Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

UK GDPR breach notification infographic

UK GDPR Breach Notification: The Essential 2026 Guide to the 72-Hour Rule

UK GDPR breach notification is the duty to report certain personal data breaches to the Information Commissioner’s Office and, where the risk is high, to tell the people affected. Under Article 33 of the UK GDPR, a controller must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of a breach, unless the breach is unlikely to result in a risk to people’s rights and freedoms.

Many organizations worry about the clock and forget the rest: assessing the risk, keeping a record of every breach, notifying individuals when needed and learning from the incident. A clear plan, agreed before anything goes wrong, makes all of this easier.

This guide explains the rules, the decision steps and the records you need. It is general information, not legal advice, so take advice on serious incidents.

Free gap assessment

Is your UK programme up to date with the 2025 Act?

Score the UK GDPR, the DPA 2018 and PECR as amended, free, including the new rights timetable, the complaints duty and the cookie exceptions.

Run the free UK GDPR gap assessment →  or  View premium report sample

What counts as a personal data breach

A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. It is broader than hacking. An email sent to the wrong person, a lost laptop, a ransomware attack that makes data unavailable and an employee who looks at records without a reason can all be breaches.

Breaches are commonly described as confidentiality, integrity or availability breaches. Loss of access to data, even without anyone seeing it, can be a breach if it affects people, for example if a clinic cannot reach patient records.

If you are unsure whether an event is a breach, treat it as one until you have assessed it. It is easier to conclude it was not reportable than to reconstruct an investigation later.

The 72-hour rule in UK GDPR breach notification

The clock starts when you become aware of the breach, meaning you have a reasonable degree of certainty that a security incident has occurred that led to personal data being compromised. It does not wait for the full investigation. The ICO’s guidance, at ICO guidance on reporting a personal data breach, encourages a report-early, update-later approach: give what you know within the deadline and add details as they emerge.

The 72 hours include weekends. If you cannot report within 72 hours, you must explain the reasons for the delay when you do report. Build your process so someone can file on a Saturday.

Notification is required unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. Document your reasoning when you decide not to report, because the ICO may ask how you reached that conclusion.

QuestionRuleAction
Who must notify the ICO?Controllers, where the breach is likely to risk people’s rights and freedomsReport within 72 hours where feasible
What if we are a processor?Tell the controller without undue delayContract deadline, often sooner
When tell individuals?Where the breach is likely to result in high riskWithout undue delay
What must we record?Every breach, reported or notBreach log with facts, effects, actions

Assess the risk to individuals

The test is risk to people, not risk to the organization. Consider the type of data, how sensitive it is, how many people are affected, how easy it is to identify them, the severity of possible consequences and any special characteristics such as children or vulnerable groups.

Examples of harm include identity theft, financial loss, discrimination, loss of confidentiality of medical information, physical harm and distress. Encryption that protects the data reduces the likelihood of harm but may not remove it entirely if keys were exposed.

Use a simple scoring approach: likelihood of harm and severity. A breach with a high score normally means reporting to the ICO, and a very high score may also mean telling the individuals.

When to tell the people affected

Where a breach is likely to result in a high risk to individuals, you must tell them without undue delay. The communication should describe the nature of the breach in clear language, give the name and contact details of the data protection contact, explain the likely consequences and describe the measures taken or proposed.

Advise people what they can do to protect themselves, such as changing passwords, watching for phishing or contacting their bank. Use a channel that will actually reach them, and keep a copy of what you sent.

There are limited exceptions, for example where data was encrypted so it is unintelligible, or where later measures mean high risk is no longer likely. Record the reasons.

Record every breach

Article 33 also requires you to document all personal data breaches, including the facts, their effects and the remedial action taken. This applies even to breaches you decide not to report. The ICO may ask to see your breach log.

A good log entry includes the date and time of discovery, a description, the data and number of people affected, the risk assessment and decision, who was notified and when, actions taken and lessons learned. Keep it in one place with access limited to those who need it.

