Do I need to report a data breach to the ICO?
The short answer: If personal data is involved and the breach could put people at risk, yes: you must report it to the ICO within 72 hours of finding out, weekends included. If the risk to people is high, you must tell them too. Whether you report or not, you must keep a record of the breach and your decision.
A data breach is more than a hack. Under UK GDPR (the UK's data protection law), a personal data breach is any security problem that leads to personal data being lost, destroyed, changed, shared with the wrong person or accessed without permission. An email sent to the wrong customer counts. So does a stolen laptop, or a hacked website that held customer details.
Not every breach has to be reported. Here is how to tell.
Who the ICO is
The ICO is the UK's data protection regulator. Since 30 September 2026 it is formally the Information Commission (it used to be the Information Commissioner), but it still goes by the ICO, now short for the Information Commission's Office. The reporting rules below haven't changed.
Do you have to report it?
Ask one question: is the breach likely to put people at risk? Risk means things like identity theft, fraud, financial loss, damage to reputation, distress, or loss of confidentiality.
- Likely to put people at risk: report it to the ICO.
- Unlikely to put anyone at risk: you don't have to report it, but you must still record it and why you decided not to.
- High risk to people: report it to the ICO and tell the people affected, without delay, so they can protect themselves.
The ICO's own example of a breach that doesn't need reporting: an appointment reminder sent to the wrong customer, who tells you and deletes it.
If you are genuinely unsure, the ICO has an online self-assessment that walks you through it.
The 72-hour deadline
You must report within 72 hours of becoming aware of the breach. Not 72 working hours: weekends and bank holidays count.
The clock starts when you find out, not when it happened. You don't need every answer before you report. You can tell the ICO what you know so far and add more as you find it. Reporting late without a good reason can count against you.
How to report
- Online: the ICO's breach report form, any time.
- By phone: the ICO helpline on 0303 123 1113, usually Monday to Friday, 9am to 5pm.
Have this ready, as far as you know it:
- What happened, and when you found out.
- What kind of personal data was involved, and roughly how many people.
- What the likely effect on those people is.
- What you have done so far, and what you are going to do.
- Who to contact at your business.
If you can't yet tell whether the breach meets the threshold, the form lets you say so, and the ICO says it will get back to you.
Keep a record of every breach
Whatever you decide, write it down: what happened, what data was involved, the effects, what you did about it, and why you did or didn't report it. The ICO can ask to see this. A simple log is fine.
Fines, in proportion
The headline maximum fines are large: up to £17.5 million or 4% of worldwide turnover for the most serious failings. For most small businesses that is not the realistic picture. When the ICO decides what to do, its policy says it looks at things like how much you co-operated to put things right and limit the harm. It also says that breaches which should have been reported but weren't can expect more serious attention. Reporting promptly and honestly works in your favour.
Also new in 2026: complaints
Since 19 June 2026, every organisation must have a way for people to complain about how their personal data is handled, and must respond to those complaints properly. If a breach leads to complaints from customers, this is the process they will use.
When to call someone
Call for help if:
- You aren't sure what data was involved or how many people are affected.
- You don't know how the breach happened, or whether it is still going on.
- The 72-hour clock is ticking and you need a clear account to give the ICO.
I can work out what happened, contain it, and help you write an accurate report and a calm message to the people affected. For legal questions, I'll recommend you speak to a solicitor.
Sources
- ICO: personal data breaches, a guide
- ICO: 72 hours, how to respond to a personal data breach
- ICO: report a breach online
- ICO: breach self-assessment
- ICO: maximum fines under UK GDPR
- ICO: regulatory action policy
- ICO: one year of the Data (Use and Access) Act
- The Information Commission regulations, SI 2026/1015
Not sure whether to report?
Help when you've been hacked: contain it, find out what happened, clean up and write it up.