Home / Data Protection Guidance and Insights / Personal Data Breach Response: What UK Organisations Should Do in the First 72 Hours

Personal Data Breach Response: What UK Organisations Should Do in the First 72 Hours

Discovering a personal data breach creates immediate pressure. The first 72 hours should be used to contain the incident, establish reliable facts, assess the risk to individuals and decide whether notification is required.


This guidance explains the practical steps a UK organisation should take after discovering a suspected personal data breach. It is intended to help organisations structure their initial response and understand the decisions that may need to be made. It does not constitute legal advice.

What we see in practice

When we support an incident, the initial facts are usually incomplete. The most useful early work is to record the awareness time, stop continuing exposure, preserve evidence and give one person responsibility for the decision log. Waiting for a perfect account can leave less time for the risk assessment and any notification.


What counts as a personal data breach?

A personal data breach is a security incident that results in personal data being accidentally or unlawfully destroyed, lost, altered, disclosed or accessed. It is wider than hacking or theft and can involve confidentiality, availability or integrity.

  • sending personal information to the wrong recipient;
  • losing a laptop, phone, file or storage device containing personal data;
  • a cyberattack that gives an unauthorised person access to systems;
  • accidental deletion or corruption of information where it cannot be restored;
  • an employee accessing or using personal information without authority; or
  • personal information being unavailable when it is needed and that unavailability creates a risk to individuals.

Did you know? The clock does not necessarily start when the incident occurred

For a notifiable breach, the 72-hour period runs from when the organisation becomes aware that a personal data breach has occurred. Start an incident log immediately, even if you do not yet know whether notification will be required.


The first response: contain the incident and preserve evidence

The immediate priority is to prevent further loss, disclosure or misuse while preserving the information needed to investigate. The appropriate response will depend on the incident, but may include:

  • recalling or securing an email, document or shared link;
  • resetting credentials, disabling accounts or restricting access;
  • isolating affected equipment or systems with support from IT or cyber specialists;
  • recovering information from the unintended recipient and obtaining confirmation of deletion;
  • preserving relevant logs, messages and system records; and
  • notifying insurers, processors or other contractual partners where required.


Containment should not destroy evidence. Record each action, who authorised it and when it was completed.


Create a reliable incident record

The breach record should be updated as facts emerge. It should distinguish confirmed information from assumptions and record the reasoning behind important decisions.

  • when the incident occurred, when it was discovered and when the organisation became aware of the breach;
  • the systems, locations and organisations involved;
  • the categories and approximate volume of personal data affected;
  • the approximate number and types of people affected;
  • containment and recovery measures taken;
  • potential consequences for individuals;
  • the risk assessment and notification decision; and
  • the people responsible for the investigation and communications.


Assess the risk to individuals

The reporting decision is based primarily on the possible effect on the people whose information is involved, rather than only the commercial or reputational effect on the organisation. Consider both the seriousness of the possible harm and the likelihood that it will occur.

  • the sensitivity of the information, including health, financial, identity or criminal offence information;
  • whether the data was encrypted or otherwise protected;
  • whether the recipient is known and can be trusted to delete or return it;
  • the number and vulnerability of the people affected;
  • the risk of fraud, identity theft, discrimination, distress, loss of confidentiality or other harm; and
  • whether practical steps can reduce the likelihood or severity of that harm.


Deciding whether to notify the ICO

Where the notification threshold is met, the organisation must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach. The ICO’s personal data breach guidance explains the reporting requirements in more detail.


A notification should describe the nature of the breach, the categories and approximate numbers of affected people and records, the likely consequences, the measures taken or proposed, and an appropriate contact point. If the notification is late, the organisation must explain the delay.


What if the investigation is not complete?

Do not delay a required notification simply because every fact is not yet known. The ICO permits information to be supplied in phases. The initial notification should be as accurate as possible, explain what remains under investigation and be followed by updates when material facts become available.


When must affected individuals be told?

If the breach is likely to result in a high risk to individuals’ rights and freedoms, those individuals must normally be informed directly and without undue delay. The message should use clear language, explain what happened and the likely consequences, describe what the organisation is doing, and give practical steps the person can take to protect themselves.


Communications should be coordinated carefully. They should help people without causing unnecessary alarm, and should provide a contact point for questions or additional support.


After the first 72 hours

The end of the initial reporting period is not the end of the response. The organisation should continue to investigate, update its assessment and implement measures that reduce the risk of recurrence.

  • provide further information to the ICO where an initial notification was incomplete;
  • respond to questions from affected individuals and maintain consistent communications;
  • review whether processors, suppliers or insurers need further information;
  • complete a root-cause analysis;
  • update policies, technical controls and staff training; and
  • retain the breach record and evidence supporting the decisions made.


Common mistakes to avoid

  • waiting for a complete technical investigation before beginning the legal assessment;
  • focusing only on damage to the organisation rather than possible harm to individuals;
  • assuming that a breach is too small to document;
  • using the 72-hour period as a reason to delay a notification that could be made earlier;
  • telling affected people without giving useful protective advice; and
  • failing to record why the ICO or affected individuals were not notified.


Frequently asked questions

Does every personal data breach need to be reported to the ICO?

No. Notification is required where the breach is likely to result in a risk to individuals’ rights and freedoms. Every breach should nevertheless be recorded and assessed.


When does the 72-hour period start?

It starts when the organisation becomes aware that a personal data breach has occurred. This may be later than the date of the underlying incident, but organisations should investigate security incidents promptly.


Can we report before we know every detail?

Yes. If notification is required, available information can be provided initially and supplemented in phases. The organisation should explain what remains under investigation.


When do we have to tell affected individuals?

Individuals must normally be informed without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

What records should we keep if the breach is not reported?

Keep a record of what happened, the information and people affected, containment measures, the risk assessment, the notification decision and the reasons supporting that decision.


When should an organisation seek specialist advice?

Specialist support can be particularly valuable where sensitive information is involved, the facts are changing quickly, several organisations share responsibility, there is potential harm to vulnerable people, or the reporting threshold is difficult to apply. Early advice can help coordinate the legal, technical and communications workstreams.

Written by Clara Westbrook, solicitor and founder.


Speak to our team

This is a photo of alexander hazell, a data protection consultant at westbrook data protection services

Alexander Hazel

Consultant

Our team have a deep understanding of the following areas of law and continue to add value to our clients’ businesses.


Latest Insights