We've had a data breach — do we have to tell the ICO within 72 hours, and do we have to tell customers?
You must report a breach to the ICO without undue delay and, where feasible, within 72 hours of becoming aware — but only if it is likely to result in a risk to people's rights and freedoms. Telling the affected individuals is a separate decision with a higher threshold: high risk. Neither test was changed by the Data (Use and Access) Act 2025.
Last updated 31 July 2026. This page explains the law as it stands on that date. It is general information, not legal advice.
The short answer
Report to the ICO only where the breach is likely to result in a risk to people's rights and freedoms, and do it without undue delay and, where feasible, within 72 hours of becoming aware. Tell the affected individuals only where the risk to them is high. Both tests are unchanged. The deadline that did change is the one for telecoms and internet providers: 24 hours became 72 hours on 20 August 2025.
Is every incident reportable?
No. Article 33(1) UK GDPR requires you to notify the Commissioner "unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons". If a risk is unlikely, you do not report it.
A personal data breach is wider than a hack. The ICO defines it as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. A misdirected email, a laptop stolen from a car, a ransomware lock-out and a file deleted with no backup all count.
The ICO's own worked contrast is useful: theft of a customer database that could be used for identity fraud would need to be notified, but the loss or inappropriate alteration of a staff telephone list would not normally need to be.
Record it even if you don't report it
Article 33(5) requires you to document every personal data breach — the facts, the effects and the remedial action — whether or not it is notifiable. The ICO is explicit that if you decide not to report, you must be able to justify that decision, so write it down at the time.
If you are unsure, the ICO publishes a self-assessment tool and runs a personal data breach advice line on 0303 123 1113.
When do the 72 hours start, and do weekends count?
The clock starts when you become aware of the breach. The ICO's guide for small organisations puts it plainly: the clock starts from when you discovered the breach, not when it actually happened.
The 72 hours are 72 clock hours, not 72 working hours. There is nothing in Article 33 that pauses for weekends, bank holidays or annual leave. A breach discovered at 4pm on a Friday has a deadline of 4pm on the Monday. That is why the ICO expects you to have named someone responsible and an escalation route before anything goes wrong.
If a processor suffers the breach, Article 33(2) requires it to notify you without undue delay. There is no separate 72-hour deadline on the processor — the reporting duty stays with you as controller, and your contract under Article 28 should set out how quickly the processor must tell you.
- Step 1 Start the timer and start a log Note the date and time you found out, who is involved and what you know. The ICO publishes a breach log template.
- Step 2 Contain what you can Recall or delete the email, wipe the stolen device remotely, force password resets, isolate the affected system.
- Step 3 Assess the risk to people Look at severity and likelihood of harm to the individuals — identity theft, financial loss, safeguarding risk, significant distress — not inconvenience to you.
- Step 4 Decide, and record the decision Risk likely: report. Risk unlikely: don't report, but document why.
- Step 5 Report inside 72 hours if it is notifiable Use the ICO's online form. Partial information now beats complete information late.
- Step 6 Tell the individuals if the risk is high Give them clear, specific steps they can take to protect themselves.
What if we don't have all the facts, or we miss the deadline?
You do not need a finished investigation to report. Article 33(4) allows the required information to be given in phases, without undue further delay. The ICO's example is an intrusion where you know files were accessed but not how, how much, or whether data was copied — you report within 72 hours, say what you do not yet know, and follow up.
If you go past 72 hours, the notification must be accompanied by reasons for the delay. Say so honestly rather than quietly filing late.
Failing to notify a notifiable breach is a standard-tier infringement. Article 83(4) UK GDPR puts infringements of Articles 25 to 39 — which include Articles 32, 33 and 34 — in the lower band: up to £8,700,000 or, for an undertaking, 2% of total annual worldwide turnover, whichever is higher. That is the same "standard maximum amount" defined in section 157 of the Data Protection Act 2018, and the figure the ICO itself quotes for failing to notify.
Reporting is not what gets punished
The ICO's guidance for small organisations says: "Not every breach reported to us results in formal action. Our main aim is to provide advice to help the organisations avoid similar incidents in the future." The maximum penalty is a ceiling on the worst cases, not a forecast.
Do we have to tell the affected individuals as well?
Only if the risk is high. This is the most common misunderstanding: people assume that if a breach is reportable to the ICO, customers must be told too. Article 34(1) sets a deliberately higher bar, and the ICO confirms the requirement to inform individuals "is higher than for notifying the ICO".
| Telling the ICO | Telling the people affected | |
|---|---|---|
| Legal basis | UK GDPR Article 33 | UK GDPR Article 34 |
| Trigger | Likely to result in a risk to rights and freedoms | Likely to result in a high risk to rights and freedoms |
| Deadline | Without undue delay and, where feasible, 72 hours after becoming aware | Without undue delay — no fixed hour count |
| Incomplete information | Report anyway; phased reporting allowed (Art 33(4)) | Describe the breach in clear and plain language and give protective advice |
| Any way out? | No — but explain any delay | Yes: the three exceptions in Article 34(3), including strong encryption already applied to the data |
| If you don't | Standard maximum: £8.7m or 2% of global turnover | The ICO can compel you to tell them (Art 34(4)) |
The ICO's examples: a hospital that accidentally discloses patient records must tell the patients; a university that deletes alumni contact details and restores them from backup need not. There is nothing stopping you telling people voluntarily where the risk is not high — but weigh that against causing unnecessary alarm.
