‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.legislation.gov.uk — Regulation (EU) 2016/679 as retained in UK law
Duty
to Act
What counts as an incident under UK law, what you must do about it, who you must tell, and how long you have. Built on the statute, and on what actually happened to UK organisations in 2026.
This course is written for two audiences at once: people running or advising a business, and people working in or for a local authority. The statutory duties are largely the same. Where they diverge — law enforcement processing, freedom of information, sector assurance frameworks — the difference is called out.
Every legal provision quoted here is reproduced from the legislation itself, with the exact citation in the margin. Where something is not yet law, it says so.
What actually counts as an incident
Most people picture a hacker. The law pictures something far broader, and that gap is where organisations get caught out.
The starting definition sits in Article 4 of the UK GDPR. It is deliberately wide, and it does not mention attackers at all.
Read it again slowly. Accidental is in there. Destruction and loss are in there — you do not need anyone to have read the data. And it is a breach of security, not a breach of a firewall.
The three kinds
The ICO groups breaches into three types, and it is useful to name them because people routinely miss the second and third:
| Type | What has gone wrong | Everyday example |
|---|---|---|
| Confidentiality | Unauthorised or accidental disclosure of, or access to, personal data | An email sent to the wrong recipient; a caseworker looking up a neighbour's record |
| Integrity | Unauthorised or accidental alteration of personal data | A records import that overwrites the wrong fields |
| Availability | Accidental or unauthorised loss of access to, or destruction of, personal data | Ransomware encrypting a case management system; a deletion with no working backup |
An availability breach is the one that surprises people. If ransomware locks your systems and the attacker never exfiltrates a single record, you have still suffered a personal data breach, because the people whose data it is have lost the benefit of it and you have lost control of it.
Incident, breach, near miss
These three words are not interchangeable, and using them loosely in an incident log will cost you later:
- Security incident — anything that threatens the confidentiality, integrity or availability of your systems or information. A phishing email that nobody clicked is an incident.
- Personal data breach — an incident that meets the Article 4(12) definition. This is the one that starts a statutory clock.
- Near miss — an incident that could have become a breach but did not. Not notifiable, but it belongs in your log, because a pattern of near misses is exactly the evidence a regulator uses to show you knew about a weakness.
Manchester Airports Group
MAG, which runs Manchester, London Stansted and East Midlands airports, confirmed that an unauthorised third party had obtained customer data relating to car park, lounge and Fast Track bookings and in-airport Wi-Fi sign-ups. The data included email addresses, phone numbers, vehicle registration numbers and postcodes. Neither MAG nor the affected system held bank or payment details.
MAG said it contained the risk immediately, restricted access to affected systems, engaged specialist cybersecurity advisers, notified the relevant authorities, and emailed affected customers directly. It suspended its online Manage My Booking service as a precaution while leaving existing bookings valid.
Why it matters here: no payment data, no operational disruption, no safety impact — and it is still unambiguously a personal data breach. Vehicle registration numbers and postcodes together are personal data. The absence of financial data changes the risk assessment, not whether the duty is engaged.
Companies House
A logic and session-handling flaw in the WebFiling service meant a user holding any valid login could file for another company — exposing personal data of directors and officers across around 5 million registered UK businesses. The flaw was introduced in October 2025 during migration to GOV.UK One Login and was live for roughly five months before discovery on 13 March 2026. Companies House suspended WebFiling and self-reported to both the ICO and the NCSC.
No attacker. No malware. A design flaw introduced by a routine platform migration, and still a personal data breach. Change is a breach vector.
Which law is pointing at you
One incident can trigger three or four separate reporting duties to three or four separate regulators, on different clocks. Knowing which apply to you is a job to do before anything happens, not during.
The core: everyone holding personal data
Two instruments do the heavy lifting for every UK organisation. The UK GDPR — Regulation (EU) 2016/679 as retained and amended in UK law — sets the principles, the security duty and the reporting duties. The Data Protection Act 2018 supplies the UK-specific machinery: exemptions, the ICO's enforcement powers, criminal offences, and a separate regime in Part 3 for law enforcement processing.
