facebook-pixel

How to Report a Data Breach to the ICO: A Complete UK Guide

L
Lunyb Security Team
··11 min read

If your organisation has suffered a personal data breach, the clock is ticking. Under the UK GDPR and the Data Protection Act 2018, you may be legally required to report the incident to the Information Commissioner's Office (ICO) within 72 hours of becoming aware of it. Failing to do so can result in significant fines, reputational damage and enforcement action.

This guide explains exactly how to report a data breach to the ICO, when reporting is mandatory, what information you need to provide, and what happens after you submit your notification. Whether you're a data protection officer, IT manager, or small business owner, this walkthrough will help you meet your legal obligations with confidence.

What Is a Personal Data Breach Under UK GDPR?

A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. It is not limited to cyberattacks — human error, lost devices, misdirected emails and even verbal disclosures can qualify.

The ICO recognises three main categories of data breach:

  • Confidentiality breach: Unauthorised or accidental disclosure of, or access to, personal data (e.g. a hacker steals a customer database).
  • Integrity breach: Unauthorised or accidental alteration of personal data (e.g. records changed by a malicious insider).
  • Availability breach: Accidental or unauthorised loss of access to, or destruction of, personal data (e.g. ransomware encrypts your files, or a server is destroyed without backups).

Common Examples of Reportable Breaches

  • An email containing personal data sent to the wrong recipient
  • Loss or theft of an unencrypted laptop, USB stick or paper file
  • Successful phishing attack that compromises staff credentials
  • Ransomware infection affecting systems holding personal data
  • Misconfigured cloud storage exposing customer records publicly
  • A rogue employee downloading or leaking personal data

When Must You Report a Data Breach to the ICO?

You must report a notifiable breach to the ICO within 72 hours of becoming aware of it. The clock starts as soon as you have a reasonable degree of certainty that a security incident has occurred that led to personal data being compromised — not when the incident itself happened.

However, not every breach needs to be reported. You only need to notify the ICO when the breach is likely to result in a risk to the rights and freedoms of individuals. If it's unlikely to pose a risk, you don't need to report — but you must still document it internally.

How to Assess the Risk

When deciding whether a breach is reportable, consider:

  1. Type of breach — Was data lost, disclosed or altered?
  2. Nature and volume of data — Special category data (health, ethnicity, biometrics) carries much higher risk.
  3. Ease of identification — Can affected individuals be identified from the compromised data?
  4. Severity of consequences — Could it lead to identity theft, financial loss, discrimination or psychological harm?
  5. Number of affected individuals — Larger scale generally means higher risk.
  6. Vulnerability of individuals — Are children or vulnerable adults involved?

What About Notifying Individuals?

If the breach is likely to result in a high risk to individuals, you must also inform the affected data subjects without undue delay. This threshold is higher than the reporting threshold to the ICO, so some breaches will be reportable to the ICO but not require notification of individuals.

Step-by-Step: How to Report a Data Breach to the ICO

The ICO offers several reporting channels depending on the type of breach and your organisation. Here is the standard process for reporting a personal data breach under the UK GDPR.

Step 1: Contain and Assess the Breach

Before notification, take immediate action to stop the breach spreading. Isolate affected systems, revoke compromised credentials, recall misdirected emails, and preserve evidence for later investigation. Convene your incident response team and begin documenting every action taken.

Step 2: Gather the Required Information

The ICO's breach report form asks for specific details. Before you start, prepare the following:

  • Your organisation's name and ICO registration number
  • Contact details of your Data Protection Officer or main contact
  • Date and time the breach occurred (or approximate)
  • Date and time you became aware of the breach
  • Description of the incident and how it happened
  • Categories and approximate number of individuals affected
  • Categories and approximate number of records affected
  • Likely consequences for affected individuals
  • Measures already taken or proposed to mitigate the breach
  • Whether you have informed affected individuals

Step 3: Use the ICO's Online Reporting Tool

The primary way to report is via the ICO's Personal Data Breach Report Form, available at ico.org.uk. Navigate to "Make a report" and select "Report a breach". You'll be guided through a self-assessment tool that helps determine whether the incident is reportable.

For urgent breaches, you can also call the ICO's helpline on 0303 123 1113 (Monday to Friday, 9am–5pm). Telephone reporting is recommended for very serious or complex incidents.

Step 4: Submit a Phased Report if Necessary

If you don't have all the information within 72 hours, you can still submit an initial notification and provide additional details in phases. Explain the reasons for the delay and give a realistic timeline for follow-up information. The ICO expects transparency, not perfection.

Step 5: Notify Affected Individuals (if High Risk)

If the breach poses a high risk to individuals, contact them directly in clear, plain language. Tell them what happened, what data was involved, the likely consequences, what you're doing about it, and how they can protect themselves (e.g. changing passwords, monitoring accounts).

Step 6: Document Everything Internally

Even for breaches you don't report, UK GDPR requires you to maintain an internal record. Your log should include the facts, effects and remedial actions taken. The ICO can request to see this documentation during audits or investigations.

ICO Breach Reporting: Key Deadlines and Consequences

Understanding the deadlines and potential consequences helps prioritise your incident response.

RequirementDeadlineConsequence of Non-Compliance
Report notifiable breach to ICOWithin 72 hours of awarenessFines up to £8.7 million or 2% of global turnover
Notify affected individuals (high risk)Without undue delayEnforcement notices, fines, reputational damage
Maintain internal breach logOngoingRegulatory scrutiny during audits
Provide follow-up informationAs soon as availableLoss of credibility with ICO
Cooperate with ICO investigationThroughout processHigher penalties for obstruction

Maximum Fines Under UK GDPR

The higher tier of fines under UK GDPR can reach £17.5 million or 4% of annual global turnover, whichever is greater. Fines for failing to report a breach fall under the lower tier — up to £8.7 million or 2% of global turnover — but repeated or aggravated failures can escalate.

