Search

How can we help?

Icon

GDPR: the ICO attempts to clarify obligation to report serious data breaches

Faced with misleading press stories, the ICO has been addressing misconceptions about the GDPR by publishing myth busting blogs, including on the new requirement to report serious breaches of personal data.

Not all personal data breaches will need to be reported to the ICO, only if a risk to people’s rights and freedoms is likely.  The ICO does not give strict instructions of what incidents are serious enough to report but reiterates it is when people may suffer a significant detriment such as damage to reputation or financial loss. The ICO has encouraged all organisations to look at the types of incidents they could face to develop a sense of what would be serious.

Although the requirement to report a serious breach is without undue delay and where feasible within 72 hours, they don’t expect a full final report with all details within this time. The ICO have said that fines will be proportionate and will not be issued for every failure (although only time will tell what this will mean in practice). They remind firms that the point of the GDPR is not to punish organisations but to encourage companies to improve their ability to prevent breaches.

Under the current data protection law, reporting is best practice anyway even if not mandatory. Involving the ICO early can ensure the firm receives the best guidance and mitigate any fines issued.

Under the current data protection law, reporting is best practice anyway even if not mandatory. Involving the ICO early can ensure the firm receives the best guidance and mitigate any fines issued.

Organisations are encouraged to start planning now to ensure roles and processes are in place for when GDPR comes into effect in May 2018.

About this article

Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website

About this article

Read, listen and watch our latest insights

art
  • 18 June 2025
  • Employment

Pride Month: How Can You Celebrate as an Employer

The UK held its first Pride Parade in 1972, inspired by events held in major American cities following the Stonewall rebellion in New York in June 1969.

Pub
  • 16 June 2025
  • Privacy and Data Protection

WhatsApp in the workplace: Is it legally safe?

In this podcast, Lucy White and Monica Mastropasqua, members of the Data Protection team at Clarkslegal, will address frequently asked questions from clients regarding the use of WhatsApp at work.

art
  • 13 June 2025
  • Employment

Human Resources – A Shift Towards artificial intelligence?

On 6 May 2025, the SRA authorised the first law firm providing legal services through artificial intelligence. Garfield.Law will provide an AI-powered tool which can assist businesses with the small claims court process, to aid in recovering unpaid debts.

art
  • 11 June 2025
  • Employment

Employment Contracts and Specific Performance

‘Specific performance’ is a type of equitable remedy available, in some circumstances, and at the court’s discretion, for breach of contract; it entails an order by the court which legally compels a party to a contract to fulfil its contractual obligations.

art
  • 10 June 2025
  • Commercial Real Estate

Taking a commercial lease: The main points to negotiate when agreeing the Heads of Terms

What are the key areas tenants may want to pay particular attention to when agreeing to the Heads of Terms (HoTs).

art
  • 09 June 2025
  • Employment

Clarkslegal representing UK employers at the International Labour Conference

I am writing this from Geneva, where I once again have the honour of attending the International Labour Organisation’s International Labour Conference.