under-reporting scope — initial estimates of affected individuals often grow; be conservative and update the ICO as you learn more.
- Poor documentation — even non-reportable breaches must be logged internally.
- Notifying individuals without a plan — ensure your customer service and complaints team is briefed before individuals receive letters.
- Ignoring processor breaches — if a supplier suffers a breach affecting your data, you remain the controller and are responsible for notification.
- Assuming encryption removes the obligation — encryption reduces risk but does not automatically exempt you from reporting.
What Happens After You Report?
Once you submit, the ICO will acknowledge receipt and assign a case reference. Depending on the severity, they may:
- Take no further action beyond logging the breach
- Request additional information
- Provide advice and guidance
- Open a formal investigation
- Issue an enforcement notice or fine in serious cases
Most reported breaches result in no formal action. The ICO's own statistics consistently show that only a small percentage of notifications lead to investigations, and an even smaller fraction result in monetary penalties. Cooperation and transparency dramatically improve outcomes.
Special Cases: Processors, Joint Controllers and PECR
If You Are a Data Processor
Processors do not report directly to the ICO. Instead, you must notify your controller "without undue delay" after becoming aware of a breach. Your contract should specify timelines — typically 24 to 48 hours — to give the controller time to meet their own 72-hour obligation.
Joint Controllers
Where two or more organisations are joint controllers, your arrangement should clearly designate which party leads on ICO notification. Both remain legally responsible, so ensure the agreement is documented.
PECR Breaches (Communications Providers)
If you provide a public electronic communications service, you must notify the ICO of any personal data breach — there is no risk threshold. Notification must be within 24 hours where feasible.
FAQ
How long do I have to report a data breach to the ICO?
You have 72 hours from the moment you become aware of the breach. If you cannot provide all details in that window, submit an initial notification and follow up in phases. Late reports must be accompanied by reasons for the delay.
Do I need to report every data breach to the ICO?
No. Only breaches likely to result in a risk to the rights and freedoms of individuals require notification. However, you must document all breaches internally, including those you decide not to report, along with your risk assessment reasoning.
Can I report a data breach to the ICO by phone?
Yes. The ICO's personal data breach helpline is 0303 123 1113 (select option 3), open Monday to Friday 9am to 5pm. The online form is generally faster and provides a structured record, but the phone line is useful for urgent or complex situations.
What is the maximum fine for failing to report a breach?
Failure to notify when required can attract fines of up to £8.7 million or 2% of global annual turnover, whichever is higher. Related failings in security or governance can push penalties higher still. In practice, organisations that report promptly and cooperate are treated far more leniently.
Do I have to tell my customers about the breach?
Only if the breach is likely to result in a high risk to their rights and freedoms — for example, exposure of financial data, passwords, health information or identity documents. When required, notification must be in plain language and "without undue delay," with practical guidance on protective steps.
What if the breach happened at one of my suppliers?
If you are the controller, you remain responsible for reporting to the ICO even when the breach occurs at a processor. Your supplier should notify you promptly under the terms of your data processing agreement, and the 72-hour clock begins when you (the controller) become aware.
Final Thoughts
Reporting a data breach to the ICO is stressful, but the process itself is well-defined and manageable if you prepare in advance. The organisations that come through breaches with reputation and finances intact are those that respond quickly, communicate honestly, and demonstrate that they had reasonable safeguards in place beforehand.
Treat the 72-hour deadline as a forcing function for better security hygiene across your business. Document your processes, train your staff, audit your suppliers, and make sure every tool you rely on — from email systems to link-sharing platforms — supports rather than undermines your compliance posture.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
How to Remove Your Personal Information from Data Brokers: Complete 2026 Guide
Data brokers sell your personal information to anyone willing to pay, exposing you to identity theft, stalking, and scams. This comprehensive guide shows you exactly how to remove your data from the top brokers, protect your privacy long-term, and leverage your legal rights.
How to Protect Your Privacy Online in 2026: The Complete Guide
Online privacy in 2026 requires more than a strong password. This complete guide walks you through the tools, habits, and settings that keep your data, identity, and browsing activity truly private.
Who Called Me? How to Identify an Unknown Number in 2026
Missed a call from a number you don't recognize? This complete 2026 guide covers 8 proven methods to identify unknown callers, from reverse phone lookups and Google searches to messaging apps and carrier spam filters. Learn how to spot scams and block unwanted callers for good.
How to Shorten a URL: Complete Guide for 2026
Learn how to shorten a URL step by step in 2026. This complete guide covers the best tools, custom aliases, branded domains, analytics, security tips, and common mistakes to avoid when creating short links.