Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

How to Report a Data Breach to the ICO: The 72-Hour Rule Explained

In short

Not every data breach must be reported to the ICO, but many must be reported within 72 hours. This article explains what counts as a reportable breach, how the 72-hour rule works, what to put in your report, and when you must also tell the people affected. Written in plain English for UK small-business owners who need a clear answer quickly.

First, what actually counts as a breach

The phrase “data breach” makes people picture a hacker in a hoodie, but the legal meaning is broader and more everyday than that. Under UK data protection law, a personal data breach is any security incident that leads to personal data being lost, destroyed, altered, or disclosed or accessed without permission.

That covers a lot of ordinary mishaps:

  • A laptop, phone or USB stick lost or stolen.
  • An email with personal details sent to the wrong recipient.
  • Customer records deleted with no backup to restore them.
  • A filing cabinet left unlocked, or paperwork left on a train.
  • A hacked email account or database.

“Personal data” simply means information about identifiable living people — names, addresses, emails, phone numbers, financial details, health information and so on. If an incident puts that kind of information at risk, you may be dealing with a reportable breach, even if no criminal was involved.

When a breach is reportable

Here is the key point that saves a lot of confusion: you do not have to report every breach to the ICO.

The test is about risk to people. You must report a personal data breach to the Information Commissioner’s Office when it is likely to result in a risk to people’s rights and freedoms. In plainer terms: could this breach cause real harm to the people whose data is involved — financial loss, fraud, identity theft, distress, damage to their reputation, or discrimination?

  • If the answer is yes, or probably, you report it.
  • If a breach is genuinely unlikely to pose such a risk — say, an internal email sent to the wrong colleague who deletes it immediately — you may not need to report it. But you must still record it internally, noting what happened, its effects and what you did.

When you are honestly unsure, the safer course is usually to report. Regulators would far rather hear about a breach that turns out to be minor than discover a serious one you decided to sit on.

The 72-hour rule

If a breach is reportable, you must tell the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it.

Two details trip businesses up.

First, the clock starts when you become aware, not when you finish investigating. “Aware” means you have a reasonable degree of certainty that a security incident has occurred and personal data is affected. You are not expected to have every answer within 72 hours — you are expected to have reported.

Second, 72 hours includes weekends and bank holidays. A breach discovered on a Friday afternoon does not get a pause until Monday. This is one reason it helps to know in advance who in your business is responsible for reporting.

You do not have to report every breach to the ICO. The test is about risk to people: could this breach cause real harm to the people whose data is involved?

If you cannot gather everything in time, the ICO accepts a report in phases. Send an initial report with what you know, flag that more will follow, and update them as your understanding improves. If you do end up reporting after 72 hours, still report — and explain the reason for the delay.

What to include in your report

The ICO provides a reporting process on its website, including an online form and a helpline. Whatever the channel, you will be asked to describe the incident clearly. Have these points ready:

  • What happened — a plain description of the breach and how it occurred.
  • When — when it happened and when you became aware of it.
  • What data is involved — the categories of personal data (for example contact details, financial information, health data) and roughly how many people and records are affected.
  • The likely consequences — what harm could come to the people involved.
  • What you are doing about it — the steps you have taken to deal with the breach and to reduce any harm, and how you will stop it happening again.
  • Your contact — who at your business the ICO can speak to, often your data protection lead.

You will not always have precise numbers early on. Give your best estimate, say it is provisional, and refine it later. Keep your own record of the timeline and decisions too; it helps with follow-up and shows you took the matter seriously.

When you must also tell the individuals

Reporting to the ICO is separate from telling the people affected. There is a higher bar for notifying individuals: you must tell them without undue delay when the breach is likely to result in a high risk to their rights and freedoms.

So a breach might be reportable to the ICO (a risk) without needing individual notification, or it might be serious enough (a high risk) that you must do both. If, for example, financial details or passwords have been exposed, the people involved need to know quickly so they can protect themselves — change passwords, watch their accounts, be alert to fraud.

When you do notify individuals, write in clear, plain language. Tell them what happened, what data is involved, what they should do to protect themselves, and how they can contact you with questions. A calm, honest message does more for trust than silence ever will.

Reduce the odds in the first place

The best breach report is the one you never have to file. Most breaches at small businesses come down to a few avoidable gaps: weak or reused passwords, no multi-factor authentication, poor backups, and staff who were never shown what a scam looks like.

A few practical steps go a long way:

None of this is a substitute for legal advice on a specific incident, and the ICO’s own website is the authoritative source on the reporting process. But getting the basics right dramatically cuts the chance you ever need it.

Get a hand before it happens

Judging whether a breach is reportable, hitting the 72-hour deadline, and knowing what to say is much easier with support already in place. If you would like help tightening your security, preparing a response plan, or you are dealing with a possible breach right now, contact DACROS or explore our cyber-security services. A little preparation turns a frightening 72 hours into a manageable process.

Frequently asked questions

What counts as a personal data breach?

A personal data breach is any security incident that leads to personal data being lost, destroyed, altered, disclosed or accessed without authorisation. That includes obvious things like a hacked database, but also a lost laptop or phone, an email sent to the wrong person, papers left on a train, or files deleted with no backup. It is not only about hackers.

Do I have to report every breach to the ICO?

No. You must report a personal data breach to the ICO only when it is likely to result in a risk to people's rights and freedoms. If a breach is unlikely to pose such a risk, you do not need to report it, but you must still record it internally. When you are genuinely unsure, the safer course is usually to report.

What happens if I miss the 72-hour deadline?

Report as soon as you can and explain the delay when you do. The ICO expects reports within 72 hours of you becoming aware, but a late report is better than none. Failing to report a reportable breach at all is the more serious problem and can lead to enforcement action. Keeping a clear record of when you became aware helps.

How do I report a breach to the ICO?

The ICO provides a reporting process on its website, including a personal data breach report form and a helpline. You submit the details of what happened, what data and how many people are involved, the likely consequences and what you are doing about it. You can send an initial report and follow up with more information as you learn it.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.