Is the deadline different for telecoms and internet service providers?
It used to be 24 hours. It is now 72 hours. Section 111 of the Data (Use and Access) Act 2025 amended regulation 5A of PECR with effect from 20 August 2025 (SI 2025/904, reg. 2(p)). Any guidance or policy still citing 24 hours is out of date.
| Until 19 August 2025 | From 20 August 2025 | |
|---|---|---|
| Deadline to notify the ICO | 24 hours after becoming aware | Without undue delay and, where feasible, not later than 72 hours |
| Late notification | No express requirement to explain | Must be accompanied by reasons for the delay (reg. 5A(3A)) |
| Penalty for not notifying | Fixed £1,000, discharged for £800 | Unchanged at £1,000, discharged for £800 (the 21-day discharge window was re-worded) |
Three things about regulation 5A catch people out. First, it applies to providers of a public electronic communications service — telecoms operators, ISPs and similar — not to every business that sends email. Second, there is no risk threshold: every personal data breach connected with the service is notifiable, not just risky ones. Third, the ICO states that PECR reporting "takes the place of UK GDPR breach reporting obligations" for those providers, using the PECR form rather than the UK GDPR process. You must also keep an inventory of breaches, which the ICO asks to be submitted monthly.
Regulation 5A sits outside the main penalty notice regime: as PECR Schedule 1 applies section 155 of the Data Protection Act 2018, the Commissioner "may not give a penalty notice to a person in respect of a failure to comply with regulation 5A". Regulation 5C instead sets a fixed monetary penalty of £1,000 for failing to notify, which a provider may discharge by paying £800 within the period of 21 days beginning when the notice of intent is received. Subscribers or users must be told where the breach is likely to adversely affect their personal data or privacy, unless the data was encrypted or otherwise made unintelligible.
Can a breach now also trigger the new complaints duty?
Yes. Section 164A of the Data Protection Act 2018, inserted by DUAA section 103, came into force on 19 June 2026 (SI 2026/82, reg. 3(a)). It requires controllers to facilitate complaints (including by providing a complaint form that can be completed electronically and by other means), acknowledge a complaint within 30 days beginning when it is received, take appropriate steps to respond, and inform the complainant of the outcome without undue delay.
The ICO's guidance lists complaints about "the security measures you've used to store their information" as data protection complaints — adding, pointedly, "eg someone who has been impacted by a data breach, regardless of whether it's reportable to us". So a breach you correctly decided not to report can still produce a complaint you are legally obliged to handle.
Infringing section 164A attracts the standard maximum under new section 157(4A) DPA 2018 — £8.7m or 2%. The duties to acknowledge and to respond apply only to complaints received on or after 19 June 2026 (SI 2026/82, reg. 7). Expect complaint volumes and subject access requests to spike after an incident; the ICO says you should have a contingency plan for that.
Will we be fined, and what does the ICO actually punish?
Recent penalties have landed on security failings, under Articles 5(1)(f) and 32, not on the reporting itself.
On 7 May 2026 the ICO fined South Staffordshire Plc and South Staffordshire Water Plc £963,900 for infringing Articles 5(1)(f) and 32(1) after a cyber attack in which data on approximately 633,887 UK data subjects was exfiltrated and published on the dark web. Malware installed via a phishing attachment went undetected for 20 months. The ICO identified four failings:
- Limited access controls, letting the attacker escalate to administrator privileges after an initial foothold
- Inadequate monitoring and logging — only 5% of the IT environment was being monitored
- Obsolete, unsupported software still in use, including Windows Server 2003
- Inadequate vulnerability management, with unpatched critical systems and no regular internal or external scanning
That list is the closest thing the ICO has published to a checklist of what it expects. Two earlier cases point the same way: Capita was fined £14m on 15 October 2025 (£8m Capita plc, £6m Capita Pension Solutions) over the March 2023 attack affecting about 6.6 million people, where a high-priority alert was raised in 10 minutes but the device was not quarantined for 58 hours; and LastPass UK Ltd was fined £1,228,283 on 20 November 2025 under Articles 5(1)(f) and 32(1)(f) after data on around 1.6 million UK customers was exfiltrated.