The security principle sits at the top of the UK GDPR and everything in Module 03 flows from it:
Personal data shall be … processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).legislation.gov.uk — UK GDPR, Chapter II
Article 5(2) then adds the accountability principle: the controller is responsible for compliance and must be able to demonstrate it. That second half is the one that decides enforcement outcomes.
The sector and service layers
| Instrument | Who it catches | The duty |
|---|---|---|
| PECR 2003, reg. 5A | Providers of a public electronic communications service — telecoms operators, ISPs | Notify ICO within 72 hours. No risk threshold: every breach is notifiable |
| NIS Regulations 2018, reg. 11 | Operators of essential services — energy, transport, water, health, digital infrastructure | Notify the competent authority within 72 hours of an incident with significant impact |
| NIS Regulations 2018, reg. 12 | Relevant digital service providers — online marketplaces, search engines, cloud services | Notify the ICO |
| Communications Act 2003, s.105K | Public electronic communications networks and services | Security compromise report to Ofcom |
| FOIA 2000 | Public authorities, including local authorities | Incident information may be requested; exemptions must be justified, not assumed |
| DPA 2018, Part 3 | Competent authorities processing for law enforcement purposes | Separate breach regime under s.67–s.68 |
The PECR change catches people out. Section 111 of the Data (Use and Access) Act 2025 replaced the old 24-hour telecoms clock with 72 hours, in force from 20 August 2025. Any internal policy or supplier contract still citing 24 hours under PECR is out of date. Note that regulation 5A still has no risk threshold — unlike the UK GDPR, every personal data breach connected with the service is notifiable, and regulation 5C sets a fixed monetary penalty of £1,000 for failing to notify.
The criminal layer
Two statutes matter here, and they point in opposite directions — one at the attacker, one potentially at you.
A person is guilty of an offence if— (a) he causes a computer to perform any function with intent to secure access to any program or data held in any computer, or to enable any such access to be secured; (b) the access he intends to secure, or to enable to be secured, is unauthorised; and (c) he knows at the time when he causes the computer to perform the function that that is the case.legislation.gov.uk — Computer Misuse Act 1990, Part I
Sections 2 and 3 escalate this to unauthorised access with intent to commit further offences, and unauthorised acts intended to impair the operation of a computer. Section 3ZA covers unauthorised acts causing, or creating a risk of, serious damage. This is the law under which UK attackers are prosecuted — and in July 2026 two men were sentenced to five years six months for the September 2024 attack on Transport for London, which disrupted Live Tube arrivals and Oyster photocard applications and exposed personal data for around 5,000 customers including bank details.
Pointing the other way, the Data Protection Act 2018 creates offences that can catch your own staff, and your organisation's conduct during an investigation:
It is an offence for a person knowingly or recklessly— (a) to obtain or disclose personal data without the consent of the controller, (b) to procure the disclosure of personal data to another person without the consent of the controller, or (c) after obtaining personal data, to retain it without the consent of the person who was the controller in relation to the personal data when it was obtained.legislation.gov.uk — Data Protection Act 2018, Part 6
This is the provision behind prosecutions of employees who look up records they have no business reason to see — a recurring issue in local authority social care and in policing. Separately, section 148 makes it an offence to destroy, dispose of, conceal, block or falsify information or documents that the Commissioner has required, with intent to prevent the ICO from seeing them. Nobody should be tidying up logs after an incident.
What is coming, and is not law yet
The Cyber Security and Resilience Bill is the most significant reform of UK cyber regulation since the NIS Regulations 2018. It amends rather than replaces them, pulls managed service providers and data centres into scope, and introduces a tighter two-stage reporting regime with a 24-hour initial notification alongside turnover-linked penalties.
Where it stands: introduced to the Commons on 12 November 2025, second reading 6 January 2026, all Commons stages completed 16 June 2026, introduced to the Lords on 17 June 2026, Lords second reading 14 July 2026, Committee stage from 1 September 2026. Royal Assent is expected in late 2026, with obligations phased in through secondary legislation potentially running to 2028.
