
Specialist advice for Data Breach Response & ICO Support
We provide specialist solicitor-led Data Breach Response & ICO Support
When a data breach happens, we help assess the potential risks, determine what your organisation needs to do next and put practical measures in place to reduce the risk of a similar incident happening again.
Personal Data Breach Response and ICO Support for UK Organisations
The first few hours matter. You may still be gathering information, but you should start recording what happened, contain the incident where possible and assess the potential impact on the individuals involved. If the breach meets the reporting threshold, the 72-hour reporting period runs from when your organisation becomes aware of it.
Read the ICO guidance on responding to a personal data breach →
Not every data breach needs to be reported to the ICO, but every incident needs to be assessed properly. Where a breach is likely to result in a risk to individuals, the ICO must be notified without undue delay and, where feasible, within 72 hours of the organisation becoming aware of it.
Dealing with a personal data breach?
Download our one-page guide to the first 72 hours.
Download the breach guide →

Clara Westbrook
25+ Years PQE
Founder | Qualified Solicitor | Data Protection Specialist
07976 939 016
Why does acting quickly matter?
Data breaches can develop quickly. An incorrectly sent email may initially involve one recipient but contain sensitive information about several people. A compromised mailbox may expose more information the longer access continues. A lost device may create very different risks depending on whether it is encrypted and can be remotely disabled.
Early action gives the organisation more time to contain the incident, preserve evidence, assess the level of risk and make a considered decision about ICO notification and communications with affected individuals.
Where a breach is likely to result in a high risk to individuals, those people must also be informed without undue delay.
What to expect from our data breach response service
We provide support from the initial assessment through to ICO notification, communications and post-incident remediation. The level of support will depend on the nature and seriousness of the incident.
1
Initial breach assessment
2
Containment and evidence
3
Risk assessment
4
ICO notification decision
5
ICO and individual communications
6
Remediation and lessons learned
The scope depends on the nature and seriousness of the incident. Some organisations need an initial risk assessment and advice on notification, while others require end-to-end support with containment, evidence, ICO reporting, communications with affected individuals and remediation.
How our data breach response service works
1. Establish what happened
We begin by gathering the available facts, including when the incident occurred, when your organisation became aware of it, what personal data is involved and who may have been affected. Where appropriate, we work alongside your IT, security or other relevant teams.
2. Assess the risk and reporting obligations
We assess the likely impact on individuals and advise whether the breach reaches the threshold for notification to the ICO. Where the risk is high, we also consider whether affected individuals need to be informed. The ICO confirms that not every personal data breach requires notification; the decision depends on the likelihood of risk to people’s rights and freedoms.
3. Manage the response
Where notification is required, we can help prepare the ICO report and communications to affected individuals. We also document the decision-making process and identify practical remedial measures following the incident.
What are the benefits of getting breach advice early?
Early specialist advice can help your organisation contain the incident, reach a defensible notification decision and preserve a clear record of the response.
1. Faster decision-making
Establish quickly what the organisation needs to do and who needs to be involved.
2. Defensible reporting decisions
Keep a clear record of why the incident was or was not reported and the information relied upon.
3. Reduced future risk
Identify the cause of the incident and practical improvements to processes, training or controls.
Do all data breaches need to be reported to the ICO?
No. A personal data breach needs to be reported to the ICO where it is likely to result in a risk to the rights and freedoms of individuals. If the organisation concludes that a risk is unlikely, notification is not required, but the decision should still be documented.
Where notification is required, it must be made without undue delay and, where feasible, within 72 hours of becoming aware of the breach. An organisation does not necessarily need to have completed its entire investigation before making an initial notification; further information can be provided as it becomes available.
This is why the early risk assessment matters. Reporting every incident unnecessarily is not the answer, but neither is delaying while waiting for perfect information.
Why choose us
We are a solicitor-led data protection organisation with over 25 years’ experience in privacy, data protection and commercial law.
We approach data breaches from both a legal and practical perspective. Our first priority is understanding what has happened and what needs to be done now, rather than assuming that every incident needs to be reported.
We work with internal stakeholders including HR, IT, security and senior management to assess the incident, document the organisation’s position and provide practical advice on notification, communications and remediation.
Our team’s previous experience includes work involving organisations such as WarnerMedia, Yum! Brands, Burberry, Expedia and Société Générale across a range of commercial environments.
Get help with a data breach
If you have discovered a personal data breach or are unsure whether an incident needs to be reported, speak directly with a data protection specialist. +44 (0)7976 939 016 (Mon – Fri: 9:00 am – 6:00 pm Sat: 10 – 4 pm).
Send us a short description of what has happened and when your organisation first became aware of it. We will let you know what information we need and the most appropriate next step.
Westbrook Data Protection Services Limited, 2nd Floor, Midas House, 62 Goldsworth Road Woking, Surrey, GU21 6LQ
View our Privacy Policy here
Related guidance
Read Personal Data Breach Response: What UK Organisations Should Do in the First 72 Hours → for practical steps on containment, risk assessment, ICO notification and communicating with affected individuals.
Explore More Data Protection & Privacy Services
Our team have a deep understanding of the following areas of law and continue to add value to our clients’ businesses.
Latest Insights
- The GDPR Accountability Principle: From Paper to PracticeAccountability principle As a new consultant at Westbrook Data Protection Services, one of the first […]
- Changes to employment law and the rise in Data Subject Access RequestsChanges to employment law and the rise in Data Subject Access Requests Employment Rights Act […]