"They only got pseudonymised data" is not a defence
In DSG Retail Ltd v Information Commissioner [2026] EWCA Civ 140 (19 February 2026), the Court of Appeal held that the security duty applies to all data that is personal data in the controller's hands — whether or not the attacker who took it could identify anyone. The case concerned the Data Protection Act 1998, but the reasoning applies directly to the equivalent UK GDPR duty.
One thing to watch: the ICO's small-organisations guidance *72 hours: how to respond to a personal data breach* now carries a notice that, because of changes made by the DUAA, it is under review and may change; the ICO's *Our plans for new and updated guidance* page is where updates are tracked. The Article 33 and Article 34 tests themselves were not amended by the Act.
Common questions
We emailed one customer's details to the wrong person. Do we have to report it?
Not automatically. You report only if the breach is likely to result in a risk to that person's rights and freedoms. The ICO's own example is a hair appointment reminder sent to the wrong customer who deleted it — unlikely to need reporting to the ICO or the customer. A misdirected email containing medical details, bank details or a home address for someone at risk is a very different assessment. Whichever way you decide, record the decision and your reasons.
Does the 72 hours include weekends and bank holidays?
Yes. Article 33 counts clock hours from when you became aware, with no pause for non-working days. If you discover a breach at 4pm on Friday, the deadline is 4pm on Monday. If you cannot meet it, report late and give the reasons for the delay.
We reported after 72 hours. Are we going to be fined?
Late reporting is a standard-tier infringement under Article 83(4) UK GDPR, carrying a maximum of £8.7m or 2% of global turnover, whichever is higher — but the ICO says not every reported breach results in formal action and that its main aim is advice to help organisations avoid similar incidents. Report as soon as you can and explain the delay. The penalties the ICO has actually issued recently have been for poor security, not for reporting.
Do we have to tell our customers about a data breach?
Only where the breach is likely to result in a high risk to their rights and freedoms (Article 34). That is a higher bar than the ICO reporting threshold, so plenty of breaches are reportable to the ICO but do not have to be communicated to individuals. Article 34(3) also sets out three exceptions, including where the affected data was already protected by measures such as strong encryption. The ICO can order you to tell people if it disagrees with your assessment.
We're an ISP. Is our deadline still 24 hours?
No. Since 20 August 2025, PECR regulation 5A(2) has required notification without undue delay and, where feasible, not later than 72 hours after becoming aware. A notification made after 72 hours must be accompanied by reasons for the delay. Unlike the UK GDPR, there is no risk threshold — every personal data breach connected with the service is notifiable — and the ICO says PECR reporting takes the place of the UK GDPR reporting process for those providers.
What is the fine for a telecoms provider that fails to report?
PECR regulation 5C sets a fixed monetary penalty of £1,000, which can be discharged by paying £800 within the period of 21 days beginning when the notice of intent is received. It is the only sanction available for that failure: the Commissioner cannot issue an ordinary penalty notice for a breach of regulation 5A. It is therefore far smaller than the general PECR penalty regime, which since 5 February 2026 uses the Data Protection Act 2018 maximums — up to £17.5m or 4% of global turnover for failings such as inadequate security under regulation 5.
Sources
This page summarises the following primary sources. Where they disagree with this summary, they take precedence.
- UK GDPR Article 33 — Notification of a personal data breach to the supervisory authority (legislation.gov.uk)
- UK GDPR Article 34 — Communication of a personal data breach to the data subject (legislation.gov.uk)
- UK GDPR Article 83 — general conditions for imposing administrative fines, including the £8.7m / 2% band for Articles 25 to 39 (legislation.gov.uk)
- PECR regulation 5A — personal data breach notification, as amended 20 August 2025 (legislation.gov.uk)
- PECR regulation 5C — fixed monetary penalty of £1,000, discharged at £800 (legislation.gov.uk)
- Data Protection Act 2018 section 157 — standard and higher maximum penalty amounts, including new subsection (4A) (legislation.gov.uk)
- Data Protection Act 2018 section 164A — complaints by data subjects to controllers, in force 19 June 2026 (legislation.gov.uk)
- Data (Use and Access) Act 2025 section 111 — duty to notify the Commissioner of personal data breach: time periods (legislation.gov.uk)
- ICO — Personal data breaches: a guide
- ICO — 72 hours: how to respond to a personal data breach (advice for small organisations)
- ICO — What are data protection complaints? (guidance published 12 February 2026)
- ICO — Fine of nearly £1m issued against South Staffordshire Plc and South Staffordshire Water Plc (11 May 2026)
Related guidance
-
My data was leaked — can I actually claim compensation, and how much?
Being in a data breach does not automatically mean compensation. What Article 82 requires, what Farley v Paymaster decided, and what payouts really look like.
-
New rule from 19 June 2026: every UK organisation must have a data protection complaints process
From 19 June 2026 every UK controller must accept data protection complaints, acknowledge them within 30 days and give an outcome. No size exemption.