Incident response
Do you have to report a data breach?
Something has gone wrong — an account was accessed, a laptop is missing, a file went to the wrong person — and underneath the practical panic sits a quieter question. Does this have to be reported, and to whom, and how long have you got?
This is a plain-English explanation of how reporting duties generally work, not legal advice. If personal data is involved and you are unsure, a short conversation with a solicitor early is far cheaper than a late notification.
The clock starts when you become aware, not when you finish investigating
This is the detail that catches people out. Under UK and EU data protection law the reporting window is 72 hours from becoming aware of a personal data breach — and awareness means having a reasonable degree of certainty that a security incident occurred, not having completed your investigation.
So the clock is usually already running while you are still working out what happened. Waiting until you have the full picture is the standard way businesses miss the deadline, and the delay itself is a separate failing from the breach.
Is it actually a personal data breach?
The definition is broader than most people assume. It is not limited to data being stolen — it covers any breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
Three consequences of that wording surprise people:
- Losing access counts. Ransomware that encrypts customer records is a breach even if nothing was taken, because the data was destroyed or made unavailable.
- Accidents count. Emailing a spreadsheet to the wrong person is a breach. So is a mis-addressed letter.
- Internal misuse counts. A staff member looking at records they had no business reason to see is a breach.
What is not personal data
If the incident genuinely involves no information about identifiable living people — product designs, your own financial models, anonymous statistics — data protection reporting does not apply. Other duties still might, particularly to your insurer, your bank or a customer whose contract requires notification.
Two different questions, two different answers
Reporting to a regulator and telling the affected people are separate decisions with different thresholds, and conflating them is common.
| Tell the regulator | Tell the individuals | |
|---|---|---|
| Threshold | Unless the breach is unlikely to be a risk to people | Only when there is a high risk to them |
| Deadline | 72 hours from awareness | Without undue delay |
| Default | Report unless you can justify not reporting | Do not notify unless the risk is high |
Note the asymmetry. Regulator notification is the default and not reporting is the exception you have to justify. Individual notification is the reverse — it is reserved for cases where people need to act to protect themselves.
What makes the risk high
Financial data that enables fraud. Passwords, especially reused ones. Health information. Anything revealing an identity or circumstance a person would want kept private — immigration status, sexuality, religion, a refuge address. Data about children. Volume matters too: one record can be high risk if it is sensitive enough.
If people need to change a password, watch their bank, or be alert to being targeted, they need to hear it from you rather than discovering it later.
Record it even when you do not report it
If you decide an incident is not reportable, you still have to document it — what happened, what the effects were, what you did, and the reasoning behind the decision not to report.
That internal record is what demonstrates you assessed the situation properly rather than ignored it. A regulator that later hears about the incident from someone else will ask for it, and "we decided it was minor" without a contemporaneous note is a much weaker position.
What to have ready before it happens
The 72 hours are not really enough time to work out who does what. Decide it in advance and write it on one page.
- Who decides whether to report, and who covers for them on holiday
- Where the log lives, and who can add to it
- What you would need to say — categories of data, approximate numbers, likely consequences, what you are doing about it
- Who you would call — solicitor, insurer, IT support — with numbers that work out of hours
- A draft notification, written calmly now rather than at speed under pressure
The most common mistake
It is not failing to report. It is deciding informally, in the first confused hour, that the incident is smaller than it is — and then having no record of how that decision was reached.
Investigate as though it is reportable. Document as you go. Decide with the facts in front of you. If it turns out to be minor, you have lost an hour and gained a written record. If it turns out not to be, you are inside the window with your evidence already assembled.