UK GDPR 72-Hour Breach Notification: What UK Businesses Must Know
UK GDPR 72-Hour Breach Notification: What UK Businesses Must Know
What Counts as a Personal Data Breach?
Any security incident resulting in accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or unauthorised access to personal data — including:
✅ Ransomware encrypting your systems ✅ Employee emailing a customer list to the wrong address ✅ Stolen laptop containing client files ✅ Compromised Microsoft 365 account with attacker reading emails ✅ Drive folder accidentally set to 'Anyone with the link'
The 72-Hour Rule (Article 33 UK GDPR)
When a breach is likely to result in risk to individuals, you must notify the ICO within 72 hours of becoming aware — not when the breach occurred.
'Become aware': The clock starts when you know (or should reasonably know) a breach occurred.
Low vs. high risk: Not every breach requires ICO notification. Breaches involving financial data, health data, large volumes, or vulnerable individuals are typically high risk.
When Must You Also Notify Individuals? (Article 34)
If the breach is likely to result in high risk to individuals — a higher bar — you must also contact those affected directly.
What to Include in ICO Notification
- Nature of the breach
- Categories and approximate number of individuals affected
- Categories and approximate records concerned
- DPO contact details (if applicable)
- Likely consequences of the breach
- Measures taken to address and mitigate
Consequences of Not Notifying
- Marriott International: £18.4M fine
- British Airways: £20M fine
- UK SMEs: £5,000–£150,000 enforcement notices
How to Prepare
- Know what data you hold (maintain a ROPA)
- Have a documented incident response plan
- Detect breaches quickly — 72 hours starts when you become aware
- Keep security logs (Microsoft 365 and Google Workspace audit logs)
- Practice with annual tabletop exercises
How Gridisys Supports ICO Notification
Gridisys detects suspicious activity in near real-time, generates structured incident records, and provides the evidence trail your DPO needs for ICO notification.