Last updated: 30 September 2026
Quick answer: ICO data breach reporting is required when a personal data breach is likely to result in a risk to people’s rights and freedoms. You must report to the ICO without undue delay and, where feasible, within 72 hours of becoming aware. You can report in phases, must tell individuals if the risk is high, and must log every breach.
For a data protection officer, the first hours after a breach are the most pressured of the job. You need to establish the facts, judge the risk, decide whether the ICO must be told and coordinate with IT, legal and communications, all while the 72-hour clock runs.
This guide explains when ICO data breach reporting is required under the UK GDPR, what the report must contain, how the ICO’s online process works, which other UK regimes may apply, and how to structure the first 72 hours. One naming note: on 30 September 2026 the ICO becomes the Information Commission, which keeps the same regulatory functions, including receiving breach reports. We use “ICO” throughout because that is the name most teams still search for.
When is ICO data breach reporting required?
You must notify the ICO when a personal data breach is likely to result in a risk to individuals’ rights and freedoms. If a risk is unlikely, you do not have to report, but you must still document the breach and your reasoning.
The ICO’s guide to personal data breaches defines a breach as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. That covers far more than cyber attacks: an email sent to the wrong recipient, a lost laptop or a ransomware attack that makes data unavailable can all qualify.
Risk depends on the likely consequences for people, such as financial loss, identity fraud, discrimination, reputational damage or distress. The type and sensitivity of the data, the number of people affected and whether the data was encrypted all feed into the assessment.
In practice: use a consistent risk scoring method for every incident, so your decision to report or not report is defensible and comparable over time.
When does the 72-hour clock start?
The clock starts when you become aware of the breach, meaning you have a reasonable degree of certainty that a security incident has led to personal data being compromised. It does not start when the incident began, and it does not wait until your investigation is complete.
The ICO encourages organisations to “report early, update later”. The ICO’s breach reporting page confirms you should report as soon as possible and, where feasible, within 72 hours, and that you can provide information in phases if the full picture is not yet clear. If you report after 72 hours, you must explain the delay.
Common mistake: waiting for forensic results before reporting. An initial report with what you know, followed by updates, is better than a complete but late one.
What must an ICO breach report include?
Article 33(3) of the UK GDPR sets out the minimum content. Your report should describe:
- The nature of the breach, including where possible the categories and approximate number of individuals and records concerned.
- The name and contact details of your DPO or other contact point.
- The likely consequences of the breach.
- The measures taken, or proposed, to deal with the breach and to mitigate possible adverse effects.
The ICO’s online form also asks what happened, when and how you found out, who is affected, what you have done and who else you have told. The ICO notes that the form takes around 30 minutes and cannot be saved and resumed, so gather the facts before you start.
How do you report a breach to the ICO?
You report through the ICO’s online personal data breach form. Before that, the ICO’s self-assessment tool can help you decide whether a report is needed.
- Contain the breach. Stop the loss, recover data where possible and preserve evidence.
- Assess the risk. Use a consistent method covering data types, volume, sensitivity and likely harm.
- Decide. Record whether the breach is reportable to the ICO and whether individuals must be told.
- Prepare the facts. Collect the Article 33(3) information, even if some parts are still estimates.
- Submit. Complete the online form in one session and keep a copy and the reference number.
- Update. Send further information without undue delay as the investigation progresses.
Running breaches through spreadsheets and email makes the 72-hour window harder to meet. You can start your 14-day free trial of Enactia’s AI-powered GRC platform and use built-in 72-hour notification workflows.
Worked example: the first 72 hours
The timeline below is an illustrative template for a ransomware incident affecting customer records. Adapt the timings to your own incident response plan.
| Time from awareness | Action | Owner |
|---|---|---|
| Hour 0 | Security team confirms personal data is affected; DPO notified; clock recorded | CISO, DPO |
| Hours 0 to 4 | Containment; evidence preserved; initial scoping of data and individuals | IT, security |
| Hours 4 to 24 | Risk assessment; decision on ICO report and individual notification; processor and insurer contacted | DPO, legal |
| Hours 24 to 48 | Draft ICO report with known facts; prepare individual notices if high risk | DPO, communications |
| By hour 72 | Submit ICO report; record reference; plan phased updates | DPO |
| After 72 hours | Send updates; notify individuals without undue delay if required; log lessons learned | DPO, CISO |
A dedicated incident and data breach management process that records the awareness time and each decision gives you the audit trail the ICO may ask for.
