Search

How can we help?

Icon

GDPR: the ICO attempts to clarify obligation to report serious data breaches

Faced with misleading press stories, the ICO has been addressing misconceptions about the GDPR by publishing myth busting blogs, including on the new requirement to report serious breaches of personal data.

Not all personal data breaches will need to be reported to the ICO, only if a risk to people’s rights and freedoms is likely.  The ICO does not give strict instructions of what incidents are serious enough to report but reiterates it is when people may suffer a significant detriment such as damage to reputation or financial loss. The ICO has encouraged all organisations to look at the types of incidents they could face to develop a sense of what would be serious.

Although the requirement to report a serious breach is without undue delay and where feasible within 72 hours, they don’t expect a full final report with all details within this time. The ICO have said that fines will be proportionate and will not be issued for every failure (although only time will tell what this will mean in practice). They remind firms that the point of the GDPR is not to punish organisations but to encourage companies to improve their ability to prevent breaches.

Under the current data protection law, reporting is best practice anyway even if not mandatory. Involving the ICO early can ensure the firm receives the best guidance and mitigate any fines issued.

Under the current data protection law, reporting is best practice anyway even if not mandatory. Involving the ICO early can ensure the firm receives the best guidance and mitigate any fines issued.

Organisations are encouraged to start planning now to ensure roles and processes are in place for when GDPR comes into effect in May 2018.

Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website

Author profile

About this article

Read, listen and watch our latest insights

art
  • 19 August 2026
  • Employment

Managing employee redundancies: Frequently asked questions (FAQs)

Redundancy should be an employer’s last option when restructuring their business. There are necessary steps that should be taken to ensure that redundancy is the best move forward

art
  • 18 August 2026
  • Immigration

Home Office curtailment of Sponsored Workers’ permission: Why employers and employees must act quickly

The Home Office has recently changed the speed at which it processes sponsor notifications following the end of a sponsored worker’s employment.

art
  • 13 August 2026
  • Employment

ACAS Draft New Code on Disciplinary and Grievance Procedures

ACAS have published a draft Code on 30 July 2026, which will replace the 2015 ACAS Code on disciplinary and grievance procedures when the Code is finalised at the end of September 2026.

art
  • 12 August 2026
  • Corporate and M&A

EMIs – April 2026 changes explained

On 6 April 2026 the Enterprise Management Incentive scheme (EMI) was expanded to make EMIs accessible to a wider range of businesses.

art
  • 06 August 2026
  • Privacy and Data Protection

The rise of the AI-powered individual: Is your business ready?

Artificial intelligence is changing the data protection landscape, but perhaps not in the way many organisations expected. Much of the discussion has centred on businesses adopting AI and ensuring they comply with the UK GDPR.

Pub
  • 06 August 2026
  • Employment

Employment law changes in 2026: What you need to know

With ongoing changes to UK employment law, staying updated is more challenging than ever. Join Monica Atwal and Harry Berryman for a live webinar covering 2026 HR changes and key employment law updates on Thursday 17 September.