Article 32 and the anatomy of a security failure
Every flagship UK data protection fine from 2024 to 2026 has been an Article 32 security case, not a privacy-policy case. This is the provision that decides whether a breach becomes a penalty.
Security of processing
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:
- the pseudonymisation and encryption of personal data;
- the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
- the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;
- a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.
Reading it properly
Four things in that text do real work, and each is regularly misread:
- "appropriate … to the risk" — this is not a checklist. There is no fixed list of controls that makes you compliant. The standard is proportionate to the risk your processing creates for people. A council holding social care records is held to a different standard than a shop holding a mailing list, on identical budgets.
- "the controller and the processor" — the duty falls on both. Your supplier is not off the hook because you are the controller, and you are not off the hook because your supplier holds the data.
- "the costs of implementation" — cost is a permitted consideration. It is not a permitted excuse. Regulators consistently find against organisations that priced a control and then never bought it.
- Paragraph (d) — the meta-measure. It is not enough to have controls; you must have a process for regularly testing, assessing and evaluating whether they work. An untested backup is not a restore capability.
Article 32(2) then tells you what to weigh when deciding what is appropriate:
In assessing the appropriate level of security account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.legislation.gov.uk — UK GDPR, Article 32
Article 32(4) closes a gap people forget: the controller and processor must take steps to ensure that anyone acting under their authority who has access to personal data does not process it except on instructions. That is the insider-access limb — access control, need-to-know, and audit trails on staff activity, not just perimeter security.
South Staffordshire Plc and South Staffordshire Water Plc — £963,900
The ICO fined the companies £963,900 following a Cl0p ransomware attack. The personal information of 633,887 people was published on the dark web in August 2022, including full names, physical addresses, email addresses, dates of birth, gender and telephone numbers.
The timeline: initial access in September 2020 when an employee opened a malicious email attachment. The attackers remained undetected until May 2022, when they began moving across systems using a domain administrator account. The company only identified the intrusion in July 2022, after investigating widespread IT performance problems. Two weeks later staff found a ransom note.
The ICO's findings on the security failings map almost line by line onto Article 32:
- No routine vulnerability scanning — a failure of 32(1)(d), the testing process
- Continued use of Windows Server 2003, unsupported for years — a failure of 32(1)(b), ongoing resilience
- Failure to patch ZeroLogon, a critical flaw publicly disclosed in 2020 — a known, published, unaddressed risk
- By late 2021, an outsourced security operations centre monitoring only 5% of the IT environment — a control that existed on paper across a twentieth of the estate
Ian Hulme, the ICO's interim executive director for regulatory supervision, made the point that customers cannot choose their water company — they are required to share their personal information and place their trust in that provider. Twenty months of undetected access, discovered by accident through performance complaints, and a fine landing nearly six years after initial access.
What non-compliance costs
Article 83 sets two tiers. Infringements of Articles 25 to 39 — which includes Article 32 and Article 33 — sit in the lower tier: up to £8.7 million or 2% of total worldwide annual turnover, whichever is higher. Infringements of the basic principles in Article 5, which includes the security principle at 5(1)(f), sit in the higher tier: up to £17.5 million or 4%.
In practice the ICO's largest security penalty to date is £14 million against Capita plc and Capita Pension Solutions, issued 15 October 2025 and reduced from a proposed £45 million through a settlement in which Capita waived its right to appeal. The root cause the ICO identified was narrow and instructive: a 58-hour delay in quarantining an infected device after a high-priority security alert had been raised within ten minutes. Personal data belonging to 6.6 million people was exposed.
The clock: what you must do, and when
Seventy-two hours is the number everyone knows. Almost nobody can say when it starts, what it is a deadline for, or what happens if you miss it.
Notification to the Commissioner
In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the Commissioner, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the Commissioner is not made within 72 hours, it shall be accompanied by reasons for the delay.legislation.gov.uk — UK GDPR, Article 33
Four things that sentence actually says
- "without undue delay and" — 72 hours is a backstop, not an allowance. If you could reasonably have reported on day one, reporting on day three is still undue delay.
