UK Data Breach Reporting: The 72-Hour ICO Rule

Independently fact-checkedBy Recording Law Editorial Team9 min read

Independently fact-checked against primary sources (last audited June 19, 2026). · 8 primary sources cited on this page. How we verify our legal content

UK Data Breach Reporting: The 72-Hour ICO Rule

Frequently Asked Questions

How long do I have to report a data breach to the ICO?

Under UK GDPR Article 33(1), you must report a notifiable personal data breach to the Information Commissioner's Office without undue delay and, where feasible, not later than 72 hours after becoming aware of it. The 72 hours run on calendar time, including weekends. If you report late, the notification must be accompanied by reasons for the delay. You do not have to finish investigating first; if you cannot provide all the information at once you can report in phases under Article 33(4).

When does the 72-hour clock start?

The clock starts when you become 'aware' of the breach, which the ICO treats as the point at which you have a reasonable degree of certainty that a security incident has occurred and compromised personal data. It is not the moment you have every detail. Where a data processor suffers the breach, the processor must tell you without undue delay under Article 33(2), and your time to report to the ICO generally runs from when you, the controller, become aware.

Do I have to report every data breach?

No. You only have to notify the ICO if the breach is likely to result in a risk to the rights and freedoms of individuals. If you assess that a risk is unlikely, you do not report it to the ICO. However, Article 33(5) still requires you to document the breach internally in your breach register, recording the facts, its effects, the remedial action taken, and your reasoning for not reporting.

What is the difference between reporting to the ICO and telling affected individuals?

They have different thresholds. You report to the ICO under Article 33 when a breach is likely to result in a risk to people's rights and freedoms. You must also tell the affected individuals directly under Article 34 only when the breach is likely to result in a high risk. The high-risk threshold is higher, so many breaches are reportable to the ICO without requiring you to contact individuals. When individual notification is required, it must be in clear and plain language and made without undue delay.

What information must a breach report to the ICO include?

Article 33(3) requires you to describe the nature of the breach, including, where possible, the categories and approximate number of individuals and personal data records affected; give the name and contact details of your data protection officer or other contact point; describe the likely consequences of the breach; and describe the measures you have taken or propose to take to address it and mitigate any adverse effects. Approximate figures and your best current assessment are acceptable in an initial report.

What counts as a personal data breach?

A personal data breach is a security incident affecting the confidentiality, integrity or availability of personal data. That covers personal data being lost, destroyed, corrupted or disclosed without authorisation, someone accessing or sharing it without authority, and data being made unavailable, for example through ransomware or accidental deletion. Breaches can be accidental as well as deliberate, so a misdirected email, a lost unencrypted laptop, or files left in a public place can all be breaches if they involve personal data.

Do I have to keep a record of breaches I decide not to report?

Yes. Article 33(5) requires controllers to document every personal data breach, including those assessed as not notifiable, recording the facts, the effects, and the remedial action taken. The ICO recommends keeping an internal breach register and a documented breach-reporting procedure. The register is accountability evidence: if the ICO ever investigates, it is how you demonstrate that your decision not to report a particular breach was reasonable.

What is the penalty for failing to report a data breach?

Failing to notify the ICO when required is a standard-tier infringement, carrying a maximum fine of GBP 8.7 million or 2% of total worldwide annual turnover, whichever is higher. This is separate from any penalty for the underlying security failure, which can fall in the higher tier of up to GBP 17.5 million or 4% of global turnover. The ICO can also issue enforcement notices and reprimands. Reporting promptly, even with incomplete information, is far safer than reporting late or not at all.

Updates

Independently fact-checked against the cited primary sources

Sources and References

  1. UK GDPR Article 33, Notification of a personal data breach to the supervisory authority(legislation.gov.uk).gov
  2. UK GDPR Article 34, Communication of a personal data breach to the data subject(legislation.gov.uk).gov
  3. ICO, Personal data breaches: a guide(ico.org.uk).gov
  4. ICO, 72 hours: how to respond to a personal data breach(ico.org.uk).gov
  5. ICO, Personal data breach examples(ico.org.uk).gov
  6. ICO, Self-assessment for data breaches(ico.org.uk).gov
  7. ICO, The maximum amount of a fine under UK GDPR and DPA 2018(ico.org.uk).gov
  8. Data Protection Act 2018(legislation.gov.uk).gov
Share: