ICO 72-HOUR BREACH NOTIFICATION · United Kingdom

ICO 72-Hour Breach Notification — Article 33 Clock Guide for UK Organisations

UK GDPR Article 33 requires notification to the ICO within 72 hours of becoming aware of a personal data breach — strict liability if not done. The clock starts on 'awareness' (not discovery), evidence requirements are specific, and errors in the notification have caused fines topping £1m. Our breach response retainer covers the clock sprint, evidence assembly, and ICO engagement — fixed-price, scoped to your needs.

Article 33 ICO clock Sprint to notification Evidence assembly pack Awareness check Self-assessed vs ICO notification Retainer available

72 hours

ICO notification clock from 'awareness' — not from incident start

Art. 33 + 34

Article 33 ICO + Article 34 data subjects where high risk

Retainer

Gridisys breach response retainer — clock sprint + ICO engagement

£1m+

largest UK GDPR Article 33 violations (£17.5m Marriott, others)

Cybersecurity Consulting + 24/7 SOC Monitoring

Every Gridisys engagement is built on two pillars — strategic consulting to design the right controls, and managed SOC monitoring to keep them effective.

Cybersecurity Consulting

UK consulting engagements: risk assessment, security architecture, conditional access design, compliance (Cyber Essentials, UK GDPR, FCA PS21/3, NIS2), incident-response planning. Board-ready documentation, no jargon, no surprise invoices.

  • Risk assessment + security architecture review
  • Conditional access + Entra ID hardening design
  • Cyber Essentials / UK GDPR / FCA / NIS2 compliance support
  • Incident response planning + tabletop exercises
  • Vendor + supply-chain security assessment
  • Board / DPO reporting + evidence pack

Managed SOC Monitoring · 24/7

AI-augmented Security Operations Centre — continuous monitoring across Microsoft 365 / Entra ID, Defender, on-prem, and cloud. UK-based analysts, sub-hour triage on critical alerts. No long contract required.

  • 24/7 SIEM monitoring — Microsoft 365, Entra ID, Defender, Azure, on-prem logs
  • BEC + mailbox-compromise + OAuth grant abuse detection
  • Suspicious sign-in + conditional access drift alerting
  • Ransomware + lateral-movement detection from EDR + Defender
  • Sub-hour triage on critical alerts, monthly ops report
  • Optional + integrated with consulting engagements

Most engagements start with consulting (1-2 weeks), then SOC monitoring (ongoing ) keeps the controls effective.

GET A QUOTE

Pricing tailored to your needs

Every engagement is scoped to your environment and requirements. Book a free consultation for a tailored quote — no obligation.

What we cover

Practical, board-ready consulting — no jargon, no surprise invoices.

Clock sprint retainer

On call: when you become aware, we activate the breach response retainer. Within 1-2 hours: evidence-pack assembly, scope determination (Article 33 reportable? Article 34 high-risk?), draft ICO notification. Sprint working until clock-breaches are not added.

Awareness determination

UK GDPR case law (Marriott case) established that the clock starts when you have a 'reasonable degree of certainty' a breach occurred — not necessarily when fully investigated. We help establish the legal awareness point and document it for ICO defence.

Evidence assembly pack

ICO notification requires: nature of breach, categories + approximate number of data subjects + records, likely consequences, measures taken or proposed. We draft this in ICO's PECR tool format — straight to submission.

Article 34 data subject comms

If breach is 'high risk to individuals', Article 34 requires positive notification to affected data subjects (not waiting for media discovery). We draft the customer communication pack: clear description, what to do, what's been done, who to contact.

Notification drafting + submission

We draft the ICO notification in your voice — clear, accurate, complete. Submit via ICO's PECR portal. ICO has rejected notifications for being vague or deliberately incomplete — we ensure the draft meets the form's evidence requirements.

Post-incident report + DPIA refresh

Post-incident, the ICO may make a 'follow-up' enquiry. We document the post-incident report — root cause, remediation, timeline — and refresh your DPIA / records of processing activity. Protects against adverse ICO follow-up enforcement.

How we work

1

Pre-incident: contract + mobilise (Day 0)

Sign retainer: breach response retainer — covered response available on call. Define internal incident-response workflow including who notices + escalates + contacts Gridisys.

2

Reminder (T+0)

When you become aware: call Gridisys immediately. We legally establish 'awareness' point and start the 72-hour clock together with internal incident team.

3

Scope + draft (T+0 to T+24)

Within first 24 hours: scope determination, risk assessment (ICO-wise — Art. 33 triggered? Art. 34 high-risk?). Draft ICO notification.

4

Submit + handle Article 34 (T+24 to T+72)

Submit notification via PECR portal before clock expires. If Art. 34 high-risk: draft + dispatch customer comms. Coordinated response.

Sectors we protect

FCA-regulated firms (operational resilience) Solicitors (Law Society cyber guidance recommends ICO clock readiness) UK GP practices + dental + care homes + pharmacies (DPIA-led) Charities + trustees Schools + MATs Local SMEs across all sectors with UK GDPR obligations
FREE CONSULTATION

Your 72-hour breach response retainer, ready when the clock starts

Sign the Gridisys breach response retainer — free consultation on internal escalation workflow and sector-specific coverage.

Frequently asked questions

Gridisys

AI-powered cybersecurity and app development. Protecting and building for businesses worldwide.

© 2026 Gridisys. All rights reserved.Gridisys Ltd — Company No. 15780405 — Registered in England & WalesRegistered Office: 128 City Road, London, United Kingdom, EC1V 2NX

We use cookies to improve your experience and analyse site traffic. By clicking "Accept", you consent to our use of cookies. Learn more.