Search

How can we help?

Icon

GDPR: the ICO attempts to clarify obligation to report serious data breaches

Faced with misleading press stories, the ICO has been addressing misconceptions about the GDPR by publishing myth busting blogs, including on the new requirement to report serious breaches of personal data.

Not all personal data breaches will need to be reported to the ICO, only if a risk to people’s rights and freedoms is likely.  The ICO does not give strict instructions of what incidents are serious enough to report but reiterates it is when people may suffer a significant detriment such as damage to reputation or financial loss. The ICO has encouraged all organisations to look at the types of incidents they could face to develop a sense of what would be serious.

Although the requirement to report a serious breach is without undue delay and where feasible within 72 hours, they don’t expect a full final report with all details within this time. The ICO have said that fines will be proportionate and will not be issued for every failure (although only time will tell what this will mean in practice). They remind firms that the point of the GDPR is not to punish organisations but to encourage companies to improve their ability to prevent breaches.

Under the current data protection law, reporting is best practice anyway even if not mandatory. Involving the ICO early can ensure the firm receives the best guidance and mitigate any fines issued.

Under the current data protection law, reporting is best practice anyway even if not mandatory. Involving the ICO early can ensure the firm receives the best guidance and mitigate any fines issued.

Organisations are encouraged to start planning now to ensure roles and processes are in place for when GDPR comes into effect in May 2018.

Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website

Author profile

About this article

Read, listen and watch our latest insights

art
  • 13 May 2026
  • Employment

10 top tips for negotiating a redundancy settlement agreement, for employers and employees

Redundancies are on the rise, resulting in increased use of settlement agreements. We’ve compiled our top 10 tips for drafting and negotiating these agreements to support both employers and employees through this challenging process.

art
  • 12 May 2026
  • Immigration

Supplementary Employment: When is it Allowed under UK Immigration Rules?

This article provides a guidance to understanding the rules on supplementary employment in the UK.

Pub
  • 11 May 2026
  • Immigration

How to prepare for Sponsor Licence Compliance in 2026: Essential tips for UK employers

Join immigration experts Ruth Karimatsenga and Monica Mastropasqua for an in-depth podcast discussion on sponsor licence compliance in 2026.

Pub
  • 07 May 2026
  • Employment

Employment Rights Act 2025: Key Changes for Employers

Join Katie Glendinning and Lucy White for a live webinar as they break down the key changes introduced by the Employment Rights Act 2025, offering clear insights into what these reforms mean in practice for employers and HR professionals.

art
  • 07 May 2026
  • Public Procurement

What the First Procurement Act 2023 Judgment Means for Automatic Suspension

It has been more than a year since the Procurement Act 2023 (PA23) came into force in February 2025, and the long wait for the first High Court judgment on the Act to be published is finally over.

art
  • 06 May 2026
  • Corporate and M&A

Community Interest Companies – What do you need to know?

This article seeks to provide an overview of the CIC structure’s key characteristics, the types of enterprises it suits, and some practical tips on the application process.