- "after having become aware of it" — the clock starts at awareness, not at the incident. The ICO treats awareness as the point at which you have a reasonable degree of certainty that a security incident has occurred and compromised personal data. Not the point at which you have every detail.
- "unless … unlikely to result in a risk" — this is the threshold. Note the double negative: the test is not "is there a risk?" but "is a risk unlikely?" If you cannot say it is unlikely, you report.
- "accompanied by reasons for the delay" — late reporting is provided for. It is not forgiven, but a late report with reasons is far better than no report.
The 72 hours run on calendar time, including weekends and bank holidays. A breach discovered at 4pm on the Friday before a bank holiday expires on the Monday.
Clock starts. Log the date and time you found out, who is involved and what you know. Preserve evidence — do not delete or overwrite logs. Begin containment.
Contain what you can. Assess severity and likelihood of harm to individuals: identity theft, financial loss, safeguarding risk, distress. Decide whether the risk is unlikely.
Confirm the notification decision and who else must be told: NCSC, Action Fraud, competent authority under NIS, Ofcom, insurers, affected controllers if you are a processor.
Report to the ICO if notifiable, using the Article 33(3) content. If you cannot supply everything, report anyway in phases under Article 33(4), with reasons for any delay.
What must be in the report
Article 33(3) sets the minimum content, and it is worth knowing because it shapes what your incident log needs to capture from hour zero:
The notification referred to in paragraph 1 shall at least:
- describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
- describe the likely consequences of the personal data breach;
- describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
You are not expected to have finished investigating. Article 33(4) permits phased reporting: where it is not possible to provide the information at the same time, it may be provided in phases without undue further delay. The ICO's own guidance is explicit that it expects controllers to prioritise the investigation, resource it adequately and expedite it urgently — and to explain the delay and say when more will follow.
The duty that applies even when you don't report
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the Commissioner to verify compliance with this Article.legislation.gov.uk — UK GDPR, Article 33
Any personal data breach. Not the notifiable ones — all of them. If you assess a breach as not notifiable, the reasoning behind that decision is exactly what the last sentence exists to let the Commissioner check. A breach register with no entries is not evidence of a clean record; to a regulator it reads as evidence that nothing is being detected or assessed.
If you are a processor
Article 33(2) is one sentence: the processor must notify the controller without undue delay after becoming aware of a personal data breach. There is no 72-hour figure attached to the processor — the reporting duty to the ICO stays with the controller. Which means your Article 28 contract has to set the processor's timescale, because the statute does not.
Parallel clocks
- NIS Regulations 2018, reg. 11 — operators of essential services notify their designated competent authority without undue delay and in any event no later than 72 hours after becoming aware of an incident with a significant impact on continuity of the essential service. Relevant digital service providers report to the ICO under reg. 12.
- PECR reg. 5A — 72 hours since 20 August 2025, no risk threshold, and the ICO states that PECR reporting takes the place of the UK GDPR reporting process for those providers.
- Communications Act 2003, s.105K — security compromise reports to Ofcom for public electronic communications networks and services.
- NCSC — reporting a significant cyber incident is not a statutory duty for most organisations, but it brings support and is expected of critical national infrastructure. In the year to May 2026 the NCSC managed more than 200 incidents affecting UK CNI and its supply ecosystem, around 75% linked to hostile state actors.
Department for Education, and the Police National Legal Database
The DfE confirmed a security incident affecting its online Customer Help Portal and the Turing Scheme portal after claims appeared over the weekend of 25 and 26 July 2026. Its official notice says affected data could include names, job titles, email addresses, phone numbers and business addresses submitted through those services. The Department temporarily took both portals offline, remediated the vulnerability and notified the ICO. The DfE notice does not confirm a final number of affected records or identify the attacker.
Weeks later the Police National Legal Database was hit by the same group, leaking names, organisations and email addresses of more than 100,000 police officers, staff and criminal justice professionals. PNLD notified the ICO and worked with the National Crime Agency and specialist cybersecurity organisations.
