Journey
Respond to a data breach
Step-by-step breach response when personal data has been compromised. Covers the 72-hour ICO notification deadline, assessing risk, notifying affected individuals, and documenting your response.
You have discovered a data breach
A personal data breach is any security incident that affects the confidentiality, integrity, or availability of personal data. This includes data being stolen, lost, accidentally shared, or accessed without authorisation.
Follow these steps: contain, assess, notify, document.
-
Contain the breach immediately
Before assessing or reporting, stop the breach getting worse:
- Disconnect compromised systems from the network
- Change passwords for affected accounts
- Revoke access tokens or credentials
- Preserve evidence (do not delete logs or emails)
If this is a cyber attack, you may also need to report to Action Fraud or the NCSC.
Report a cyber incident
If this breach involves a cyber attack, ransomware, or criminal activity, report to the relevant authorities.
-
Assess the risk to individuals
You must assess whether the breach poses a risk to the people whose data was affected. Consider:
- What data? Names, financial details, health information, passwords?
- How many people? One person or thousands?
- How sensitive? Special category data (health, race, religion) is higher risk
- What harm could result? Identity theft, financial loss, discrimination, distress?
-
Notify the ICO (if required)
You must report to the ICO if the breach is likely to result in a risk to individuals' rights and freedoms. Most breaches involving personal data will meet this threshold.
Data breach response requirements
Full guidance on assessing breach severity, what to include in your ICO notification, and the information you must provide.
-
Notify affected individuals (if required)
You must notify individuals directly if the breach is likely to result in a high risk to their rights and freedoms. This is a higher threshold than ICO notification.
When notifying individuals, tell them:
- What happened (in plain language)
- What data was affected
- What you are doing about it
- What they should do to protect themselves
- How to contact your Data Protection Officer or privacy team
-
Document everything
You must keep records of all breaches, even those you decide not to report. Your breach log should include:
- Date and time you became aware
- What happened and what data was affected
- Your risk assessment and reasoning
- Actions taken to contain and remediate
- Decision on whether to notify ICO and individuals
- Lessons learned and preventive measures
The ICO may ask to see your breach records during an investigation or audit.
Understand the consequences
Failing to report a breach, or reporting late without good reason, can result in significant penalties. However, reporting a breach does not automatically mean you will be fined.
Data protection compliance overview
Understand your broader GDPR obligations and how to prevent future breaches.
Breach response resources