How to Report a Data Breach: A Practical Guide

How to report a Data Breach: A Practical Guide

What does the law say about reporting a breach?

As previously mentioned, under Article 33(1) you are required to report a breach to the ICO unless it is “unlikely to result in a risk to the rights and freedoms of natural persons”.

Or, to put it in plain English, you must report a data breach when your assessment has identified that there is a risk to the rights and freedoms of the people affected.

Following on from that, if you have identified a high risk to individuals, you also need to notify them.

How do we report a breach?

Reporting a breach to the ICO is a fairly straightforward process which can be done using their website.

Before reporting a breach, you should ensure that you have:

  • An understanding of what happened
  • When and how did you become aware of the breach
  • Identified the groups who have been affected (clients, employees etc.)
  • How are you working to mitigate the breach, and
  • Contact details for the person responsible for liaising with the ICO about the breach

If you are notifying the ICO outside of the 72-hour timeframe, you must also explain why your notification is late.

You will receive an acknowledgement from the ICO and a follow-up email from the caseworker assigned, though this can take some time and is dependent on the severity of the breach and availability of ICO caseworkers.

How do we not report a breach?

So, you got lucky and it’s not reportable to the ICO? Well, even if you don’t have to report back into your board that there were no ICO reportable breaches this quarter you still have some work to do!

Throughout the process of investigating the breach, you will have been keeping a log of your actions and findings. This is the time to wrap it all together in a neat bow. Article 33(5) requires you to document all facts and any action taken during the course of the breach. This includes, at this stage when you have deemed it non-reportable, your reasoning for why it is non-reportable.

Communicating a breach to a data subject

This is less straightforward than reporting a breach.

As above, if you have identified a high risk you must notify the affected data subjects.

However, this does come with some caveats. If you have:

  • Implemented appropriate technical and organisational measures to reduce the impact of the breach, or
  • Taken measures to ensure the risks you identified are no longer likely to occur

Then you are not required to make the notification.

Otherwise, if it is not possible to communicate directly with a data subject affected you are released from the requirement in one sense, but must instead make a public communication that informs the data subjects.

In your communication to the individual, you must include the following:

  • A plain English explanation of what occurred and how they are affected
  • Contact details for the person responsible for liaising with the individual(s) about the breach
  • The possible consequences of the breach, and
  • How you are working to mitigate the breach

The ICO may also compel you to report a breach to individuals if they have identified that the breach you reported is of sufficient risk. As such, it is important to have a procedure in place for if such an event were to occur.

related posts

Sophie Costain

Should All My Employees Be Able to Recognise a Subject Access Request?

Data protection is not just about cybersecurity; it relies on your employees recognising Subject Access Requests. The statutory one-month deadline begins the moment a request is received, even informally. Discover why training your entire workforce to instantly spot and escalate these requests is essential to avoid serious regulatory compliance breaches.

Read More »
Alex Haslam

DPAS Data Protection Bulletin – July 2026

Welcome back to our monthly DPAS bulletin, where we cover the latest data protection news and developments from around the world.

Ever wondered how a routine government spreadsheet leak turns into a two-year covert court order? How about why the police might feel your mother-in-law’s contact details were key to national security? Have you ever pondered how many working weeks it takes to read a cookie banner? Whether Wall Street knows about your last GP visit? Or if you’re in Australia (g’day) why an AI is sending notes on your worst rashes to faraway cloud servers?

Read about all this and more in our latest DPAS Data Protection Bulletin.

Read More »
Alex Haslam

Root Cause Analysis: A Practical Guide

A practical guide to data breach reporting under UK GDPR, covering when you must notify the ICO, how to report a breach (and what to do if you don’t need to), and when affected individuals need to be told. Includes the key steps, timeframes, and documentation requirements to keep your organisation compliant.

Read More »

Get a Free Consultation