Search

How can we help?

Icon

GDPR: the ICO attempts to clarify obligation to report serious data breaches

Faced with misleading press stories, the ICO has been addressing misconceptions about the GDPR by publishing myth busting blogs, including on the new requirement to report serious breaches of personal data.

Not all personal data breaches will need to be reported to the ICO, only if a risk to people’s rights and freedoms is likely.  The ICO does not give strict instructions of what incidents are serious enough to report but reiterates it is when people may suffer a significant detriment such as damage to reputation or financial loss. The ICO has encouraged all organisations to look at the types of incidents they could face to develop a sense of what would be serious.

Although the requirement to report a serious breach is without undue delay and where feasible within 72 hours, they don’t expect a full final report with all details within this time. The ICO have said that fines will be proportionate and will not be issued for every failure (although only time will tell what this will mean in practice). They remind firms that the point of the GDPR is not to punish organisations but to encourage companies to improve their ability to prevent breaches.

Under the current data protection law, reporting is best practice anyway even if not mandatory. Involving the ICO early can ensure the firm receives the best guidance and mitigate any fines issued.

Under the current data protection law, reporting is best practice anyway even if not mandatory. Involving the ICO early can ensure the firm receives the best guidance and mitigate any fines issued.

Organisations are encouraged to start planning now to ensure roles and processes are in place for when GDPR comes into effect in May 2018.

Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website

Author profile

About this article

Read, listen and watch our latest insights

art
  • 18 December 2025
  • Employment

Employment Law: Looking back at 2025 and what to expect in 2026

2025 has certainly been an interesting year for employment law. While the Employment Rights Bill has pulled much of the focus since it was introduced in October 2024, there have been other important updates this year as well.

art
  • 18 December 2025
  • Corporate and M&A

Deal Announcement: Clarkslegal’s corporate lawyers advise on the sale of Chatterbox Labs Limited to subsidiary of American tech giant

Clarkslegal’s corporate team, led by Senior Consultant Jon Chapman and supported by Senior Solicitor Emma Docking, advised the founders of Chatterbox Labs Limited on the sale of the AI security specialist to Red Hat, Inc., a wholly owned subsidiary of IBM.

art
  • 16 December 2025
  • Employment

Christmas Parties – Festive Fun or a New Year Hangover?

It’s Christmas party season! The office party is often a mixed blessing – an opportunity to boost morale and perhaps celebrate a successful year yet also a melting pot of workers letting their hair down, with potential for accidents, injuries, threats and claims.

art
  • 10 December 2025
  • Privacy and Data Protection

The 12 Data Protection Mistakes of Christmas

As the festive season approaches, it is not just last-minute shopping and office parties that can catch organisations off guard; data protection slip-ups are just as common.

Pub
  • 04 December 2025
  • Immigration

UK Immigration: What to expect in 2026 for employers

Join our UK immigration specialists, Ruth Karimatsenga and Monica Mastropasqua, as they explore the key updates and how they affect your business in 2026.

Pub
  • 04 December 2025
  • Corporate and M&A

Autumn Budget 2025 Breakdown: Key takeaways for business buyers and sellers

Join Stuart Mullins and Nicky Goringe Larkin as they delve into the key updates from the Chancellor’s announcement, with a focus on what matters most for businesses looking to buy and sell.