Blue abstract lines representing data breach response and ico support for data protection services in the uk.
Home / Services / Data Breach Response & ICO Support


When a data breach happens, we help assess the potential risks, determine what your organisation needs to do next and put practical measures in place to reduce the risk of a similar incident happening again.


Personal Data Breach Response and ICO Support for UK Organisations


Not every data breach needs to be reported to the ICO, but every incident needs to be assessed properly. Where a breach is likely to result in a risk to individuals, the ICO must be notified without undue delay and, where feasible, within 72 hours of the organisation becoming aware of it.

Dealing with a personal data breach?
Download our one-page guide to the first 72 hours.
Download the breach guide →

Data breaches can develop quickly. An incorrectly sent email may initially involve one recipient but contain sensitive information about several people. A compromised mailbox may expose more information the longer access continues. A lost device may create very different risks depending on whether it is encrypted and can be remotely disabled.


Early action gives the organisation more time to contain the incident, preserve evidence, assess the level of risk and make a considered decision about ICO notification and communications with affected individuals.

Where a breach is likely to result in a high risk to individuals, those people must also be informed without undue delay.


What to expect from our data breach response service

We provide support from the initial assessment through to ICO notification, communications and post-incident remediation. The level of support will depend on the nature and seriousness of the incident.

1

Initial breach assessment

2

Containment and evidence

3

Risk assessment

4

ICO notification decision

5

ICO and individual communications

6

Remediation and lessons learned

The scope depends on the nature and seriousness of the incident. Some organisations need an initial risk assessment and advice on notification, while others require end-to-end support with containment, evidence, ICO reporting, communications with affected individuals and remediation.

1. Establish what happened

We begin by gathering the available facts, including when the incident occurred, when your organisation became aware of it, what personal data is involved and who may have been affected. Where appropriate, we work alongside your IT, security or other relevant teams.


2. Assess the risk and reporting obligations

We assess the likely impact on individuals and advise whether the breach reaches the threshold for notification to the ICO. Where the risk is high, we also consider whether affected individuals need to be informed. The ICO confirms that not every personal data breach requires notification; the decision depends on the likelihood of risk to people’s rights and freedoms.

3. Manage the response

Where notification is required, we can help prepare the ICO report and communications to affected individuals. We also document the decision-making process and identify practical remedial measures following the incident.


What are the benefits of getting breach advice early?

Early specialist advice can help your organisation contain the incident, reach a defensible notification decision and preserve a clear record of the response.

1. Faster decision-making

Establish quickly what the organisation needs to do and who needs to be involved.


2. Defensible reporting decisions

Keep a clear record of why the incident was or was not reported and the information relied upon.


3. Reduced future risk

Identify the cause of the incident and practical improvements to processes, training or controls.

Do all data breaches need to be reported to the ICO?

No. A personal data breach needs to be reported to the ICO where it is likely to result in a risk to the rights and freedoms of individuals. If the organisation concludes that a risk is unlikely, notification is not required, but the decision should still be documented.


Where notification is required, it must be made without undue delay and, where feasible, within 72 hours of becoming aware of the breach. An organisation does not necessarily need to have completed its entire investigation before making an initial notification; further information can be provided as it becomes available.


This is why the early risk assessment matters. Reporting every incident unnecessarily is not the answer, but neither is delaying while waiting for perfect information.

We are a solicitor-led data protection organisation with over 25 years’ experience in privacy, data protection and commercial law.


We approach data breaches from both a legal and practical perspective. Our first priority is understanding what has happened and what needs to be done now, rather than assuming that every incident needs to be reported.


We work with internal stakeholders including HR, IT, security and senior management to assess the incident, document the organisation’s position and provide practical advice on notification, communications and remediation.


Our team’s previous experience includes work involving organisations such as WarnerMedia, Yum! Brands, Burberry, Expedia and Société Générale across a range of commercial environments.


Get help with a data breach

If you have discovered a personal data breach or are unsure whether an incident needs to be reported, speak directly with a data protection specialist. +44 (0)7976 939 016 (Mon – Fri: 9:00 am – 6:00 pm Sat: 10 – 4 pm).

Send us a short description of what has happened and when your organisation first became aware of it. We will let you know what information we need and the most appropriate next step.

Westbrook Data Protection Services Limited, 2nd Floor, Midas House, 62 Goldsworth Road Woking, Surrey, GU21 6LQ

Our team have a deep understanding of the following areas of law and continue to add value to our clients’ businesses.


Latest Insights