Duty to Act · Orvanta Open College
Start
← Back to Short Course Library
Awareness course · approx. 60 minutes · 7 modules

Duty
to Act

What counts as an incident under UK law, what you must do about it, who you must tell, and how long you have. Built on the statute, and on what actually happened to UK organisations in 2026.

72hours to notify the ICO of a notifiable personal data breach
£17.5mor 4% of worldwide turnover — the higher UK GDPR penalty tier
43%of UK businesses identified a breach or attack in the last 12 months
£963,900fined to one UK water company in May 2026 for Article 32 failings

This course is written for two audiences at once: people running or advising a business, and people working in or for a local authority. The statutory duties are largely the same. Where they diverge — law enforcement processing, freedom of information, sector assurance frameworks — the difference is called out.

Every legal provision quoted here is reproduced from the legislation itself, with the exact citation in the margin. Where something is not yet law, it says so.

There is no assessment or certificate attached to this course. Each module ends with a knowledge check so you can test your recall as you go. Your answers are not recorded anywhere.
Module 01 — of seven

What actually counts as an incident

Most people picture a hacker. The law pictures something far broader, and that gap is where organisations get caught out.

The starting definition sits in Article 4 of the UK GDPR. It is deliberately wide, and it does not mention attackers at all.

Art. 4(12) UK GDPR
‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed. legislation.gov.uk — Regulation (EU) 2016/679 as retained in UK law

Read it again slowly. Accidental is in there. Destruction and loss are in there — you do not need anyone to have read the data. And it is a breach of security, not a breach of a firewall.

The three kinds

The ICO groups breaches into three types, and it is useful to name them because people routinely miss the second and third:

TypeWhat has gone wrongEveryday example
ConfidentialityUnauthorised or accidental disclosure of, or access to, personal dataAn email sent to the wrong recipient; a caseworker looking up a neighbour's record
IntegrityUnauthorised or accidental alteration of personal dataA records import that overwrites the wrong fields
AvailabilityAccidental or unauthorised loss of access to, or destruction of, personal dataRansomware encrypting a case management system; a deletion with no working backup

An availability breach is the one that surprises people. If ransomware locks your systems and the attacker never exfiltrates a single record, you have still suffered a personal data breach, because the people whose data it is have lost the benefit of it and you have lost control of it.

Incident, breach, near miss

These three words are not interchangeable, and using them loosely in an incident log will cost you later:

Case · 27 August 2026
Manchester Airports Group

MAG, which runs Manchester, London Stansted and East Midlands airports, confirmed that an unauthorised third party had obtained customer data relating to car park, lounge and Fast Track bookings and in-airport Wi-Fi sign-ups. The data included email addresses, phone numbers, vehicle registration numbers and postcodes. Neither MAG nor the affected system held bank or payment details.

MAG said it contained the risk immediately, restricted access to affected systems, engaged specialist cybersecurity advisers, notified the relevant authorities, and emailed affected customers directly. It suspended its online Manage My Booking service as a precaution while leaving existing bookings valid.

Why it matters here: no payment data, no operational disruption, no safety impact — and it is still unambiguously a personal data breach. Vehicle registration numbers and postcodes together are personal data. The absence of financial data changes the risk assessment, not whether the duty is engaged.

Case · March 2026
Companies House

A logic and session-handling flaw in the WebFiling service meant a user holding any valid login could file for another company — exposing personal data of directors and officers across around 5 million registered UK businesses. The flaw was introduced in October 2025 during migration to GOV.UK One Login and was live for roughly five months before discovery on 13 March 2026. Companies House suspended WebFiling and self-reported to both the ICO and the NCSC.

No attacker. No malware. A design flaw introduced by a routine platform migration, and still a personal data breach. Change is a breach vector.

Knowledge check · 01
A ransomware attack encrypts your housing case management system. Forensics later confirm no data was copied out. Have you suffered a personal data breach?
Article 4(12) covers accidental or unlawful destruction and loss, not just disclosure. Losing access to personal data is an availability breach whether or not anyone read it, and whether or not you can restore from backup. Backups affect your risk assessment and your recovery, not whether a breach occurred.
A member of staff opens a phishing email, recognises it, and reports it without clicking. What is this?
No personal data was destroyed, lost, altered, disclosed or accessed. So there is no Article 4(12) breach and no 72-hour clock. It is still worth logging: a run of similar attempts against the same team is precisely the kind of evidence that shows a known and unaddressed risk.
Module 02 — of seven

Which law is pointing at you

One incident can trigger three or four separate reporting duties to three or four separate regulators, on different clocks. Knowing which apply to you is a job to do before anything happens, not during.

