4.8Top Rated Service 2026verified by TrustindexTrustindex verifies that the company has a review score above 4.5, based on reviews collected on Google over the past 12 months, qualifying it to receive the Top Rated Certificate.
Under the UK GDPR, a personal data breach can include accidental or unlawful loss, destruction, alteration, disclosure of, or access to personal data. Organisations need a clear breach response process so they can assess risk, keep records, and notify the ICO or affected individuals where required.
Under the UK GDPR, a personal data breach is a security incident that leads to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Organisations must assess the risk, keep a record of the breach, and notify the ICO where the breach is likely to result in a risk to people’s rights and freedoms.
First step
Contain the incident and identify what personal data is affected
ICO notification
Required within 72 hours if the breach is likely to create risk
Records
All breaches should be documented, even if they are not reported
A personal data breach is broader than a cyber attack. It can include accidental loss, unauthorised access, disclosure to the wrong person, alteration, destruction, or loss of availability of personal data.
This could include sending an email to the wrong person, sharing a file with the wrong permissions, or exposing customer, staff, supplier, or enquiry records.
A breach can happen where personal data is accidentally or unlawfully altered, corrupted, overwritten, or made unreliable.
Ransomware, system failure, accidental deletion, or lost access to key records can create a breach if personal data is unavailable when needed.
Data breaches connect closely to personal data, accountability, and practical data security duties under the UK GDPR.
When a breach is discovered, the first priority is to act quickly and calmly. The organisation needs enough information to understand what happened, reduce harm, and decide whether notification is required.
Stop further exposure where possible. This may involve disabling access, recalling emails, changing permissions, isolating systems, or contacting a supplier.
Work out what personal data is involved, how sensitive it is, how many people are affected, and whether the data can be recovered or protected.
Consider whether the breach could lead to identity theft, financial loss, distress, discrimination, reputational damage, or loss of control over personal data.
Record what happened, what was assessed, what action was taken, and why the organisation did or did not notify the ICO or affected individuals.
Not every personal data breach must be reported to the ICO, and not every breach requires affected individuals to be told. The decision depends on the level of risk.
If the breach is likely to result in a risk to people’s rights and freedoms, the organisation should notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it.
If the breach is likely to result in a high risk to affected individuals, they may need to be told directly so they can take steps to protect themselves.
The question is not simply whether something went wrong. The key issue is what harm could realistically happen to people because of the breach, and whether the organisation can evidence its decision.
Breach mistakes usually happen when organisations delay, panic, fail to document decisions, or treat every security incident the same way without assessing the actual risk to individuals.
The 72-hour period can become difficult very quickly if no one knows who should investigate, who should decide, or what information needs to be gathered.
Even if the ICO does not need to be notified, the organisation should still record the breach, the risk assessment, and the reasoning behind the decision.
A breach process should be prepared before an incident happens. Organisations need a clear internal route for reporting incidents, assessing risk, escalating decisions, and keeping evidence.
Data breaches can happen in everyday business situations, not just during major cyber attacks. The key is whether personal data has been compromised.
A spreadsheet, invoice, HR document, customer list, or enquiry record sent to the wrong recipient may be a personal data breach.
A lost device may create a breach risk, especially if it contains personal data and is not properly encrypted or access controlled.
A cyber incident can be a breach if personal data is accessed, encrypted, exfiltrated, altered, destroyed, or made unavailable.
If staff, suppliers, or third parties can access personal data they should not see, this may amount to unauthorised disclosure or unauthorised access.
If a breach is missed or poorly handled, the organisation may fail to notify the ICO, fail to protect affected individuals, and struggle to evidence its accountability later.
This article is based on ICO guidance on personal data breaches, security, breach reporting, and accountability under the UK GDPR. It also connects to wider duties around accountability, personal data, data retention, and practical governance processes such as complaint handling and incident records.
Use the glossary for key terms, or download the checklist if you want a practical starting point for reviewing breach response steps, incident reporting routes, security controls, breach records, ICO notification decisions, and internal escalation processes.
We use cookies and similar technologies to make our website work and to provide optional features such as live chat.
Some cookies are strictly necessary for the website to function. Optional cookies support tools such as live chat and will only be used if you choose to allow them.
We also use privacy-friendly, cookieless website analytics to understand aggregated website usage. This does not use cookies or track you across websites.
You can choose to accept all cookies, reject non-essential cookies, or manage your preferences.