Regmindr
Guides

Data breach reporting: the 72-hour deadline

Updated

Under UK GDPR Article 33, you report a personal data breach to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it's unlikely to result in a risk to people's rights and freedoms. If it's likely to result in a high risk, you also tell the people affected without undue delay (Art. 34). Every breach goes in your breach log, whether you report it or not.

Timeline of the UK GDPR breach reporting deadline: hour 0, you become aware, and the 72 hours run from here (Art. 33(1)); straight away, assess the risk; within 72 hours, report to the ICO unless it's unlikely to result in a risk, with details able to follow in phases (Art. 33(1) and (4)); without undue delay, tell the people affected when the breach is likely to result in a high risk (Art. 34(1)). Record every breach (Art. 33(5)).
The 72 hours run from when you become aware of the breach, and include weekends.

When the clock starts

The 72 hours run from when you become aware of the breach, not from when it happened. They're hours, not working days, so a breach found on a Friday afternoon is due on Monday afternoon.

A processor that finds a breach must tell you without undue delay (Art. 33(2)). Check your processor contracts set a short, specific time for this.

Do you need to report it?

Report it unless the breach is unlikely to result in a risk to people's rights and freedoms. Assess the likely consequences for the people affected, such as financial loss, identity fraud or distress. The ICO has a self-assessment tool if you're unsure.

What to send

The report must at least (Art. 33(3)):

  • Describe the breach, with the categories and approximate numbers of people and records affected, where possible
  • Give the name and contact details of your data protection officer or another contact point
  • Describe the likely consequences
  • Describe what you've done or plan to do about it, including reducing the harm

If you don't have everything yet, send what you have and follow up in phases (Art. 33(4)). A report made after 72 hours must give the reasons for the delay. Reports go through the ICO's online form, which takes about 30 minutes.

Telling the people affected

When the breach is likely to result in a high risk to them, tell the people affected without undue delay, in clear and plain language, with the same contact point, consequences and measures (Art. 34). You don't need to if the data was protected, for example by encryption, if later measures mean the high risk is no longer likely, or if it would take disproportionate effort, in which case a public notice takes its place. The ICO can require you to tell them.

Keep a record of every breach

Record the facts, effects and remedial action for every breach, including the ones you decide not to report (Art. 33(5)). The record is how you show the ICO your decisions were right.

Other reporting duties

Regulated firms may have more to report. FCA firms should consider whether the incident needs notifying to the FCA under SUP 15.3, and EU financial entities have DORA's incident reporting deadlines.

Get reminded before each deadline

Regmindr sets up your compliance calendar from a template in about two minutes, and emails your team before each deadline is due.

Sources

This page is a summary, not legal or regulatory advice. The rules in the sources above take precedence.

Related