Search

How can we help?

Icon

GDPR: the ICO attempts to clarify obligation to report serious data breaches

Faced with misleading press stories, the ICO has been addressing misconceptions about the GDPR by publishing myth busting blogs, including on the new requirement to report serious breaches of personal data.

Not all personal data breaches will need to be reported to the ICO, only if a risk to people’s rights and freedoms is likely.  The ICO does not give strict instructions of what incidents are serious enough to report but reiterates it is when people may suffer a significant detriment such as damage to reputation or financial loss. The ICO has encouraged all organisations to look at the types of incidents they could face to develop a sense of what would be serious.

Although the requirement to report a serious breach is without undue delay and where feasible within 72 hours, they don’t expect a full final report with all details within this time. The ICO have said that fines will be proportionate and will not be issued for every failure (although only time will tell what this will mean in practice). They remind firms that the point of the GDPR is not to punish organisations but to encourage companies to improve their ability to prevent breaches.

Under the current data protection law, reporting is best practice anyway even if not mandatory. Involving the ICO early can ensure the firm receives the best guidance and mitigate any fines issued.

Under the current data protection law, reporting is best practice anyway even if not mandatory. Involving the ICO early can ensure the firm receives the best guidance and mitigate any fines issued.

Organisations are encouraged to start planning now to ensure roles and processes are in place for when GDPR comes into effect in May 2018.

About this article

Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website

About this article

Read, listen and watch our latest insights

art
  • 08 May 2025
  • Employment

Statutory Sick Pay Scheme changes: how can employers prepare for such changes?

The government has recently changed the Statutory Sick Pay provisions; it is anticipated that such changes will ‘help people to stay in work and grow the economy’.

Pub
  • 07 May 2025
  • Corporate and M&A

Thinking of exiting your business? Part 1

In the first part of this three-part series, we explore why planning your exit strategy early can shape the way you build, grow, and eventually sell your business for maximum value. From mindset to strategy, we unpack how thinking about the end from the beginning can lead to smarter decisions and better outcomes.

Pub
  • 07 May 2025
  • Immigration

UK Immigration: Essential update for employers

The UK’s immigration system will see major changes in 2025. Watch our UK immigration specialists, Ruth Karimatsenga and Monica Mastropasqua, as they explore the key updates and how they affect your business.

art
  • 06 May 2025
  • Corporate and M&A

Can a disclosure letter give rise to a misrepresentation claim?

Provided by a seller to a buyer, a disclosure letter is an important element in any business sale or purchase transaction.

art
  • 02 May 2025
  • Employment

Sex, Gender and the Law: What the Supreme Court’s Recent Ruling Means for Employers

The recent UK Supreme Court decision in For Women Scotland Ltd v The Scottish Ministers  UKSC 16 has generated significant attention, but for most employers, we would argue that its practical impact is relatively limited—at least for now.

art
  • 29 April 2025
  • Privacy and Data Protection

Use of Personal Devices at Work: Why a Bring Your Own Device Policy is Essential

We will highlight in this article what changes have been made to the DUAB since the early stages of the Bill.