Back to Blog
Cybersecurity 12 min read2026-07-24

UK GDPR Breach Notification: The 72-Hour Response Playbook

UK GDPR breach notification ICO breach reporting 72 hours GDPR incident response UK personal data breach UK SME ICO cybersecurity

UK GDPR Breach Notification: The 72-Hour Response Playbook

According to the 2024 UK Cyber Security Breaches Survey, 50% of UK businesses have experienced a cyber attack in the past 12 months, with the average cost of a breach for SMEs exceeding £1,000 per incident in immediate recovery costs alone. When a breach involves personal data, the regulatory clock starts ticking immediately, leaving organisations with a strictly enforced 72-hour window to satisfy the Information Commissioner's Office (ICO).

The Criticality of the 72-Hour ICO Clock

In our managed SOC UK at Gridisys, we often see SMEs confuse "discovery" with "notification." Under Article 33 of the UK GDPR, you must report a personal data breach to the ICO within 72 hours of becoming aware of it. In a professional SOC environment, "awareness" is not when a board member finds out; it is when your monitoring tools or security team first identify a confirmed breach event.

Failing to meet this deadline is not just a breach of data protection law; it is a signal to the ICO that your internal incident response capabilities are immature. When we provide UK GDPR compliance support, we teach clients that the 72-hour window is not for conducting a full forensic investigation—it is for initial assessment and containment.

Phase 1: Immediate Triage and Containment (Hours 0-12)

Upon detection, your immediate priority is stopping the bleed. If the breach involves credential theft, we immediately trigger Microsoft Entra security monitoring to revoke active sessions and enforce conditional access policies.

  1. Isolate Affected Systems: Disconnect compromised servers or cloud instances from the network.
  2. Log Preservation: Halt any automated cleanup scripts. We need the raw logs to determine what was exfiltrated.
  3. Assess the Nature of the Data: Is it special category data? Financial data? PII? The classification determines your subsequent regulatory obligations.

Phase 2: Evidence Collection for the ICO

The ICO does not expect a perfect report in 72 hours, but they do expect a factual one. When you submit your report, you must provide:

  • The nature of the breach (e.g., ransomware, phishing, misconfigured cloud storage).
  • The categories and approximate number of data subjects concerned.
  • The categories and approximate number of personal data records concerned.
  • The name and contact details of your DPO.
  • Likely consequences of the breach.
  • Measures taken to mitigate adverse effects.

In our UK cybersecurity services, we generate an "Incident Impact Summary" that automates the collection of this data, ensuring our clients aren't scrambling for evidence during the heat of a crisis.

Phase 3: The Risk-Based Approach to Reporting

Not every security incident is a reportable personal data breach under UK GDPR. If the incident involves data that is fully encrypted and the keys remain secure, or if the data is rendered unintelligible, it may not meet the threshold for ICO notification. However, if there is a risk to the rights and freedoms of individuals, you must notify.

We frequently see organisations over-reporting minor incidents to "play it safe." While this might seem protective, it draws unnecessary attention to your security posture. For FCA-regulated firms, the intersection between ICO breach reporting and operational resilience requirements (FCA PS21/3) means you likely have a secondary notification obligation to the regulator that must be managed concurrently.

Phase 4: Beyond the 72 Hours – Remediation and Recovery

Once the initial notification is filed, the work shifts to long-term containment. If you are using Google Workspace security, this might involve a full audit of OAuth permissions and marketplace apps that could be acting as backdoors.

We also leverage Cyber Essentials support to ensure that the remediation steps taken post-breach harden the organisation against the specific tactics—such as those used by LockBit or Cl0p—that caused the initial breach. An incident is the best time to perform a "Security Posture Reset."

Key Takeaways

  • 72 Hours is Absolute: The clock starts at the moment of discovery, not the moment you confirm the full extent of the data loss.
  • Evidence is King: You must maintain a detailed log of the incident, including timestamped actions taken by your team.
  • Notify Data Subjects: If the breach presents a "high risk" to individuals, you have an additional legal requirement to notify them without undue delay.
  • Regulatory Alignment: Ensure your incident response plan covers both UK GDPR and your sector-specific regulator (e.g., FCA, SRA).

Frequently Asked Questions

Do I need to notify the ICO if the data was encrypted?

If the encryption keys were not compromised and the data remains unreadable, it may not constitute a reportable breach. However, you must document your risk assessment clearly to justify why you chose not to notify.

What happens if I miss the 72-hour deadline?

Missing the deadline is an aggravating factor. You must document the reason for the delay in your final report to the ICO. Being transparent about why the discovery was delayed is better than attempting to hide the timeline.

Can I hire a third party to handle the report?

Yes, but you remain the controller. While you can outsource the drafting and investigation, the legal responsibility for the accuracy of the notification rests with your organisation.

Secure Your Organisation Today

Navigating the complexities of UK GDPR and managing an active breach requires more than just policy—it requires technical expertise. Whether you are seeking cybersecurity consulting London or need an immediate SOC team to handle an ongoing incident, Gridisys provides the specialized support your organisation needs. Contact our team today at hello@gridisys.com to review your incident response readiness.

Gridisys

AI-powered cybersecurity and app development. Protecting and building for businesses worldwide.

© 2026 Gridisys. All rights reserved.Gridisys Ltd — Company No. 15780405 — Registered in England & WalesRegistered Office: 128 City Road, London, United Kingdom, EC1V 2NX

We use cookies to improve your experience and analyse site traffic. By clicking "Accept", you consent to our use of cookies. Learn more.