A personal data breach is any security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Under UK GDPR, organisations must assess every breach, document it, and in many cases notify the ICO within 72 hours. This guide sets out a straightforward, compliance-focused approach to breach response.
What counts as a personal data breach?
Under Article 4(12) of UK GDPR, a personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. This includes:
- Sending an email to the wrong person
- Losing an unencrypted USB stick or device
- Exposure of records due to a cyber incident
- Accidental deletion of key customer data with no backup
- Systems accessed unlawfully through phishing
It does not need to involve hacking or criminal intent. A simple human error can qualify, if it compromises the confidentiality, integrity, or availability of personal data.
Who should be responsible for a breach response?
Every organisation that processes personal data, whether as a controller or a processor, needs a clear response structure. Typical roles include:
- Incident lead – often the DPO or equivalent, overseeing the response
- IT lead – handling technical diagnosis and containment
- Communications lead – coordinating contact with affected individuals, regulators, and stakeholders
- Data owner(s) – those responsible for the records affected
- Record-keeper – maintaining logs to meet documentation obligations
Smaller organisations may combine these roles into one or two people. What matters is that responsibility is clearly assigned before an incident happens, not worked out on the day.
How should a breach be detected and triaged?
Quick identification is critical. Many breaches are detected internally, by staff noticing something odd or systems behaving unusually. Others are reported by third parties, including affected individuals themselves.
Organisations should have a single, clearly communicated reporting route, a triage process to assess how serious the incident is, and criteria for escalation covering legal, operational, and reputational risk. Initial containment might involve revoking access, contacting IT support, or recovering files from backups; more complex cases may need forensic analysis or third-party input.
When do you have to notify the ICO and affected individuals?
You must notify the Information Commissioner’s Office within 72 hours of becoming aware of a notifiable breach, unless it is unlikely to result in a risk to individuals’ rights and freedoms. You must also inform affected individuals directly where the risk is high, particularly where the breach could lead to identity theft, financial loss, or distress.
Notification to the ICO must include a description of the breach, its likely consequences, the steps taken or proposed to address it, and contact details for further information. If you decide not to notify the ICO or affected individuals, you must document that decision and your reasoning – this may be reviewed later, particularly if a complaint follows.
What documentation does the ICO expect?
Article 33(5) of UK GDPR requires organisations to document every personal data breach, regardless of whether it is reportable. The ICO expects to see a description of what happened, when and how it was discovered, the actions taken at each stage, the decision-making rationale (especially around notification), and any steps taken to prevent recurrence.
This is part of the accountability principle: you must be able to demonstrate compliance, not just assert it. For smaller organisations, a simple breach log with date, summary, outcome, and lessons learned is often sufficient. Larger organisations may need more formal reporting and audit trails.
What happens after the breach is contained?
Once a breach has been contained and reported (if required), the focus turns to learning. Even minor incidents are worth reviewing: was the breach preventable, were existing policies followed and are they fit for purpose, was staff training sufficient, and does anything need to change in your technical or organisational measures?
A well-handled breach – contained quickly, assessed properly, and documented thoroughly – is one of the clearest indicators of a mature data protection function. If you would like support reviewing your breach response arrangements, or building a breach response process from scratch, see our Data Protection advisory services.