Under UK GDPR Article 33, you report a personal data breach to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it's unlikely to result in a risk to people's rights and freedoms. If it's likely to result in a high risk, you also tell the people affected without undue delay (Art. 34). Every breach goes in your breach log, whether you report it or not.

When the clock starts
The 72 hours run from when you become aware of the breach, not from when it happened. They're hours, not working days, so a breach found on a Friday afternoon is due on Monday afternoon.
A processor that finds a breach must tell you without undue delay (Art. 33(2)). Check your processor contracts set a short, specific time for this.
Do you need to report it?
Report it unless the breach is unlikely to result in a risk to people's rights and freedoms. Assess the likely consequences for the people affected, such as financial loss, identity fraud or distress. The ICO has a self-assessment tool if you're unsure.
What to send
The report must at least (Art. 33(3)):
- Describe the breach, with the categories and approximate numbers of people and records affected, where possible
- Give the name and contact details of your data protection officer or another contact point
- Describe the likely consequences
- Describe what you've done or plan to do about it, including reducing the harm
If you don't have everything yet, send what you have and follow up in phases (Art. 33(4)). A report made after 72 hours must give the reasons for the delay. Reports go through the ICO's online form, which takes about 30 minutes.
Telling the people affected
When the breach is likely to result in a high risk to them, tell the people affected without undue delay, in clear and plain language, with the same contact point, consequences and measures (Art. 34). You don't need to if the data was protected, for example by encryption, if later measures mean the high risk is no longer likely, or if it would take disproportionate effort, in which case a public notice takes its place. The ICO can require you to tell them.
Keep a record of every breach
Record the facts, effects and remedial action for every breach, including the ones you decide not to report (Art. 33(5)). The record is how you show the ICO your decisions were right.
Other reporting duties
Regulated firms may have more to report. FCA firms should consider whether the incident needs notifying to the FCA under SUP 15.3, and EU financial entities have DORA's incident reporting deadlines.
Get reminded before each deadline
Regmindr sets up your compliance calendar from a template in about two minutes, and emails your team before each deadline is due.
Sources
- UK GDPR Article 33: Notification of a personal data breach
- UK GDPR Article 34: Communication of a personal data breach
- ICO: Report a personal data breach
This page is a summary, not legal or regulatory advice. The rules in the sources above take precedence.