Both went to the regulator promptly and named the law enforcement bodies they were working with. Neither had full victim counts at the point of disclosure — and neither waited for one. That is Article 33(4) working as designed.
Telling the people it happened to
Notifying the regulator and notifying individuals are two separate decisions, on two different thresholds. Organisations routinely confuse them in both directions.
Communication to the data subject
When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.legislation.gov.uk — UK GDPR, Article 34
Two thresholds, not one
| Tell the ICO | Tell the individuals | |
|---|---|---|
| Provision | Article 33(1) | Article 34(1) |
| Threshold | Unless a risk is unlikely | Where a high risk is likely |
| Deadline | Without undue delay, within 72 hours where feasible | Without undue delay — no fixed hours |
So there is a middle band: breaches you must report to the ICO but need not communicate to individuals. That band is large, and treating every reportable breach as requiring mass notification causes real harm — it exhausts people's attention and dilutes the warnings that matter.
What the message must contain
Article 34(2) requires the communication to describe, in clear and plain language, the nature of the personal data breach, and to provide at least the information listed in points (b), (c) and (d) of Article 33(3) — the contact point, the likely consequences, and the measures taken or proposed, including measures to mitigate adverse effects.
"Clear and plain language" is a legal requirement, not a communications preference. A notification written to minimise reputational damage rather than to help people protect themselves does not satisfy Article 34.
When you don't have to tell individuals
Article 34(3) sets out three exceptions. Communication is not required if:
- You had implemented appropriate technical and organisational protection measures and applied them to the affected data — in particular measures that render the data unintelligible to anyone not authorised to access it, such as encryption;
- You have taken subsequent measures which ensure the high risk is no longer likely to materialise;
- It would involve disproportionate effort — in which case there must instead be a public communication or similar measure by which the data subjects are informed in an equally effective manner.
Note the shape of the first exception. Encryption does not stop a breach being a breach, and it does not remove the Article 33 duty to consider reporting to the ICO. What it can do is remove the Article 34 duty to tell individuals, because the data is unintelligible to whoever now holds it. That is one of the strongest practical arguments for encrypting data at rest.
Article 34(4) adds a backstop: if you have not communicated the breach to individuals, the Commissioner may require you to do so, or may decide that one of the exceptions applies. The decision is not finally yours.
Manchester Airports Group
MAG contacted affected customers directly by email. The message stated plainly what had happened, identified the specific data accessed — email addresses, phone numbers, vehicle registration numbers and postcodes — and stated clearly that neither MAG nor the affected system held bank or payment details.
It then did the thing Article 34(2)(d) is for: it told people what to do. Remain alert for suspicious emails, text messages and phone calls; avoid clicking links or opening unexpected attachments. It confirmed that existing bookings remained valid and that no action was needed on those, and explained that the online Manage My Booking service had been suspended as a precaution, directing anyone needing changes within 72 hours to the customer services team.
Why this is a good model: it separates what people must do from what they need not do. Most breach notifications fail on the second half — they alarm without directing, and leave every recipient to work out for themselves whether they are in danger. The likely consequence here is targeted phishing using real travel details, and the letter names it.
When it wasn't you — it was your supplier
Across UK incidents in 2026, the single most common entry point was not the breached organisation's own systems. It was somebody they had contracted with.
This does not divide the duty. It multiplies it. Article 32 binds controller and processor alike, and Article 24 puts the burden of proof on you:
Responsibility of the controller
Taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation. Those measures shall be reviewed and updated where necessary.legislation.gov.uk — UK GDPR, Article 24
"To be able to demonstrate" is the operative phrase. You cannot demonstrate a supplier's security by having once received a completed questionnaire.
What Article 28 requires in the contract
Article 28(1) sets the selection duty: a controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures. Article 28(3) then requires a written contract that, among other things, binds the processor to:
- process only on documented instructions from the controller;
- ensure persons authorised to process the data are under an appropriate duty of confidentiality;
- take all measures required by Article 32;
- not engage a sub-processor without prior specific or general written authorisation;
- assist the controller in ensuring compliance with Articles 32 to 36 — which expressly includes breach notification;
- make available all information necessary to demonstrate compliance, and allow for and contribute to audits, including inspections.
