Skip to content
UK GDPR

Data Breach Reporting to the ICO: Step-by-Step

4 min readUpdated 2 September 2026

Reporting a personal data breach to the ICO is a mandatory requirement under UK GDPR when a breach is likely to result in risk to individuals' rights and freedoms. The deadline is 72 hours from becoming aware. Missing this deadline, or reporting with inadequate information, can turn a manageable incident into an aggravated enforcement matter.


When You Must Report to the ICO

UK GDPR Article 33 requires notification to the ICO when a breach "is likely to result in risk to the rights and freedoms of natural persons."

Assess risk using these factors:

  • Type of data (health, financial, special category = high risk; basic contact data = lower risk)
  • Number of individuals affected
  • Sensitivity of the context (e.g., medical records vs general marketing data)
  • Likelihood and severity of consequences for individuals
  • Any mitigating factors (encryption that renders data unusable, rapid containment)

You do not need to notify if: The breach is unlikely to result in any risk to individuals. Example: a single employee email address accidentally sent to the wrong internal colleague, immediately recalled, no sensitive information. Document this assessment.

You must notify if: The data could enable harm — identity theft, financial fraud, discrimination, reputational damage, physical harm, emotional distress.


The 72-Hour Deadline

The clock starts when you become "aware" of the breach. This means the point at which there is reasonable certainty that a security incident has occurred which has led to personal data being compromised — not when you have completed your investigation.

Partial notification is acceptable. If you cannot provide all required information within 72 hours, notify with what you know and provide the rest as soon as possible. The ICO explicitly supports this — late submission with complete information is worse than timely submission with an interim update.


Step-by-Step Breach Reporting to the ICO

Step 1: Contain the Breach

Before reporting, take immediate steps to limit ongoing damage:

  • Revoke compromised credentials
  • Disable affected systems if necessary
  • Recover exposed data if possible
  • Document what you have done

Step 2: Assess the Breach

Determine:

  • What happened (how was the breach caused?)
  • What data was involved (categories and volume)
  • How many individuals are affected (estimate if exact number not known)
  • What are the likely consequences for those individuals?
  • What is the risk level — low, medium, high?

Document this assessment. It forms the basis of the ICO notification.

Step 3: Make the Notification Decision

Based on the risk assessment:

  • Low risk: Document internally, no ICO notification required
  • Medium/high risk: Notify ICO within 72 hours

Step 4: Submit to the ICO

Report online at ico.org.uk/make-a-complaint/data-security-incident-reports/

The ICO's self-reporting tool guides you through the required fields:

Section 1 — About the organisation:

  • Organisation name and type
  • Your contact details
  • Whether you are a controller or processor
  • Whether you have a DPO (and their details if so)

Section 2 — About the breach:

  • Date you became aware of the breach
  • Nature of the breach (confidentiality, integrity, availability, or combination)
  • Cause of the breach (accident, malicious attack, system failure, human error)
  • How the breach occurred

Section 3 — Personal data involved:

  • Categories of personal data (contact details, financial, health, etc.)
  • Approximate number of individuals affected
  • Approximate number of records
  • Whether special category data is involved

Section 4 — Consequences:

  • Likely consequences for affected individuals
  • Risk assessment (low, medium, high)

Section 5 — Measures taken:

  • Actions already taken to address the breach
  • Actions planned to prevent recurrence

Step 5: Individual Notification

Where the breach "is likely to result in high risk" to individuals, notify affected individuals under UK GDPR Article 34:

  • Without undue delay
  • In clear and plain language
  • Describing the breach, likely consequences, and what you are doing
  • Providing a contact point

What Happens After You Report

Most reports: The ICO logs the notification. You receive a reference number. No further action is taken if the risk was assessed correctly and appropriate measures were taken.

Follow-up enquiries: For more significant breaches, an ICO caseworker may contact you for additional information. Respond fully and promptly.

Investigation: For serious breaches (large scale, sensitive data, systemic failures), the ICO may open a formal investigation. Cooperation is expected.

Enforcement action: For breaches where inadequate security was the cause, or where the breach was not reported on time, enforcement action including fines may follow.


Documenting Non-Reported Breaches

UK GDPR requires you to maintain a record of all breaches, including those that do not require notification. For each non-reported breach:

  • Record the facts of the breach
  • Record your risk assessment and why you determined notification was not required
  • Keep this record for at least 3–5 years

If the ICO later reviews your breach handling, this documentation demonstrates a structured assessment process rather than arbitrary decisions.

ComplyOne covers UK GDPR and EU GDPR in one platform — identifying the specific gaps between the two frameworks.

Check your UK GDPR compliance →