Search

How can we help?

Icon

GDPR: the ICO attempts to clarify obligation to report serious data breaches

Faced with misleading press stories, the ICO has been addressing misconceptions about the GDPR by publishing myth busting blogs, including on the new requirement to report serious breaches of personal data.

Not all personal data breaches will need to be reported to the ICO, only if a risk to people’s rights and freedoms is likely.  The ICO does not give strict instructions of what incidents are serious enough to report but reiterates it is when people may suffer a significant detriment such as damage to reputation or financial loss. The ICO has encouraged all organisations to look at the types of incidents they could face to develop a sense of what would be serious.

Although the requirement to report a serious breach is without undue delay and where feasible within 72 hours, they don’t expect a full final report with all details within this time. The ICO have said that fines will be proportionate and will not be issued for every failure (although only time will tell what this will mean in practice). They remind firms that the point of the GDPR is not to punish organisations but to encourage companies to improve their ability to prevent breaches.

Under the current data protection law, reporting is best practice anyway even if not mandatory. Involving the ICO early can ensure the firm receives the best guidance and mitigate any fines issued.

Under the current data protection law, reporting is best practice anyway even if not mandatory. Involving the ICO early can ensure the firm receives the best guidance and mitigate any fines issued.

Organisations are encouraged to start planning now to ensure roles and processes are in place for when GDPR comes into effect in May 2018.

Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website

Author profile

About this article

Read, listen and watch our latest insights

Pub
  • 27 March 2026
  • Corporate and M&A

Shareholder Disputes: What to do when disputes arise – Episode 4

Join Stuart Mullins and Jack Hobbs for episode four of our Shareholder Disputes podcast series as they confront the realities of shareholder fallouts and share practical strategies for managing these complex situations.

art
  • 24 March 2026
  • Immigration

Spouse Visa – Is your relationship genuine and subsisting?

For years many couples have become frustrated by the requirements for a spouse visa as the rules and guidance are difficult to understand. A significant amount of applications are rejected on the basis of the applicant not providing the adequate documents to evidence the relationship requirement.

art
  • 20 March 2026
  • Corporate and M&A

Drag-Along & Tag-Along Rights: Why Every Company Needs Them

When starting a company, very few founders are aware of the potential issues around shares, share ownership and the implications of that when selling their company.

art
  • 19 March 2026
  • Privacy and Data Protection

WhatsApp in the Workplace

This article explores the potential risks of using WhatsApp for workplace communications, the implications for GDPR compliance and under UK legislation, and provides practical tips for employers to mitigate these risks.

art
  • 16 March 2026
  • Employment

Trade Union Law Changes from April 2026

April brings the next tranche of reforms under the Employment Rights Act 2025 including changes to the statutory recognition scheme making it easier for trade unions to be recognised in the workplace.

Pub
  • 16 March 2026
  • Corporate and M&A

Shareholder Disputes: Managing Shareholder Buyouts and Exits – Episode 3

Join Stuart Mullins and Nicky Goringe Larkin for the third episode of our Shareholder Disputes series, where we move from prevention to resolution—exploring what happens when a founder’s exit becomes unavoidable.