Search

How can we help?

Icon

GDPR: the ICO attempts to clarify obligation to report serious data breaches

Faced with misleading press stories, the ICO has been addressing misconceptions about the GDPR by publishing myth busting blogs, including on the new requirement to report serious breaches of personal data.

Not all personal data breaches will need to be reported to the ICO, only if a risk to people’s rights and freedoms is likely.  The ICO does not give strict instructions of what incidents are serious enough to report but reiterates it is when people may suffer a significant detriment such as damage to reputation or financial loss. The ICO has encouraged all organisations to look at the types of incidents they could face to develop a sense of what would be serious.

Although the requirement to report a serious breach is without undue delay and where feasible within 72 hours, they don’t expect a full final report with all details within this time. The ICO have said that fines will be proportionate and will not be issued for every failure (although only time will tell what this will mean in practice). They remind firms that the point of the GDPR is not to punish organisations but to encourage companies to improve their ability to prevent breaches.

Under the current data protection law, reporting is best practice anyway even if not mandatory. Involving the ICO early can ensure the firm receives the best guidance and mitigate any fines issued.

Under the current data protection law, reporting is best practice anyway even if not mandatory. Involving the ICO early can ensure the firm receives the best guidance and mitigate any fines issued.

Organisations are encouraged to start planning now to ensure roles and processes are in place for when GDPR comes into effect in May 2018.

Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website

Author profile

About this article

Read, listen and watch our latest insights

Pub
  • 23 February 2026
  • Corporate and M&A

Shareholder Disputes: Planning for the Worst – Episode 2

Join Stuart Mullins and Nicky Goringe Larkin for the second episode of our podcast series on shareholder disputes, where they explore what happens when business partners disagree.

art
  • 20 February 2026
  • Corporate and M&A

EMI Schemes – following the 2025 Autumn Statement

In an economic landscape where attracting, retaining and incentivising key employees is key to commercial success.

art
  • 19 February 2026

Clarkslegal’s international legal alliance TAGLaw achieves top “Elite” – Band 1 ranking by Chambers & Partners 2026

Clarkslegal’s international legal alliance, TAGLaw®, has again been recognised by Chambers & Partners as “Elite – Band 1” for 2026—the highest ranking awarded to legal networks and alliances.

art
  • 17 February 2026
  • Employment

The Employment Rights Act – A shift in power: why employers will face greater pressure from industrial action and union relations in 2026

Substantial union-related changes under the Employment Rights Act 2025 will take effect on 18 February 2026, ushering in significant shifts in the legal landscape for industrial action in the UK.

art
  • 16 February 2026
  • Immigration

High Potential Individual Visa (HPI Visa) – UK Immigration Route

The High Potential Individual (HPI) visa is a UK immigration route designed to attract recent graduates from top-ranked international universities.

art
  • 13 February 2026
  • Employment

Businesses Prepare for Stronger Trade Union Rights: Monica Atwal Comments

The new trade union rights introduced by the Employment Rights Act 2025 will come into force on 18 February 2026. These changes are expected to make strikes easier to organise and will extend protections for striking workers. Monica Atwal comments on the implications of these reforms in People Management magazine.