How to Report a Data Breach: A Practical Guide

How to report a Data Breach: A Practical Guide

What does the law say about reporting a breach?

As previously mentioned, under Article 33(1) you are required to report a breach to the ICO unless it is “unlikely to result in a risk to the rights and freedoms of natural persons”.

Or, to put it in plain English, you must report a data breach when your assessment has identified that there is a risk to the rights and freedoms of the people affected.

Following on from that, if you have identified a high risk to individuals, you also need to notify them.

How do we report a breach?

Reporting a breach to the ICO is a fairly straightforward process which can be done using their website.

Before reporting a breach, you should ensure that you have:

  • An understanding of what happened
  • When and how did you become aware of the breach
  • Identified the groups who have been affected (clients, employees etc.)
  • How are you working to mitigate the breach, and
  • Contact details for the person responsible for liaising with the ICO about the breach

If you are notifying the ICO outside of the 72-hour timeframe, you must also explain why your notification is late.

You will receive an acknowledgement from the ICO and a follow-up email from the caseworker assigned, though this can take some time and is dependent on the severity of the breach and availability of ICO caseworkers.

How do we not report a breach?

So, you got lucky and it’s not reportable to the ICO? Well, even if you don’t have to report back into your board that there were no ICO reportable breaches this quarter you still have some work to do!

Throughout the process of investigating the breach, you will have been keeping a log of your actions and findings. This is the time to wrap it all together in a neat bow. Article 33(5) requires you to document all facts and any action taken during the course of the breach. This includes, at this stage when you have deemed it non-reportable, your reasoning for why it is non-reportable.

Communicating a breach to a data subject

This is less straightforward than reporting a breach.

As above, if you have identified a high risk you must notify the affected data subjects.

However, this does come with some caveats. If you have:

  • Implemented appropriate technical and organisational measures to reduce the impact of the breach, or
  • Taken measures to ensure the risks you identified are no longer likely to occur

Then you are not required to make the notification.

Otherwise, if it is not possible to communicate directly with a data subject affected you are released from the requirement in one sense, but must instead make a public communication that informs the data subjects.

In your communication to the individual, you must include the following:

  • A plain English explanation of what occurred and how they are affected
  • Contact details for the person responsible for liaising with the individual(s) about the breach
  • The possible consequences of the breach, and
  • How you are working to mitigate the breach

The ICO may also compel you to report a breach to individuals if they have identified that the breach you reported is of sufficient risk. As such, it is important to have a procedure in place for if such an event were to occur.

related posts

Jack Penaligon

How to Respond to a Data Breach: A Practical Guide

This blog provides an overview of the practical steps organisations can take to reduce the impact of a data breach once it has been identified. It focuses on the actions that should be taken during the early stages of an incident to contain the breach, protect affected individuals, and meet regulatory requirements.

The article discusses a range of mitigation measures, including contacting unintended recipients of personal data, securing the deletion or recovery of exposed information, isolating compromised systems, and maintaining clear records of actions taken. It also explores the challenges posed by both digital and physical data breaches, highlighting the importance of balancing operational needs with data protection obligations.

Finally, the blog emphasises the value of preparation, explaining how established procedures, communication templates, and predefined response plans can help organisations respond more effectively and demonstrate accountability during a regulatory investigation.

Read More »
Noah de Wild

How to Assess a Data Breach: A Practical Guide

This blog explains how to assess a data breach by identifying its cause, determining what information was exposed, and evaluating the potential impact on affected individuals and the organisation. It outlines common causes of breaches, the importance of understanding the type and scale of compromised data, and how assessing the timeline of an incident can help businesses respond effectively, meet legal obligations, and reduce long-term risks.

Read More »
Noah de Wild

Don’t Panic: A Pragmatic Guide to the June 2026 Enforcement of the Data (Use and Access) Act Changes

With the June 19, 2026 enforcement of the Data (Use and Access) Act approaching, ensuring your business is compliant doesn’t have to be complicated or expensive. In our latest guide, we break down exactly what the new data protection complaint rules mean for you. Cut through the noise and discover our simple, free six-step checklist to update your protocols, designate handlers, and keep your business confidently compliant.

Read More »

Get a Free Consultation