October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Reporting a Personal Data Breach Under UK GDPR: A Guide for UK Businesses

Learn what UK businesses should do after discovering a personal data breach, when to notify the ICO and affected people, and what to record.
From TheFinanceBase Team5 min to read

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If your business discovers a personal data breach, contain it, start a record and assess the risk to people straight away. A controller must notify the Information Commissioner’s Office (ICO) without undue delay and, where feasible, within 72 hours of becoming aware if the breach is likely to pose a risk to people’s rights and freedoms. Tell affected people separately if a high risk is likely. The ICO’s guidance says it is under review following the Data (Use and Access) Act 2025, so check the current official guidance and legislation when acting.

What counts as a personal data breach?

A security incident is not automatically a reportable personal data breach. The relevant question is whether personal data has been lost, destroyed, altered, disclosed, or accessed without authorisation. A misdirected email, a stolen laptop or files lost in a flood can all involve a breach; a cyberattack is not required. The ICO’s personal data breach guide explains the reporting and record-keeping duties.

First establish what happened and whether personal data was affected. Take reasonable steps to stop ongoing exposure, recover data where possible, preserve relevant evidence and limit further harm. Do not delay containment while waiting for a complete investigation.

What should a business do first?

  1. Contain the incident. Restrict unauthorised access, stop further disclosure where possible, and protect affected systems and people.
  2. Open an incident record. Note when the breach was discovered, the timeline, data involved, people and records affected if known, who received or accessed the data, containment steps, possible consequences, and decisions made. Separate confirmed facts from assumptions and identify unanswered questions.
  3. Assess the risk to people. Consider the nature of the data, who could access it, whether it was recovered or made unintelligible, who is affected, and how effective the mitigation is. Document the reasoning; the decision depends on the circumstances.
  4. Make two distinct notification decisions. Decide whether the ICO must be notified and, separately, whether affected people must be told.
  5. Follow up. Record further information and actions, review whether detection and escalation worked, and capture lessons for improving controls and response procedures.

The ICO’s guide to personal data breaches says organisations must document all breaches and decisions, including cases where no external notification is made.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When must a business report a breach to the ICO?

A controller must notify the ICO if a personal data breach is likely to result in a risk to people’s rights and freedoms. The duty is to report without undue delay and, where feasible, within 72 hours after becoming aware. If the breach is unlikely to result in such a risk, Article 33 notification is not required, but the business must still document the breach and its decision.

Risk is contextual, not determined by a single checklist item. For example, an accidental disclosure with little potential impact may not require notification, while sensitive records exposed to others may create substantial risk. These are illustrations, not automatic outcomes. The ICO’s reporting guidance sets out the threshold and process.

How is the 72-hour deadline calculated?

The clock starts when the organisation becomes aware of the breach, not when the breach happened. The ICO’s small-organisation guide states: “The clock starts from when you discovered the breach, not when it actually happened.” Investigate promptly, but do not treat incomplete fact-finding as permission to wait.

The deadline is 72 hours, not three business days. If it is not feasible to notify within that period, notify without undue delay and explain why the report is late. If information is incomplete, submit what is available and provide the remaining details in phases without undue further delay. The ICO encourages early reporting followed by updates, particularly for complex or ongoing incidents.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Rapidesign Office Planner Template, 1/8 Inch Scale, 1 Each (R706)
  • Contains desks, credenzas, files, bookcases, tables, chairs, sofas, door swings, etc.
  • Great for office furniture, planning and arrangement
  • Includes 1/4" and 1/8" scale on top edges
  • 1/8" = 1' Scale
  • Made in USA

Should affected people be told?

This is a separate decision from notifying the ICO. A controller must communicate a breach to affected people without undue delay if it is likely to result in a high risk to their rights and freedoms. The ICO notification threshold is risk; the individual-notification threshold is high risk.

Use clear, plain language. Explain what happened, how people can contact the organisation, the likely consequences, and the steps taken or proposed to address the breach and reduce harm. Article 34 includes exceptions—for example, where appropriate technical and organisational measures made the data unintelligible to unauthorised people. Encryption alone should not be treated as an automatic exemption; whether an exception applies depends on the circumstances. The official text of UK GDPR Article 34 sets out the conditions.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What information should an ICO notification contain?

Under Article 33, provide the following information where possible:

  • A description of the breach, including the categories and approximate number of affected people and personal data records.
  • The data protection officer’s name and contact details, or another contact point.
  • The likely consequences of the breach.
  • The measures taken or proposed to address it, including steps to mitigate possible adverse effects.

If not all details are available at once, supply them in phases without undue further delay. The official text of UK GDPR Article 33 sets out these requirements. The ICO says that early, open contact helps it deal with a breach efficiently and protect personal information.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What if the business is a processor?

A processor must tell its controller about a personal data breach without undue delay after becoming aware of it. The controller is responsible for assessing the risk and deciding whether to notify the ICO or affected people. Contracts and incident procedures should enable the processor to escalate quickly enough for the controller to meet its duties; a processor should not wait for its own investigation to be complete before alerting the controller.

How does the Data (Use and Access) Act 2025 affect breach reporting?

The ICO says its UK GDPR breach-reporting guidance is under review following the Data (Use and Access) Act 2025, which received Royal Assent on 19 June 2025. The ICO’s reporting page was last updated on 28 May 2025 and notes the review.

Do not confuse the PECR reporting-period change with the UK GDPR Article 33 deadline. The ICO says the PECR period changed from 24 to 72 hours after awareness, with the change recorded on 20 August 2025. The official UK GDPR text itself states the Article 33 72-hour rule. Check the current legislation and ICO guidance for any later amendments before relying on a legal requirement.

How should a business review its response?

After the immediate response, record follow-up actions and lessons learned. Review whether staff recognised the incident, internal escalation was fast enough, processor arrangements worked, decisions were documented, and controls reduced the chance or impact of recurrence. The ICO’s data protection audit framework calls for a reporting process, a communications process and a lessons-learned debrief.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.