Search

How can we help?

Icon

GDPR: the ICO attempts to clarify obligation to report serious data breaches

Faced with misleading press stories, the ICO has been addressing misconceptions about the GDPR by publishing myth busting blogs, including on the new requirement to report serious breaches of personal data.

Not all personal data breaches will need to be reported to the ICO, only if a risk to people’s rights and freedoms is likely.  The ICO does not give strict instructions of what incidents are serious enough to report but reiterates it is when people may suffer a significant detriment such as damage to reputation or financial loss. The ICO has encouraged all organisations to look at the types of incidents they could face to develop a sense of what would be serious.

Although the requirement to report a serious breach is without undue delay and where feasible within 72 hours, they don’t expect a full final report with all details within this time. The ICO have said that fines will be proportionate and will not be issued for every failure (although only time will tell what this will mean in practice). They remind firms that the point of the GDPR is not to punish organisations but to encourage companies to improve their ability to prevent breaches.

Under the current data protection law, reporting is best practice anyway even if not mandatory. Involving the ICO early can ensure the firm receives the best guidance and mitigate any fines issued.

Under the current data protection law, reporting is best practice anyway even if not mandatory. Involving the ICO early can ensure the firm receives the best guidance and mitigate any fines issued.

Organisations are encouraged to start planning now to ensure roles and processes are in place for when GDPR comes into effect in May 2018.

Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website

Author profile

About this article

Read, listen and watch our latest insights

art
  • 03 September 2026
  • Employment

Employment Rights Act – October Changes

We are well and truly underway with implementation of the Employment Rights Act 2025 (“ERA 2025”) and October brings the next tranche of changes that employers will need to be ready for.

art
  • 02 September 2026
  • Immigration

Mandatory MFA for Sponsor Management System Users: What Sponsors Need to Know

The Home Office is introducing a significant security change to the Sponsor Management System (SMS). From 3 September 2026, the Home Office will begin a phased rollout of mandatory Multi-Factor Authentication (MFA) for SMS users.

art
  • 01 September 2026

Orwins continues growth with investment in Milners and Acquisition of Roe Lawyers

Clarkslegal is pleased to share the news that Orwins, the legal services group we joined earlier this year, has announced a significant investment in Yorkshire law firm Milners and the acquisition of London-based specialist practice Roe Lawyers.

Pub
  • 28 August 2026
  • Immigration

Right to Work and Sponsor Licence Changes 2026: Key dates for businesses

In this podcast, immigration solicitors Ruth Karimatsenga and Monica Mastropasqua discuss the key immigration compliance changes coming into force in September and October 2026 and what employers, HR teams, sponsors and individuals should do to prepare.

art
  • 28 August 2026
  • Commercial Real Estate

Modernising security of tenure: The Law Commission’s follow up consultation paper

On 16th June 2026, the Commission published its second consultation paper: Business Tenancies: the right to renew – modernising security of tenure.

Pub
  • 27 August 2026
  • Litigation and dispute resolution

The Highly Expedited Arbitration Provisions – ICC Rules 2026 – Factsheet

This factsheet provides an overview of the ICC’s Highly Expedited Arbitration Provisions (HEAP), outlining some of the key procedural features introduced by Appendix VI of the 2026 Rules and the potential benefits of this new expedited process.