How to report a Data Breach: A Practical Guide
What does the law say about reporting a breach?
As previously mentioned, under Article 33(1) you are required to report a breach to the ICO unless it is “unlikely to result in a risk to the rights and freedoms of natural persons”.
Or, to put it in plain English, you must report a data breach when your assessment has identified that there is a risk to the rights and freedoms of the people affected.
Following on from that, if you have identified a high risk to individuals, you also need to notify them.
How do we report a breach?
Reporting a breach to the ICO is a fairly straightforward process which can be done using their website.
Before reporting a breach, you should ensure that you have:
- An understanding of what happened
- When and how did you become aware of the breach
- Identified the groups who have been affected (clients, employees etc.)
- How are you working to mitigate the breach, and
- Contact details for the person responsible for liaising with the ICO about the breach
If you are notifying the ICO outside of the 72-hour timeframe, you must also explain why your notification is late.
You will receive an acknowledgement from the ICO and a follow-up email from the caseworker assigned, though this can take some time and is dependent on the severity of the breach and availability of ICO caseworkers.
How do we not report a breach?
So, you got lucky and it’s not reportable to the ICO? Well, even if you don’t have to report back into your board that there were no ICO reportable breaches this quarter you still have some work to do!
Throughout the process of investigating the breach, you will have been keeping a log of your actions and findings. This is the time to wrap it all together in a neat bow. Article 33(5) requires you to document all facts and any action taken during the course of the breach. This includes, at this stage when you have deemed it non-reportable, your reasoning for why it is non-reportable.
Communicating a breach to a data subject
This is less straightforward than reporting a breach.
As above, if you have identified a high risk you must notify the affected data subjects.
However, this does come with some caveats. If you have:
- Implemented appropriate technical and organisational measures to reduce the impact of the breach, or
- Taken measures to ensure the risks you identified are no longer likely to occur
Then you are not required to make the notification.
Otherwise, if it is not possible to communicate directly with a data subject affected you are released from the requirement in one sense, but must instead make a public communication that informs the data subjects.
In your communication to the individual, you must include the following:
- A plain English explanation of what occurred and how they are affected
- Contact details for the person responsible for liaising with the individual(s) about the breach
- The possible consequences of the breach, and
- How you are working to mitigate the breach
The ICO may also compel you to report a breach to individuals if they have identified that the breach you reported is of sufficient risk. As such, it is important to have a procedure in place for if such an event were to occur.





