Start when anyone reports loss, alteration, unauthorised disclosure or access, or loss of availability involving personal data. Contain the incident without destroying evidence. The controller is aware when it has a reasonable degree of certainty that a security incident has compromised personal data; record that timestamp and the facts supporting it.
Notify the ICO unless the breach is unlikely to result in a risk to people's rights and freedoms. The deadline is without undue delay and, where feasible, no later than 72 hours after awareness. If the facts are incomplete, submit the available Article 33 information and provide the rest in phases without undue further delay.
Apply the thresholds to the likely consequences for people, not only to the incident's technical severity or cost to the organisation. For example, ICO guidance says theft of a customer database that could enable identity fraud is likely to be reportable, while loss or inappropriate alteration of a staff telephone list would not normally require notification. These examples illustrate the test; the data, exposure, safeguards, affected people, and likely harm in the actual incident control the decision.
Run the Article 34 decision separately. A breach likely to create a high risk requires direct communication to affected people without undue delay. The message must describe the breach in clear language, give the DPO or other contact point, explain likely consequences and measures, and should give practical protection steps. Individual communication is not required where effective measures such as encryption made the data unintelligible, later measures removed the likely high risk, or direct contact would involve disproportionate effort and an equally effective public or similar communication is used.