Journey

Data breach 72-hour checklist

Emergency checklist when you discover a personal data breach. Covers immediate containment, the 72-hour ICO notification rule, when to notify affected individuals, and who else to contact.

Running a Business Updated 15 September 2026
8 milestones references 2 guides

A data breach includes any incident where personal data is lost, stolen, accessed without authorisation, or sent to the wrong person. If you have discovered a breach, work through these steps immediately.

  1. Contain the breach now

    Stop the breach spreading. Disable compromised accounts. Isolate affected systems. Recover lost devices if possible. Do not wait until you understand everything - contain first, investigate second.

  2. Assess what happened

    Work out: what data was involved, how many people are affected, what harm could result. You do not need complete answers to report - the ICO expects early notification with updates later.

  3. Decide: must you report to the ICO?

    Report if the breach is likely to result in a risk to individuals. When in doubt, report. The ICO prefers over-reporting to under-reporting.

  4. Report to the ICO (if required)

    Use the ICO's online breach reporting tool. You will need: your contact details, nature of the breach, categories and numbers affected, likely consequences, and measures you are taking.

  5. Notify affected individuals (if high risk)

    If the breach poses a high risk to individuals, you must notify them directly. Tell them what happened, what you are doing, and what they can do to protect themselves (e.g., change passwords, monitor bank statements).

  6. Report cyber crime (if applicable)

    If the breach resulted from a cyber attack, also report the crime. This is separate from ICO notification.

    Report a cyber incident

    Who to contact for cyber crimes: Report Fraud (England, Wales, NI), Police Scotland, and the NCSC.

  7. Document everything

    Record the breach in your breach register - even if you did not report to the ICO. Document: what happened, who was affected, your decisions, and actions taken. The ICO can audit your records.

  8. After the crisis: review and improve

    Once contained, conduct a post-incident review. Identify what went wrong and update your security measures.

    Full data breach response guide

    Detailed guidance on the complete breach response process, including when you do and do not need to notify, what to tell affected individuals, and preparing for future incidents.