The audit right is the one most often written in and never exercised. An unexercised audit right is not evidence of oversight.
The gap the statute leaves you to close
Article 33(2) requires the processor to notify the controller "without undue delay" — with no hours attached. Your 72-hour clock, meanwhile, generally runs from when you become aware. So the practical exposure is the space between your supplier knowing and you knowing. The statute does not close that gap. Your Article 28 contract has to, with a specific figure — 24 hours is common — and a named contact who is reachable outside office hours.
One supplier, many victims
Group GTI / CareerConnect, May–June 2026. The careers platform was breached on 28 May, exposing first and last names, email addresses and encrypted passwords for users not signing in through Single Sign-On. Oxford disclosed; the same platform is used by King's College London and the University of Manchester. One supplier compromise, multiple institutions notifying at once.
CEVA Logistics, August 2026. A breach at the shipping and logistics giant put customer names, home addresses, phone numbers and email addresses at risk across organisations that had no relationship with each other — Dutch retailer Bol, De Bijenkorf, football club Ajax, ING, Ace & Tate, Valve, and Pokémon Center customers in the UK and Germany, notified separately weeks later. Trezor's customers were exposed through a different logistics provider, ShipMonk, in the same period.
Synnovis, June 2024 to June 2026. The Qilin ransomware attack on the NHS pathology provider was still generating patient notifications two years later — around 35,000 records across Bedfordshire and Essex trusts, following an 18-month forensic review, with a court injunction in place and NCSC support ongoing. Both trusts notified the ICO.
The Synnovis case is the one to sit with. Two years after an attack on a supplier, individual NHS trusts were still writing to patients and still notifying the regulator. A supplier incident does not end when the supplier says it has ended.
Five questions to ask before you sign
- How quickly, in hours, will you notify us of a personal data breach affecting our data — and who makes that call at your end, out of hours?
- Who are your sub-processors, and how will we be told when that list changes?
- When were your restore procedures last tested end to end, and can we see the result?
- What would you actually give us within 24 hours of an incident, so we can meet our own Article 33(3) duty?
- Will you accept an audit or inspection, and when was the last one you underwent?
Holding the standard between incidents
The regulator does not assess you on the day of the breach. It assesses the years before it. Nearly everything that determines the outcome is decided while nothing is happening.
What the ICO actually looks for
Read across the enforcement record and a consistent pattern emerges. In every major UK security case, the finding was not that the organisation lacked a security team or a budget. It was one of four things:
| Finding | Where it showed up |
|---|---|
| A known risk left unaddressed | South Staffordshire: ZeroLogon, publicly disclosed in 2020, unpatched. The Legal Aid Agency had rated its cyberattack risk "extremely high" on its own register since 2021, and the Ministry of Justice had spent £50m on improvements there before the breach still happened. |
| A control that existed on paper only | South Staffordshire: an outsourced SOC monitoring 5% of the estate |
| Detection without response | Capita: a high-priority alert raised within ten minutes, the infected device not quarantined for 58 hours |
| Legacy systems nobody owned | South Staffordshire: Windows Server 2003, years past support |
None of those is a sophisticated attack. All four are visible from inside the organisation, in advance, for free.
Five things to be able to produce on demand
- A breach register with entries in it — Article 33(5) requires documentation of any personal data breach, including the ones you decided not to report and why. The ICO publishes a log template; use it or something better.
- An incident response plan that names people, not roles — with out-of-hours contacts for your DPO or equivalent, your processors, your insurers and your regulator, and with the first action being preserve evidence and start the clock.
- Evidence that you test — Article 32(1)(d) requires a process for regularly testing, assessing and evaluating effectiveness. Restore tests with dates and outcomes. Tabletop exercises with a written debrief.
- A current record of processing and suppliers — you cannot notify within 72 hours if it takes two days to establish whose data was in the affected system.
