Search

How can we help?

Icon

GDPR: the ICO attempts to clarify obligation to report serious data breaches

Faced with misleading press stories, the ICO has been addressing misconceptions about the GDPR by publishing myth busting blogs, including on the new requirement to report serious breaches of personal data.

Not all personal data breaches will need to be reported to the ICO, only if a risk to people’s rights and freedoms is likely.  The ICO does not give strict instructions of what incidents are serious enough to report but reiterates it is when people may suffer a significant detriment such as damage to reputation or financial loss. The ICO has encouraged all organisations to look at the types of incidents they could face to develop a sense of what would be serious.

Although the requirement to report a serious breach is without undue delay and where feasible within 72 hours, they don’t expect a full final report with all details within this time. The ICO have said that fines will be proportionate and will not be issued for every failure (although only time will tell what this will mean in practice). They remind firms that the point of the GDPR is not to punish organisations but to encourage companies to improve their ability to prevent breaches.

Under the current data protection law, reporting is best practice anyway even if not mandatory. Involving the ICO early can ensure the firm receives the best guidance and mitigate any fines issued.

Under the current data protection law, reporting is best practice anyway even if not mandatory. Involving the ICO early can ensure the firm receives the best guidance and mitigate any fines issued.

Organisations are encouraged to start planning now to ensure roles and processes are in place for when GDPR comes into effect in May 2018.

Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website

Author profile

About this article

Read, listen and watch our latest insights

art
  • 03 June 2026
  • Employment

Holiday Pay Record Keeping – What this new duty means for employers

The Employment Rights Act 2025 made certain changes to the rules around holiday records, which came into effect on 6th April 2026.

art
  • 03 June 2026
  • Corporate and M&A

Is your Company’s Register of Members accurate? The hidden risks of getting it wrong

Ensure your company’s Register of Members is accurate and compliant. Learn the legal risks, common mistakes, and how to protect your business from penalties.

art
  • 02 June 2026
  • Corporate and M&A

Clarkslegal welcomes leading Corporate Law expert Mark Ridley as Partner

Clarkslegal is delighted to announce the appointment of Mark Ridley as a new Partner in the Corporate and Commercial team.

art
  • 28 May 2026

Newly rebranded legal services group Orwins makes investment in Clarkslegal

Orwins, the law firm for ambitious businesses and high net worth individuals, has today, 27 May 2026, announced a significant investment in Reading-based commercial law firm Clarkslegal.

art
  • 20 May 2026
  • Immigration

AI vs Home Office approved Translations – why migrants are paying the price

AI is transforming almost every professional sector. Law firms now use AI-assisted drafting, businesses rely on automated translation software, and governments increasingly use digital systems for decision-making.

art
  • 20 May 2026
  • Employment

Trade Unions Right of Access from October – What you need to know

Under the Employment Rights Act 2025, independent Trade Unions (i.e. those with a certificate of independence) will have a right to access workplaces (physically and digitally) from October 2026.