Free privacy risk assessment

Which privacy risks would hurt the people whose data you hold?

List your personal data and processing, pick from 38 privacy risk scenarios, rate them for the people concerned and for you, and plan treatment with ISO 27701 controls. You get a heat map, a process score and the findings an auditor would raise, free.

Run the free privacy risk assessment →  or  View premium report sample

Review the log regularly for patterns. Repeated misdirected emails, for example, suggest a need for technical controls or training rather than another reminder.

Processors, vendors and contracts

A processor must notify the controller without undue delay after becoming aware of a breach. Your contracts should set a specific deadline, often 24 to 48 hours, and require the processor to provide the information you need to assess the incident and to cooperate on notification.

Keep a list of the vendors that hold personal data, with contact details for incident reporting. When a vendor tells you about a breach, the 72 hours for you as controller generally start when you become aware. Plan for that.

Also check what other regimes apply. If you operate in the EU, you may have parallel obligations, and communications providers have shorter deadlines under separate rules. See UK GDPR vs EU GDPR for how the regimes differ.

Build a UK GDPR breach notification response plan

A workable plan has roles and steps. Name an incident lead, a decision-maker for notification, legal or data protection support, IT or security, communications and a scribe. Write a short runbook: contain, assess, decide, notify, recover, review.

Practice. A tabletop exercise once a year reveals gaps in contact lists, approvals and information that is hard to find. Include realistic scenarios such as ransomware, a misdirected email with special category data and a vendor breach.

The data protection officer or privacy lead should be involved early, as described in UK GDPR data protection officer. Your overall framework is explained in UK GDPR.

A short UK GDPR breach notification example

An employee at a small clinic emails a spreadsheet of appointment details to the wrong external address on a Friday afternoon. The team recalls the email, contacts the recipient and receives confirmation of deletion. It assesses the risk: 40 patients, names and appointment types, some sensitive. The team judges that the risk is not low, reports to the ICO on Saturday within the 72 hours, and tells the affected patients on Monday.

It records the breach in the log, adds an email warning for external recipients and trains staff on attachment checks. The example is invented, but it shows how UK GDPR breach notification combines assessment, reporting, communication and improvement.

Notice that the decisions and the reasoning are recorded at each step. That record is what the ICO will want to see.

UK GDPR breach notification penalties and other duties

Failing to notify when required can lead to enforcement. The maximum fines under the UK GDPR are higher for serious infringements and lower for procedural ones, and the ICO considers the circumstances, including how well you handled the breach. Prompt, honest reporting and strong remediation count in your favor.

Affected people can complain to you and to the ICO, so make sure your complaints process works. See data protection complaints procedure. The recent reforms are summarized in Data (Use and Access) Act 2025.

Keep your privacy notice accurate about how you handle breaches and how people can contact you, as explained in UK GDPR privacy notice.

Using a ready-made UK GDPR breach notification pack

Preparing a breach policy, a log, a risk assessment form, notification templates and a runbook from scratch takes time. A prepared set gives you a structure to adapt.

The UK GDPR Toolkit provides 90 editable UK data protection templates written for the UK GDPR as amended by the Data (Use and Access) Act 2025, including breach management, privacy notices, subject access and complaints procedures and international transfer guides. Adapt the wording to your organization.

Review your UK GDPR breach notification plan after every incident and at least once a year.

UK GDPR breach notification FAQ

How long do I have to report a breach to the ICO?

Without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to people.

Do I have to report every breach?

No, but you must record every breach and be able to explain why you decided not to report a low-risk one.

When must I tell individuals?

Without undue delay when the breach is likely to result in a high risk to their rights and freedoms.

What if I do not have all the facts?

Report what you know within the deadline and send further information as it becomes available.

Does a processor report to the ICO?

A processor tells the controller without undue delay. The controller decides on notification to the ICO and individuals.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.