Blog

Data Breaches Under UK GDPR: What Organisations Must Do

Under the UK GDPR, a personal data breach can include accidental or unlawful loss, destruction, alteration, disclosure of, or access to personal data. Organisations need a clear breach response process so they can assess risk, keep records, and notify the ICO or affected individuals where required.

Estimated reading time: 6 minutesTopic: Data SecurityRelated terms: Personal data and UK GDPR
Quick answer

What organisations must do after a data breach

Under the UK GDPR, a personal data breach is a security incident that leads to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Organisations must assess the risk, keep a record of the breach, and notify the ICO where the breach is likely to result in a risk to people’s rights and freedoms.

First step

Contain the incident and identify what personal data is affected

ICO notification

Required within 72 hours if the breach is likely to create risk

Records

All breaches should be documented, even if they are not reported

Section one

What counts as a personal data breach?

A personal data breach is broader than a cyber attack. It can include accidental loss, unauthorised access, disclosure to the wrong person, alteration, destruction, or loss of availability of personal data.

Confidentiality

Someone sees data they should not see

This could include sending an email to the wrong person, sharing a file with the wrong permissions, or exposing customer, staff, supplier, or enquiry records.

Integrity

Personal data is changed or damaged

A breach can happen where personal data is accidentally or unlawfully altered, corrupted, overwritten, or made unreliable.

Availability

Personal data becomes unavailable

Ransomware, system failure, accidental deletion, or lost access to key records can create a breach if personal data is unavailable when needed.

Data breaches connect closely to personal data, accountability, and practical data security duties under the UK GDPR.

Section two

What organisations should do first

When a breach is discovered, the first priority is to act quickly and calmly. The organisation needs enough information to understand what happened, reduce harm, and decide whether notification is required.

Identify the affected data

Work out what personal data is involved, how sensitive it is, how many people are affected, and whether the data can be recovered or protected.

Assess the risk to people

Consider whether the breach could lead to identity theft, financial loss, distress, discrimination, reputational damage, or loss of control over personal data.

Document the decision

Record what happened, what was assessed, what action was taken, and why the organisation did or did not notify the ICO or affected individuals.

Section three

When the ICO and individuals must be notified

Not every personal data breach must be reported to the ICO, and not every breach requires affected individuals to be told. The decision depends on the level of risk.

Notify the ICO

Where the breach is likely to result in risk

If the breach is likely to result in a risk to people’s rights and freedoms, the organisation should notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it.

Tell individuals

Where there is likely to be high risk

If the breach is likely to result in a high risk to affected individuals, they may need to be told directly so they can take steps to protect themselves.

The practical way to think about it

The question is not simply whether something went wrong. The key issue is what harm could realistically happen to people because of the breach, and whether the organisation can evidence its decision.

Section five

Examples of data breaches in practice

Data breaches can happen in everyday business situations, not just during major cyber attacks. The key is whether personal data has been compromised.

Email sent to the wrong person

A spreadsheet, invoice, HR document, customer list, or enquiry record sent to the wrong recipient may be a personal data breach.

Lost laptop or device

A lost device may create a breach risk, especially if it contains personal data and is not properly encrypted or access controlled.

Ransomware or cyber attack

A cyber incident can be a breach if personal data is accessed, encrypted, exfiltrated, altered, destroyed, or made unavailable.

Wrong permissions on a shared folder

If staff, suppliers, or third parties can access personal data they should not see, this may amount to unauthorised disclosure or unauthorised access.

Why this distinction matters

If a breach is missed or poorly handled, the organisation may fail to notify the ICO, fail to protect affected individuals, and struggle to evidence its accountability later.

```html
Next step

Keep building your understanding

Use the glossary for key terms, or download the checklist if you want a practical starting point for reviewing breach response steps, incident reporting routes, security controls, breach records, ICO notification decisions, and internal escalation processes.

```
Future Implementation Support Waitlist