Blue abstract lines representing data breach response and ico support for data protection services in the uk.

Data Breach Response Services & ICO Support

Home / Services / Data Breach Response & ICO Support


If you’ve experienced a data breach, we’ll help assess the potential risks, determine what your organisation needs to do next and put practical measures in place to reduce the risk of a similar incident happening again.


Talk to us about specialist advice for data breach response & ICO support.


Not every data breach needs to be reported to the ICO, but every incident needs to be assessed properly. Where a breach is likely to result in a risk to individuals, the ICO must be notified without undue delay and, where feasible, within 72 hours of the organisation becoming aware of it.

Dealing with a personal data breach?
Download our one-page guide to the first 72 hours.
Download the breach guide →

Prompt action can limit further disclosure and preserve evidence. WDPS has dealt with breaches involving sensitive information emailed to the wrong recipient. Assessing the risk means establishing what was disclosed, who received it and what can be done to contain it.

A breach may only come to light long after it occurred. Where reporting is required, the ICO must be notified without undue delay and, where feasible, within 72 hours of the organisation becoming aware of the breach. An initial report can be supplemented as the investigation progresses.


What to expect from our data breach response service

The breaches we deal with vary considerably. Some breaches we deal with can be assessed and dealt with relatively quickly; others require mitigations to be implemented and ongoing monitoring to be put in place.

1

Initial breach assessment

2

Containment and evidence

3

Risk assessment

4

ICO notification decision

5

ICO and individual communications

6

Remediation and lessons learned

The scope depends on the nature and seriousness of the incident. Some organisations need an initial risk assessment and advice on notification, while others require end-to-end support with containment, evidence, ICO reporting, communications with affected individuals and remediation.

1. Establish what happened

We begin by gathering the available facts, including when the incident occurred, when your organisation became aware of it, what personal data is involved and who may have been affected. Where appropriate, we work alongside your IT, security or other relevant teams to mitigate the breach.


2. Assess the risk and reporting obligations

The assessment considers the possible consequences for the people affected and how likely those consequences are. WDPS advises on whether notification is required and records the reasons for that conclusion, including where the decision is not to report.

3. Manage the response

Where notification is required, we can help prepare the ICO report and communications to affected individuals. We also document the decision-making process and identify practical remedial measures following the incident.


What are the benefits of getting breach advice early?

Early specialist advice can help your organisation contain the incident, and reduce the risk of individuals data being compromised further. Where organisations fail to act appropriately they can face serious fines and may have to provide credit monitoring to those affected which can add additional costs the organisation.

Do all data breaches need to be reported to the ICO?

No. An email-address disclosure is not automatically low risk. For example, a visible recipient list may reveal that someone uses a specialist health service. The assessment depends on what was disclosed, who received it and the possible consequences for the people affected.


Under the UK GDPR, a personal data breach must be reported to the ICO unless it is unlikely to result in a risk to individuals’ rights and freedoms. Where a breach is likely to result in a high risk, the people affected must generally also be informed without undue delay.WDPS can assess both notification obligations and record the reasons for the decisions made.

With more than 25 years’ experience in data protection and privacy, we’ve dealt with breaches ranging from information being sent to the wrong person through to incidents requiring assessment and notification to the ICO.


We work with HR, IT, security and senior management to establish what happened, assess the risk to those affected and determine what needs to be done.


Our experience means we can help you make an initial assessment, document the decisions made and review the position as further information becomes available.


Get help with a data breach

If you have discovered a personal data breach or are unsure whether an incident needs to be reported, speak directly with a data protection specialist. +44 (0)7976 939 016 (Mon – Fri: 9:00 am – 6:00 pm Sat: 10 – 4 pm).

Send us a short description of what has happened and when your organisation first became aware of it. We will let you know what information we need and the most appropriate next step.

Westbrook Data Protection Services Limited, 2nd Floor, Midas House, 62 Goldsworth Road Woking, Surrey, GU21 6LQ

Our team have a deep understanding of the following areas of law and continue to add value to our clients’ businesses.


Latest Insights