- A decision trail on risk — where you accepted a risk, the note saying who accepted it, on what basis, and when it is due for review. An accepted risk with a name against it is a defensible position; an unaccepted risk that nobody looked at is not.
Frameworks worth mapping to
- Cyber Essentials — the government's baseline, five controls. Not a statutory requirement for most organisations, but it is the floor that suppliers are increasingly asked to certify against, and it is a reasonable answer to "what did you do?"
- NCSC Cyber Assessment Framework (CAF) — the outcome-based framework used across critical national infrastructure and now in local government assurance. The Cyber Security and Resilience Bill is expected to put the CAF on a statutory footing for in-scope organisations.
- ISO/IEC 27001 — a management system rather than a control list. Article 32(3) expressly notes that adherence to an approved code of conduct or certification mechanism may be used as an element to demonstrate compliance. Note the wording: an element. Certification is evidence, not a defence.
Where this is heading
Three changes are already fixed or close to it. The Data (Use and Access) Act 2025 is being commenced in stages: document-notice powers commenced two months after Royal Assent, while specified data-protection and PECR enforcement provisions commenced on 5 February 2026. The ICO applied a 40% settlement reduction in the South Staffordshire case; its draft enforcement procedural guidance proposes tiered discounts of 40%, 30% and 20% depending on when a case settles. And the Cyber Security and Resilience Bill, expected to receive Royal Assent in late 2026, brings a 24-hour initial notification duty for in-scope organisations, phased in through secondary legislation to around 2028.
The through-line across all three is the same: less tolerance for delay, more weight on evidence, and a shorter gap between knowing and acting.
The five things worth keeping
- A breach is wider than a hack. Article 4(12) covers accidental destruction, loss and alteration, not just unauthorised access. Ransomware with no exfiltration is still a breach.
- The clock starts at awareness — reasonable certainty that a security incident has occurred and compromised personal data — and runs on calendar time. Seventy-two hours is a backstop, not an allowance.
- Report on time and incomplete, rather than late and complete. Article 33(4) exists for exactly this.
- Document everything, including what you decided not to report. Article 33(5) applies to any breach, and your reasoning is what the Commissioner will ask to see.
- Article 32 is judged on the years before the breach. Known risks, paper controls, detection without response, and unowned legacy systems are what enforcement actually turns on.
Legislation cited in this course
- UK GDPR — Articles 4(12), 5(1)(f), 5(2), 24, 28, 32, 33, 34, 83
- Data Protection Act 2018 — Part 3 (law enforcement processing), s.148, s.170
- Privacy and Electronic Communications (EC Directive) Regulations 2003 — regs. 5A, 5C
- Network and Information Systems Regulations 2018 — regs. 11, 12
- Communications Act 2003 — s.105K
- Computer Misuse Act 1990 — ss. 1, 2, 3, 3ZA
- Freedom of Information Act 2000 — including ss. 31, 43
- Data (Use and Access) Act 2025 — s.111 (PECR breach notification timescale, in force 20 August 2025); further specified data-protection and PECR enforcement provisions commenced 5 February 2026
- Accounts and Audit Regulations 2015 — internal control and risk management (local authorities)
- Cyber Security and Resilience Bill — before Parliament, not yet law
Where to go next
- ICO — report a breach, and the personal data breach guidance and log template: ico.org.uk/for-organisations/report-a-breach
- ICO — enforcement action taken, including every published penalty notice: ico.org.uk/action-weve-taken/enforcement-action
- ICO — South Staffordshire cyber attack and £963,900 fine: ICO enforcement report
- Department for Education — Customer Help Portal and Turing Scheme incident: DfE incident notice
- UK Parliament — Cyber Security and Resilience (Network and Information Systems) Bill: Bill stages and documents
- GOV.UK — Cyber Security Breaches Survey 2025/2026: official survey
- NCSC — incident reporting, the Cyber Assessment Framework and Cyber Essentials: ncsc.gov.uk
- legislation.gov.uk — the full text of every provision quoted here: legislation.gov.uk