What an ICO breach report actually looks like
Most small incidents are not reportable, and reporting the ones that are not just adds noise. Here is how the decision is genuinely made, and why writing it down matters even when you decide no.
There is a persistent belief that any data mishap has to be reported to the Information Commissioner's Office within 72 hours or you are in trouble. That is not the rule. The rule is that a personal data breach must be reported when it is likely to result in a risk to people's rights and freedoms, and most small incidents do not clear that bar. Knowing where the bar sits saves you from either panic or complacency.
The test is about risk to the people whose data it was, not about your embarrassment. An email sent to the wrong colleague inside your own firm, spotted and deleted, is low risk. A spreadsheet of customer names, addresses and payment details emailed to a stranger is a different matter, because someone could be defrauded with it. The question you are answering is: could this realistically harm the people involved, and how badly.
The part organisations get wrong is thinking that “not reportable” means “nothing to do”. Every breach, reported or not, has to be recorded internally: what happened, when you found it, what data and how many people, your risk assessment, and what you decided. That record is the thing that protects you. If the ICO ever asks, a considered “we assessed it as low risk, here is the reasoning” is a strong position. A shrug is not.
So the honest workflow is: contain it first, then assess the risk to individuals, then decide. If it clears the bar, report within 72 hours of becoming aware and tell the affected people if the risk to them is high. If it does not, record the decision anyway. The discipline is in writing down the judgement, not in reporting everything that ever goes slightly wrong.
- ✓Contain the incident first: recall the email, reset the password, stop the spread.
- ✓Assess the risk to the people whose data it was, not to your reputation.
- ✓Record every incident internally, whether or not you report it.
- ✓If it is reportable, notify the ICO within 72 hours of becoming aware.
- Personal data breaches: a guide INFORMATION COMMISSIONER'S OFFICE ↗
- Reporting a personal data breach GOV.UK ↗
- Responding to a cyber incident NATIONAL CYBER SECURITY CENTRE ↗
Links open each publisher’s live coverage of this topic.