ICO 72-Hour Breach Notification — Article 33 Clock Guide for UK Organisations
UK GDPR Article 33 requires notification to the ICO within 72 hours of becoming aware of a personal data breach — strict liability if not done. The clock starts on 'awareness' (not discovery), evidence requirements are specific, and errors in the notification have caused fines topping £1m. Our breach response retainer covers the clock sprint, evidence assembly, and ICO engagement — fixed-price, scoped to your needs.
72 hours
ICO notification clock from 'awareness' — not from incident start
Art. 33 + 34
Article 33 ICO + Article 34 data subjects where high risk
Retainer
Gridisys breach response retainer — clock sprint + ICO engagement
£1m+
largest UK GDPR Article 33 violations (£17.5m Marriott, others)
Cybersecurity Consulting + 24/7 SOC Monitoring
Every Gridisys engagement is built on two pillars — strategic consulting to design the right controls, and managed SOC monitoring to keep them effective.
Cybersecurity Consulting
UK consulting engagements: risk assessment, security architecture, conditional access design, compliance (Cyber Essentials, UK GDPR, FCA PS21/3, NIS2), incident-response planning. Board-ready documentation, no jargon, no surprise invoices.
- Risk assessment + security architecture review
- Conditional access + Entra ID hardening design
- Cyber Essentials / UK GDPR / FCA / NIS2 compliance support
- Incident response planning + tabletop exercises
- Vendor + supply-chain security assessment
- Board / DPO reporting + evidence pack
Managed SOC Monitoring · 24/7
AI-augmented Security Operations Centre — continuous monitoring across Microsoft 365 / Entra ID, Defender, on-prem, and cloud. UK-based analysts, sub-hour triage on critical alerts. No long contract required.
- 24/7 SIEM monitoring — Microsoft 365, Entra ID, Defender, Azure, on-prem logs
- BEC + mailbox-compromise + OAuth grant abuse detection
- Suspicious sign-in + conditional access drift alerting
- Ransomware + lateral-movement detection from EDR + Defender
- Sub-hour triage on critical alerts, monthly ops report
- Optional + integrated with consulting engagements
Most engagements start with consulting (1-2 weeks), then SOC monitoring (ongoing ) keeps the controls effective.
Pricing tailored to your needs
Every engagement is scoped to your environment and requirements. Book a free consultation for a tailored quote — no obligation.
What we cover
Practical, board-ready consulting — no jargon, no surprise invoices.
Clock sprint retainer
On call: when you become aware, we activate the breach response retainer. Within 1-2 hours: evidence-pack assembly, scope determination (Article 33 reportable? Article 34 high-risk?), draft ICO notification. Sprint working until clock-breaches are not added.
Awareness determination
UK GDPR case law (Marriott case) established that the clock starts when you have a 'reasonable degree of certainty' a breach occurred — not necessarily when fully investigated. We help establish the legal awareness point and document it for ICO defence.
Evidence assembly pack
ICO notification requires: nature of breach, categories + approximate number of data subjects + records, likely consequences, measures taken or proposed. We draft this in ICO's PECR tool format — straight to submission.
Article 34 data subject comms
If breach is 'high risk to individuals', Article 34 requires positive notification to affected data subjects (not waiting for media discovery). We draft the customer communication pack: clear description, what to do, what's been done, who to contact.
Notification drafting + submission
We draft the ICO notification in your voice — clear, accurate, complete. Submit via ICO's PECR portal. ICO has rejected notifications for being vague or deliberately incomplete — we ensure the draft meets the form's evidence requirements.
Post-incident report + DPIA refresh
Post-incident, the ICO may make a 'follow-up' enquiry. We document the post-incident report — root cause, remediation, timeline — and refresh your DPIA / records of processing activity. Protects against adverse ICO follow-up enforcement.
How we work
Pre-incident: contract + mobilise (Day 0)
Sign retainer: breach response retainer — covered response available on call. Define internal incident-response workflow including who notices + escalates + contacts Gridisys.
Reminder (T+0)
When you become aware: call Gridisys immediately. We legally establish 'awareness' point and start the 72-hour clock together with internal incident team.
Scope + draft (T+0 to T+24)
Within first 24 hours: scope determination, risk assessment (ICO-wise — Art. 33 triggered? Art. 34 high-risk?). Draft ICO notification.
Submit + handle Article 34 (T+24 to T+72)
Submit notification via PECR portal before clock expires. If Art. 34 high-risk: draft + dispatch customer comms. Coordinated response.
Sectors we protect
Your 72-hour breach response retainer, ready when the clock starts
Sign the Gridisys breach response retainer — free consultation on internal escalation workflow and sector-specific coverage.
RELATED UK CYBERSECURITY SERVICES