Artifact GuideUKBreach Notification

UK GDPR Breach Notification

A controller reports a personal data breach to the ICO unless risk to people's rights and freedoms is unlikely. It tells affected people only when high risk is likely, subject to Article 34 exceptions.

Use this guide for implementation planning, not as a substitute for checking the consolidated UK GDPR, applicable Data Protection Act 2018 provisions, current ICO guidance, contracts, and the facts of the processing.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 16, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 16, 2026
Overview

Start the assessment when a security breach causes accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. A processor must alert the controller without undue delay. The controller separately decides whether to notify the ICO under Article 33 and affected people under Article 34, while documenting every .

Section 1

What should teams decide about Breach Notification under the UK GDPR?

Start by deciding whether the incident is a and whether it is likely to result in a risk to individuals. If that threshold is met, the controller must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach.

Run a separate high-risk test for affected individuals. If high risk is likely, communicate without undue delay in clear, plain language. Direct communication is not required where effective measures such as encryption made the data unintelligible, later measures ensure high risk is no longer likely, or direct contact would involve disproportionate effort and an equally effective public communication is used.

  • Record when the controller became aware, the facts then known, and how the 72-hour deadline was calculated.
  • Assess likelihood and severity using the data, people, scale, identifiability, consequences, containment, and vulnerability of affected people.
  • If reporting, describe the breach, approximate people and records, contact point, likely consequences, and measures taken or proposed. Give reasons for delay after 72 hours.
  • Report available information on time and provide missing information in phases without undue further delay.
  • Record the facts, effects, remedial action, ICO decision, individual-communication decision, Article 34 exception if used, and follow-up.
Section 2

Who should own Breach Notification, and what evidence should prove the decision?

The controller owns the Article 33 and 34 decisions. An incident lead should coordinate security containment and fact-finding, privacy or legal risk analysis, communications, service support, and processor evidence. Processor contracts should require escalation without undue delay and enough information for the controller to meet its deadline.

Evidence should show the awareness timestamp, incident facts, affected data and people, containment steps, risk assessment, notification decision, ICO submission or non-reporting rationale, data-subject notice decision, and follow-up updates.

  • Incident lead: preserve the first alert, investigation timeline, systems, containment, recovery and changing factual picture.
  • Privacy or legal decision owner: record awareness, Article 33 risk, Article 34 high risk, reasons, report timing, delay and any exception.
  • Processor manager: obtain the processor's awareness time, affected controller data, scope, measures, updates and contract escalation evidence.
  • Communications owner: prepare a clear individual notice with the breach nature, contact point, likely consequences, mitigation and steps people can take.
  • Closure owner: reconcile ICO updates, individual communications, remediation, lessons learned and the final breach record.
Section 3

Which edge cases should teams check before relying on a Breach Notification decision?

Check processor-to-controller reporting duties, PECR security-breach rules for communications service providers, sector reporting duties, EU GDPR or other foreign notification rules, vulnerable individuals, encrypted data, and whether phased reporting is needed because facts are incomplete. These clocks and thresholds can run in parallel.

Do not reuse transfer, DPIA, lawful-basis, or Article 30 evidence as a substitute for a breach record. The breach file needs its own timeline, risk test, notification decisions, and mitigation record.

  • A confidentiality breach, integrity breach or loss of availability can qualify; recovery from backup affects the harm assessment but does not erase the event.
  • A small breach can still be reportable or high risk where the data or affected people make the possible harm severe.
  • Encryption supports an Article 34 exception only when it applied to the affected data and made it unintelligible to unauthorised people.
  • A processor's notice does not replace the controller's ICO decision, and the processor should not wait for a complete investigation before escalating.
  • PECR, sector, contractual, insurer, law-enforcement and foreign-regulator duties can have different triggers, recipients and clocks; record each separately.
Section 4

How should teams operationalize Breach Notification with proportionate controls?

Use a UK GDPR breach workflow that records the awareness time, preserves evidence, contains the incident, identifies affected data and people, assesses risk, and makes the separate ICO and individual-notification decisions. Do not wait for a complete forensic report before deciding whether phased ICO notification is required.

The output should be a dated breach log, risk assessment, ICO report or non-reporting rationale, individual notice decision, mitigation actions, and follow-up review.

