Back to Blog
Cybersecurity 8 min read2026-07-05

UK GDPR 72-Hour Breach Notification: What UK Businesses Must Know

UK GDPR breach notification 72 hours ICO breach notification UK data breach reporting UK UK GDPR incident response

UK GDPR 72-Hour Breach Notification: What UK Businesses Must Know

What Counts as a Personal Data Breach?

Any security incident resulting in accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or unauthorised access to personal data — including:

✅ Ransomware encrypting your systems ✅ Employee emailing a customer list to the wrong address ✅ Stolen laptop containing client files ✅ Compromised Microsoft 365 account with attacker reading emails ✅ Drive folder accidentally set to 'Anyone with the link'

The 72-Hour Rule (Article 33 UK GDPR)

When a breach is likely to result in risk to individuals, you must notify the ICO within 72 hours of becoming aware — not when the breach occurred.

'Become aware': The clock starts when you know (or should reasonably know) a breach occurred.

Low vs. high risk: Not every breach requires ICO notification. Breaches involving financial data, health data, large volumes, or vulnerable individuals are typically high risk.

When Must You Also Notify Individuals? (Article 34)

If the breach is likely to result in high risk to individuals — a higher bar — you must also contact those affected directly.

What to Include in ICO Notification

  1. Nature of the breach
  2. Categories and approximate number of individuals affected
  3. Categories and approximate records concerned
  4. DPO contact details (if applicable)
  5. Likely consequences of the breach
  6. Measures taken to address and mitigate

Consequences of Not Notifying

  • Marriott International: £18.4M fine
  • British Airways: £20M fine
  • UK SMEs: £5,000–£150,000 enforcement notices

How to Prepare

  1. Know what data you hold (maintain a ROPA)
  2. Have a documented incident response plan
  3. Detect breaches quickly — 72 hours starts when you become aware
  4. Keep security logs (Microsoft 365 and Google Workspace audit logs)
  5. Practice with annual tabletop exercises

How Gridisys Supports ICO Notification

Gridisys detects suspicious activity in near real-time, generates structured incident records, and provides the evidence trail your DPO needs for ICO notification.

See GDPR compliance support →

Gridisys

AI-powered cybersecurity and app development. Protecting and building for businesses worldwide.

© 2026 Gridisys. All rights reserved.Gridisys Ltd — Company No. 15780405 — Registered in England & WalesRegistered Office: 128 City Road, London, United Kingdom, EC1V 2NX

We use cookies to improve your experience and analyse site traffic. By clicking "Accept", you consent to our use of cookies. Learn more.