Compliance7 min read22 September 2026

GDPR Data Breach Notification UK: What You Must Do and When

If your UK business experiences a data breach, you have 72 hours to notify the ICO. Here is exactly what counts as a breach, what you must report, and what happens if you miss the deadline.

By Yrzo AI — UK cybersecurity specialists

GDPR data breach notification UK: what you must do and when

A data breach is not just a cyber attack. Under UK GDPR, a personal data breach is any security incident — accidental or deliberate — that leads to the destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This includes a hacked website, but also a misdirected email, a lost laptop, or an employee accessing records they should not have.

If your business experiences a breach, you have obligations. The most time-critical is notification to the ICO.

The 72-hour rule

Article 33 of UK GDPR requires that data controllers notify the ICO of a personal data breach without undue delay and, where feasible, no later than 72 hours after becoming aware of it.

The 72-hour clock starts when you become aware — not when the breach occurred. If a breach happened three weeks ago but you discovered it today, you have 72 hours from today.

The 72 hours includes weekends. It does not stop on Saturday.

Not every breach requires notification

The notification requirement is triggered when the breach is likely to result in a risk to the rights and freedoms of natural persons. A low-risk breach — where the data involved is minimal and the likelihood of harm is negligible — does not need to be reported to the ICO, though it must be documented internally.

Examples of breaches that typically must be reported: a hacked website exposing customer email addresses and passwords; a ransomware attack encrypting patient records; an employee emailing customer financial data to the wrong recipient.

Examples that typically do not require ICO notification: a single misdirected email containing non-sensitive information to one recipient who confirms they have deleted it; a brief outage with no data accessed or lost.

What you must include in the notification

The ICO notification must include: the nature of the breach, the categories and approximate number of individuals concerned, the categories and approximate number of data records concerned, the name and contact details of your Data Protection Officer or other contact point, the likely consequences of the breach, and the measures taken or proposed to address it.

If you do not have all this information within 72 hours — which is often the case in complex incidents — you can notify with the information available and provide further details later. A phased notification is acceptable; missing the deadline entirely is not.

Notifying affected individuals

If a breach is likely to result in a high risk to individuals — not just a risk, but a high risk — you must also notify the affected individuals directly, without undue delay. High risk means the breach could lead to significant harm: financial loss, discrimination, identity theft, physical harm, or significant social disadvantage.

Documenting breaches you decide not to report

All breaches must be documented internally, regardless of whether they are reported to the ICO. This includes breaches that do not meet the notification threshold. The documentation must be sufficient to allow the ICO to verify your compliance if they investigate.

The cost of getting it wrong

The ICO has fined organisations for failing to report breaches within the 72-hour window. Fines for breach notification failures have ranged from tens of thousands to hundreds of thousands of pounds. The ICO also considers breach notification compliance when calculating fines for the underlying security failure.

Prevention through regular security testing

Most notifiable breaches result from preventable vulnerabilities — unpatched software, weak passwords, SQL injection vulnerabilities. Yrzo AI runs 44 automated security checks against your live website, identifying vulnerabilities before they can be exploited. Starting at £399. A scan before a breach is worth considerably more than a fine after one.

Find out if your website has these vulnerabilities

Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.

Scan your website →