Common Mistakes to Avoid When Reporting

Even well-prepared organisations make errors during the stress of a data breach. Here are the most frequent pitfalls to avoid.

  • Waiting too long to start the clock: The 72-hour period begins when you become aware, not when you complete your investigation.
  • Under-reporting details: Vague or incomplete reports frustrate the ICO and often trigger follow-up requests.
  • Assuming encryption means no report needed: Strong encryption may lower the risk, but you still need to assess and document your decision.
  • Skipping individual notifications: If risk to individuals is high, telling only the ICO is not enough.
  • Poor documentation: Failing to maintain a breach log is itself a compliance breach.
  • Blaming the processor: Controllers remain responsible even if a third-party processor caused the breach.

Preventing Data Breaches: Practical Steps

The best breach response is prevention. Reducing your attack surface and tightening operational controls significantly lowers the risk of a reportable incident.

Technical Controls

  • Encrypt data at rest and in transit
  • Enforce multi-factor authentication on all business accounts
  • Keep operating systems and software fully patched
  • Use endpoint protection with behavioural detection
  • Segment networks to limit lateral movement
  • Deploy encrypted DNS resolvers and secure browsers
  • Perform regular, tested backups stored offline

Organisational Controls

  • Deliver annual data protection training to all staff
  • Run phishing simulation exercises
  • Maintain a written incident response plan with defined roles
  • Perform Data Protection Impact Assessments (DPIAs) for high-risk processing
  • Vet suppliers and include data protection clauses in contracts
  • Conduct regular internal audits and tabletop exercises

Link Security and External Sharing

Many breaches stem from mishandled links — misdirected file-sharing URLs, expired credentials, or malicious short links used in phishing. When sharing externally, use trusted, transparent link management tools with expiry controls, click analytics and password protection. Services like Lunyb offer secure short links that can help track and control access to sensitive resources without exposing raw URLs. For a broader comparison of options, see our 2026 buyer's guide.

What Happens After You Report?

Once you submit your report, the ICO will acknowledge receipt and may follow up with additional questions. Their response depends on the severity of the breach.

  1. Low-severity breaches: The ICO may simply log the report and take no further action.
  2. Moderate breaches: You may be asked to provide additional information, evidence of remedial actions, or a formal statement.
  3. Serious breaches: The ICO may open a formal investigation, request interviews, issue information notices, or ultimately levy a monetary penalty.

Throughout this process, cooperation, transparency and demonstrable improvements to your controls will weigh heavily in your favour. The ICO's approach is generally proportionate — organisations that self-report promptly and take breaches seriously are treated more favourably than those that appear evasive.

Special Cases: Processors, Cross-Border Breaches and Sectors

If You Are a Data Processor

Processors do not report directly to the ICO. Instead, you must notify the controller "without undue delay" after becoming aware of a breach. The controller is then responsible for the 72-hour ICO notification. Your contract should specify timeframes and information requirements.

Cross-Border Breaches

If your organisation processes data across multiple jurisdictions, you may also need to notify supervisory authorities in the EU under the EU GDPR. Post-Brexit, the ICO is no longer the lead authority for EU-wide breaches, so identify your "main establishment" and lead supervisory authority in advance.

Sector-Specific Reporting

Some sectors have additional obligations. Telecoms and internet service providers must report under the Privacy and Electronic Communications Regulations (PECR) within 24 hours. Financial services firms may need to notify the FCA. Health organisations may have NHS-specific reporting duties. Always check sector-specific rules alongside UK GDPR.

Frequently Asked Questions

What is the 72-hour rule for reporting a data breach?

The UK GDPR requires organisations to notify the ICO of a personal data breach within 72 hours of becoming aware of it, where the breach is likely to result in a risk to the rights and freedoms of individuals. The clock starts when you have reasonable certainty a breach has occurred, not when the incident began.

Do I need to report every data breach to the ICO?

No. You only need to report breaches that are likely to result in a risk to individuals' rights and freedoms. Minor incidents with negligible impact — such as an internal email sent to the wrong colleague and immediately deleted — usually don't need reporting, but you must still document them internally.

What happens if I miss the 72-hour deadline?

Late reporting is still better than no reporting. Submit the report as soon as possible and explain the reasons for the delay. The ICO may take the lateness into account when deciding on enforcement action, but transparency and cooperation generally lead to better outcomes than concealment.

Can I be fined for reporting a breach?

Reporting itself does not trigger a fine. Fines are imposed for underlying compliance failures such as inadequate security measures, failure to have a lawful basis for processing, or failing to report when required. Self-reporting is a mitigating factor and demonstrates good faith.

How do I report a breach if my organisation is small or has no DPO?

You don't need a designated Data Protection Officer to report a breach. Any responsible person — typically the business owner, IT lead or compliance manager — can complete the ICO's online form or call the helpline on 0303 123 1113. The reporting process is designed to be accessible to organisations of all sizes.

Final Thoughts

Reporting a data breach to the ICO can feel daunting, especially under the pressure of a live incident. But the process is well-defined, and the ICO is generally supportive of organisations that act in good faith. Preparation is everything: have a written incident response plan, know who is responsible for reporting, keep contact details up to date, and rehearse your response before you need it.

By understanding your obligations, acting quickly, and being transparent with both the ICO and affected individuals, you not only meet the letter of the law — you also demonstrate the accountability that sits at the heart of the UK's data protection regime.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles