Digital Gnome
TECHNOLOGY ASSURANCE

Tell us who you are and we’ll cut the rest

One tool for the whole job, from a locked laptop to a signed policy. Answer two questions and we’ll show you only what fits, priced for your size.

1 · HOW MANY OF YOU?
2 · WHAT DO YOU DO? OPTIONAL
✓ NO CARD NEEDED ✓ FREE FOREVER FOR SMALL TEAMS ✓ BUILT IN WALES
Your business
LIVE PREVIEW
YOUR PLAN
WHAT YOU’D GET
← Back to news
STANDARDS 27 JUN 2026 · 3 MIN

What an ICO breach report actually looks like

Most small incidents are not reportable, and reporting the ones that are not just adds noise. Here is how the decision is genuinely made, and why writing it down matters even when you decide no.

PRIYA SHAH · GUEST CONTRIBUTOR
SHARE LinkedIn X Email
STANDARDS cover image

There is a persistent belief that any data mishap has to be reported to the Information Commissioner's Office within 72 hours or you are in trouble. That is not the rule. The rule is that a personal data breach must be reported when it is likely to result in a risk to people's rights and freedoms, and most small incidents do not clear that bar. Knowing where the bar sits saves you from either panic or complacency.

The test is about risk to the people whose data it was, not about your embarrassment. An email sent to the wrong colleague inside your own firm, spotted and deleted, is low risk. A spreadsheet of customer names, addresses and payment details emailed to a stranger is a different matter, because someone could be defrauded with it. The question you are answering is: could this realistically harm the people involved, and how badly.

The part organisations get wrong is thinking that “not reportable” means “nothing to do”. Every breach, reported or not, has to be recorded internally: what happened, when you found it, what data and how many people, your risk assessment, and what you decided. That record is the thing that protects you. If the ICO ever asks, a considered “we assessed it as low risk, here is the reasoning” is a strong position. A shrug is not.

So the honest workflow is: contain it first, then assess the risk to individuals, then decide. If it clears the bar, report within 72 hours of becoming aware and tell the affected people if the risk to them is high. If it does not, record the decision anyway. The discipline is in writing down the judgement, not in reporting everything that ever goes slightly wrong.

WHAT TO DO
  • ✓Contain the incident first: recall the email, reset the password, stop the spread.
  • ✓Assess the risk to the people whose data it was, not to your reputation.
  • ✓Record every incident internally, whether or not you report it.
  • ✓If it is reportable, notify the ICO within 72 hours of becoming aware.