  • Triage: confirm personal data and a security breach, preserve evidence, contain the event, and record controller awareness with date, time and time zone.
  • ICO branch: decide whether risk to rights and freedoms is unlikely; if not, report without undue delay and, where feasible, within 72 hours, then phase missing information.
  • People branch: decide separately whether high risk is likely; if so, communicate without undue delay unless a stated Article 34 exception applies.
  • Parallel branch: identify processor, PECR, sector, contractual and foreign notification duties without assuming the UK GDPR report satisfies them.
  • Close: retain facts, effects, remedial action, submissions, notices, non-notification reasons, delay reasons, updates and recurrence-prevention work.
Primary sources

References and citations

ico.org.uk
Referenced sections
  • Explains the UK GDPR duty to report certain personal data breaches to the ICO within 72 hours where feasible and to inform individuals where high risk is likely.
"report certain personal data breaches to the relevant supervisory authority"
Related guides

Explore more topics

How do you choose a lawful basis under the UK GDPR?
Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.
UK Children's Code: Scope and 15 Standards
Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.
UK GDPR 72-hour Breach Reporting Guide
Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
UK GDPR 72-Hour Breach Reporting: Decision Guide
Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.
UK GDPR Adequacy Guide
Use UK transfer approval regulations by checking the destination, recipient, data, sector, effective status, scope limits, and review evidence.
UK GDPR Adequacy: When Can You Rely on It?
Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.
UK GDPR AI and Automated Decisions Guide
Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
UK GDPR AI and Automated Decisions: Articles 22A-22D
Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.
UK GDPR Applicability Test Guide
Apply the UK GDPR material and territorial scope tests to one processing activity, including exclusions, non-UK organisations, roles, and evidence.
UK GDPR Article 30 Records Guide
Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
UK GDPR Article 30 Records: What to Document
See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.
UK GDPR Breach Workflow Guide
Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
UK GDPR Children and Age Appropriate Design Guide
Apply UK GDPR children's protections and the Age Appropriate Design Code to online services likely to be accessed by children.
UK GDPR Children's Code Guide
A practical guide to Children's Code scope, its 15 standards, age 13 consent, evidence, exceptions, and product implementation.
UK GDPR Compliance Checklist
A verifiable UK GDPR checklist for scope, lawful processing, transparency, rights, governance, security, breaches, DPIAs, children, and transfers.
UK GDPR Compliance FAQ: Duties, Rights, and Decisions
Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.
UK GDPR Compliance Guide
Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.
UK GDPR Controller and Processor Status Guide
Decide whether each party is a controller, joint controller, or processor under the UK GDPR, then record the role-specific duties, contract terms, and evidence.
UK GDPR Controller or Processor: How to Decide
Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.
UK GDPR Data Subject Rights Guide
Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
UK GDPR Deadlines and Compliance Calendar Guide
Track UK GDPR deadlines for rights requests, privacy information, breach notification, DPIAs, and ICO prior consultation, with triggers and exceptions.
UK GDPR DPIA Workflow Guide
Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
UK GDPR DPIA: When It Is Required and What to Record
Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.
UK GDPR DPIAs and DPOs Guide
Decide when the UK GDPR requires a DPIA or DPO, what each must cover, when to consult the ICO, and what evidence to retain.
UK GDPR DPO: When Appointment Is Mandatory
Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.
UK GDPR DSAR Workflow Guide
Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
UK GDPR IDTA Addendum and Transfer Risk Assessment Guide
Choose the UK IDTA or Addendum, complete the current Article 46 data protection test, add needed measures, and maintain evidence for restricted transfers.
UK GDPR Lawful Bases Guide
Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
UK GDPR PECR Cookies Guide
UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
UK GDPR Penalties and Fines: Maximums and ICO Factors
Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine.
UK GDPR Requirements Guide
Map UK GDPR requirements by processing activity, role, lawful basis, data type, risk, rights, suppliers, automated decisions, and transfers.
UK GDPR Transfer Workflow Guide
Apply the UK GDPR restricted-transfer sequence: map the transfer, check Article 45A approval, choose an Article 46 safeguard and assessment, or justify a specific Article 49 derogation.
UK GDPR Transfers, IDTA, and UK Addendum Guide
Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.
UK GDPR vs Data Protection Act 2018: How They Work Together
See when to use the UK GDPR, when the Data Protection Act 2018 adds a condition or exemption, and which regime covers law enforcement or intelligence processing.
UK GDPR vs EU GDPR: Scope, Regulators and Transfers
Determine whether UK GDPR, EU GDPR, or both apply, then separate representatives, regulators, transfer routes, national law, and post-Brexit UK amendments.
UK IDTA vs EU SCCs: Which Transfer Contract to Use
Choose between the UK IDTA and EU SCCs with the UK Addendum, complete the right documents, and record the separate UK and EU transfer assessments.
UK IDTA, Addendum, and Transfer Risk Assessment Guide
Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.
UK vs EU GDPR Differences After the 2025 UK Reforms
Compare current UK and EU rules for recognised legitimate interests, rights requests, access searches, automated decisions, and international transfers.
UK vs EU GDPR Operations: Regulators, Breaches and Transfers
Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.
When do PECR cookie rules require consent?
Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.