24/7 Support Available
Skip to main content
Intermediate
Within 72 hours

GDPR Data Breach Response

How to handle a personal data breach under UK GDPR: judge the risk to people, decide whether the ICO and those affected need to be told, and keep the records the law requires.

Prerequisites

  • A record of what personal data you hold and where, so you can judge what a breach actually exposed.
  • Your Data Protection Officer or the person responsible for data protection, brought in straight away.
  • A breach log, ready to record every incident whether or not you end up reporting it.
  • The ICO reporting details and your account, so you are not searching for them under pressure.

Step-by-Step Instructions

Confirm you have a personal data breach

Not every security incident is a personal data breach, but many are. A breach is any event that leads to personal data being lost, stolen, altered, destroyed, or shared without authorisation. Lost laptops, emails sent to the wrong person and ransomware all count. When in doubt, treat it as a breach and assess it properly.

Contain it and note the time

Stop the exposure continuing: recover the device, recall the message where you can, or shut down the affected system. Write down the moment you became aware of the breach, because the 72 hour reporting window starts then, not when the breach first happened. This timestamp shapes every deadline that follows.

Tip

Awareness starts the clock, and it includes weekends and bank holidays. If you become aware on a Friday evening, the deadline is Monday evening, so decide who can act out of hours before you ever need them.

Assess the risk to people

The duty to report turns on the risk to the people whose data is involved, not the size of the breach. Consider how sensitive the data is, how many people are affected, and what harm could follow, such as fraud, distress or discrimination. A single record of health or financial data can carry more risk than thousands of ordinary email addresses.

Decide whether to tell the ICO

If the breach is likely to result in a risk to people's rights and freedoms, you must report it to the ICO within 72 hours. If it is unlikely to, you do not report it, but you must still record why you decided that. If you miss the 72 hours, you can still report late with an explanation, which is far better than not reporting at all.

Decide whether to tell the individuals

Where the breach is likely to result in a high risk to the people affected, you must tell them without undue delay, in plain language. Explain what happened, what data was involved, what you are doing about it, and the practical steps they can take to protect themselves, such as changing a password or watching for suspicious contact.

Record everything and fix the cause

Document the facts, your assessment, your decisions and the reasoning, even for breaches you choose not to report. The ICO can ask to see this log. Once the incident is closed, deal with the underlying cause, because a pattern of similar breaches is what turns a manageable situation into a much larger problem.

Every organisation is different, and a playbook can only take you so far. If you would like a second pair of eyes, or you would rather we handled the work, our compliance & certification team is here to help. Talk to us about your requirements.