When must you tell affected individuals?
You must tell individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms. The threshold is higher than for reporting to the ICO.
Your message should explain, in clear and plain language, the nature of the breach, the DPO or contact point, the likely consequences and the measures taken. The ICO also recommends giving practical advice, such as resetting passwords or watching for suspicious activity. Under Article 34(3), notification may not be required where the data was protected, for example by encryption, or where you have taken steps that mean the high risk is no longer likely.
Do other UK reporting rules apply?
Possibly. Depending on your sector, a single incident can trigger more than one UK reporting duty.
| Regime | Who it applies to | Deadline | Report to |
|---|---|---|---|
| UK GDPR Article 33 | Controllers processing personal data | Without undue delay, where feasible within 72 hours | ICO |
| PECR | Providers of public electronic communications services | Within 72 hours of becoming aware | ICO |
| NIS Regulations 2018 | Operators of essential services and relevant digital service providers | Set by the regulations; check your competent authority’s guidance | Sector competent authority, or the ICO for digital service providers |
| EU GDPR | UK organisations also processing EU residents’ data under the EU GDPR | Within 72 hours where feasible | Relevant EU supervisory authority |
The ICO’s PECR guidance confirms that the Data (Use and Access) Act 2025 changed the PECR reporting window from 24 hours to 72 hours, and that failure to notify can lead to a GBP 1,000 fixed penalty. Change is also coming for critical sectors: the government’s Cyber Security and Resilience Bill, introduced on 12 November 2025 and at report stage in the House of Lords at the time of writing, proposes reporting significant incidents to the regulator and the NCSC within 24 hours, with a full report within 72 hours. If you also operate in the EU, our NIS2 incident reporting guide covers the EU cascade.
What happens if you get breach reporting wrong?
Failing to notify a reportable breach can itself lead to a fine of up to GBP 8.7 million or 2% of global turnover, according to the ICO. The underlying security failure can attract higher penalties.
In October 2025 the ICO fined Capita GBP 14 million over a 2023 cyber attack affecting 6.6 million people. The ICO highlighted that a security alert was raised within 10 minutes but the affected device was not quarantined for 58 hours. The lesson for DPOs is that detection, escalation and decision-making speed matter as much as the report itself.
Common mistake: forgetting processors. Your contracts should require processors to notify you without undue delay, and your vendor risk management reviews should test that they can.
Key takeaways
- Report to the ICO when a breach is likely to result in a risk to individuals, where feasible within 72 hours of awareness.
- Report early and update later; phased reporting is accepted.
- Tell individuals without undue delay if the risk is high.
- Log every breach, including those you decide not to report, with your reasoning.
- Check whether PECR, the NIS Regulations or the EU GDPR also apply to the same incident.
Frequently asked questions
Do all personal data breaches need to be reported to the ICO?
No. You only need to report a breach that is likely to result in a risk to people’s rights and freedoms. However, you must document every breach, including the facts, effects and remedial action, and record why you decided not to report. The ICO’s self-assessment tool can help you make the decision.
What if we cannot give full details within 72 hours?
Report what you know within 72 hours and provide the rest in phases without undue delay. The ICO accepts that a complete picture is often not available at first. If your initial report is late, explain the reasons for the delay in the report itself.
Can we report a data breach to the ICO by phone?
The ICO’s primary route for personal data breach reports is its online form, supported by a self-assessment tool. Check the ICO’s report a breach page for the current contact options before an incident happens, and include them in your incident response plan so staff are not searching under pressure.
Who is responsible for reporting: the controller or the processor?
The controller reports to the ICO and, where needed, to individuals. A processor must notify the controller without undue delay after becoming aware of a breach. Contracts should set clear processor notification timescales so the controller can still meet its own 72-hour deadline.
Is ICO breach reporting different from EU GDPR breach reporting?
The rules are almost identical: the same risk test, 72-hour window and content requirements. The difference is the regulator. UK processing is reported to the ICO; processing under the EU GDPR is reported to the relevant EU supervisory authority, so one incident may need both reports.
Conclusion: be ready before the clock starts
ICO data breach reporting rewards preparation. Agree your risk method, rehearse the first 72 hours, know which regimes apply to you and keep a clear log of every decision. For wider pitfalls, see our article on common mistakes in GDPR compliance and our GDPR framework page.
If you want to see how structured breach workflows can help you meet the ICO deadline, contact us or book a demo or start your 14-day free trial.
This article is for general information and is not legal advice.
