When must a controller report a breach to the ICO?
A is a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. It covers confidentiality, integrity, and availability failures, not only theft or disclosure.
The must notify the ICO unless the breach is unlikely to result in a risk to people's rights and freedoms. If notification is required, it must be made without undue delay and, where feasible, within 72 hours after the controller becomes aware. A must notify its controller without undue delay after becoming aware; Article 33 does not give processors their own 72-hour ICO deadline, although the contract may set a shorter escalation period.
- Record the 's time and the facts that made the breach reasonably certain.
- Assess the type of harm, affected people, sensitivity and volume of data, ease of identification, likely consequences, and measures already protecting the data.
- Notify the ICO when risk is possible; record a reasoned decision when the breach is unlikely to result in risk.
- Do not confuse the lower ICO-notification risk threshold with the high-risk threshold for telling affected people.
Binding source for the controller's risk threshold and 72-hour duty, the processor's notice duty, phased reporting, required report content, and breach records.
Explains breach recognition, awareness, risk assessment, controller and processor roles, ICO reporting, individual communication, and documentation.