Journey

Respond to a data breach

Step-by-step breach response when personal data has been compromised. Covers the 72-hour ICO notification deadline, assessing risk, notifying affected individuals, and documenting your response.

Running a Business Updated 15 September 2026
5 milestones references 3 guides

You have discovered a data breach

A personal data breach is any security incident that affects the confidentiality, integrity, or availability of personal data. This includes data being stolen, lost, accidentally shared, or accessed without authorisation.

Follow these steps: contain, assess, notify, document.

  1. Contain the breach immediately

    Before assessing or reporting, stop the breach getting worse:

    • Disconnect compromised systems from the network
    • Change passwords for affected accounts
    • Revoke access tokens or credentials
    • Preserve evidence (do not delete logs or emails)

    If this is a cyber attack, you may also need to report to Action Fraud or the NCSC.

    Report a cyber incident

    If this breach involves a cyber attack, ransomware, or criminal activity, report to the relevant authorities.

  2. Assess the risk to individuals

    You must assess whether the breach poses a risk to the people whose data was affected. Consider:

    • What data? Names, financial details, health information, passwords?
    • How many people? One person or thousands?
    • How sensitive? Special category data (health, race, religion) is higher risk
    • What harm could result? Identity theft, financial loss, discrimination, distress?
  3. Notify the ICO (if required)

    You must report to the ICO if the breach is likely to result in a risk to individuals' rights and freedoms. Most breaches involving personal data will meet this threshold.

    Data breach response requirements

    Full guidance on assessing breach severity, what to include in your ICO notification, and the information you must provide.

  4. Notify affected individuals (if required)

    You must notify individuals directly if the breach is likely to result in a high risk to their rights and freedoms. This is a higher threshold than ICO notification.

    When notifying individuals, tell them:

    • What happened (in plain language)
    • What data was affected
    • What you are doing about it
    • What they should do to protect themselves
    • How to contact your Data Protection Officer or privacy team
  5. Document everything

    You must keep records of all breaches, even those you decide not to report. Your breach log should include:

    • Date and time you became aware
    • What happened and what data was affected
    • Your risk assessment and reasoning
    • Actions taken to contain and remediate
    • Decision on whether to notify ICO and individuals
    • Lessons learned and preventive measures

    The ICO may ask to see your breach records during an investigation or audit.

    Understand the consequences

    Failing to report a breach, or reporting late without good reason, can result in significant penalties. However, reporting a breach does not automatically mean you will be fined.

    Data protection compliance overview

    Understand your broader GDPR obligations and how to prevent future breaches.

    Breach response resources