The core: everyone holding personal data

Two instruments do the heavy lifting for every UK organisation. The UK GDPR — Regulation (EU) 2016/679 as retained and amended in UK law — sets the principles, the security duty and the reporting duties. The Data Protection Act 2018 supplies the UK-specific machinery: exemptions, the ICO's enforcement powers, criminal offences, and a separate regime in Part 3 for law enforcement processing.

The security principle sits at the top of the UK GDPR and everything in Module 03 flows from it:

Art. 5(1)(f) UK GDPR
Personal data shall be … processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’). legislation.gov.uk — UK GDPR, Chapter II

Article 5(2) then adds the accountability principle: the controller is responsible for compliance and must be able to demonstrate it. That second half is the one that decides enforcement outcomes.

The sector and service layers

InstrumentWho it catchesThe duty
PECR 2003, reg. 5A Providers of a public electronic communications service — telecoms operators, ISPs Notify ICO within 72 hours. No risk threshold: every breach is notifiable
NIS Regulations 2018, reg. 11 Operators of essential services — energy, transport, water, health, digital infrastructure Notify the competent authority within 72 hours of an incident with significant impact
NIS Regulations 2018, reg. 12 Relevant digital service providers — online marketplaces, search engines, cloud services Notify the ICO
Communications Act 2003, s.105K Public electronic communications networks and services Security compromise report to Ofcom
FOIA 2000 Public authorities, including local authorities Incident information may be requested; exemptions must be justified, not assumed
DPA 2018, Part 3 Competent authorities processing for law enforcement purposes Separate breach regime under s.67–s.68

The PECR change catches people out. Section 111 of the Data (Use and Access) Act 2025 replaced the old 24-hour telecoms clock with 72 hours, in force from 20 August 2025. Any internal policy or supplier contract still citing 24 hours under PECR is out of date. Note that regulation 5A still has no risk threshold — unlike the UK GDPR, every personal data breach connected with the service is notifiable, and regulation 5C sets a fixed monetary penalty of £1,000 for failing to notify.

The criminal layer

Two statutes matter here, and they point in opposite directions — one at the attacker, one potentially at you.

s.1(1) Computer Misuse Act 1990
A person is guilty of an offence if— (a) he causes a computer to perform any function with intent to secure access to any program or data held in any computer, or to enable any such access to be secured; (b) the access he intends to secure, or to enable to be secured, is unauthorised; and (c) he knows at the time when he causes the computer to perform the function that that is the case. legislation.gov.uk — Computer Misuse Act 1990, Part I

Sections 2 and 3 escalate this to unauthorised access with intent to commit further offences, and unauthorised acts intended to impair the operation of a computer. Section 3ZA covers unauthorised acts causing, or creating a risk of, serious damage. This is the law under which UK attackers are prosecuted — and in July 2026 two men were sentenced to five years six months for the September 2024 attack on Transport for London, which disrupted Live Tube arrivals and Oyster photocard applications and exposed personal data for around 5,000 customers including bank details.

Pointing the other way, the Data Protection Act 2018 creates offences that can catch your own staff, and your organisation's conduct during an investigation:

s.170(1) Data Protection Act 2018
It is an offence for a person knowingly or recklessly— (a) to obtain or disclose personal data without the consent of the controller, (b) to procure the disclosure of personal data to another person without the consent of the controller, or (c) after obtaining personal data, to retain it without the consent of the person who was the controller in relation to the personal data when it was obtained. legislation.gov.uk — Data Protection Act 2018, Part 6

This is the provision behind prosecutions of employees who look up records they have no business reason to see — a recurring issue in local authority social care and in policing. Separately, section 148 makes it an offence to destroy, dispose of, conceal, block or falsify information or documents that the Commissioner has required, with intent to prevent the ICO from seeing them. Nobody should be tidying up logs after an incident.

What is coming, and is not law yet

The Cyber Security and Resilience Bill is the most significant reform of UK cyber regulation since the NIS Regulations 2018. It amends rather than replaces them, pulls managed service providers and data centres into scope, and introduces a tighter two-stage reporting regime with a 24-hour initial notification alongside turnover-linked penalties.

Where it stands: introduced to the Commons on 12 November 2025, second reading 6 January 2026, all Commons stages completed 16 June 2026, introduced to the Lords on 17 June 2026, Lords second reading 14 July 2026, Committee stage from 1 September 2026. Royal Assent is expected in late 2026, with obligations phased in through secondary legislation potentially running to 2028.

Treat the Bill's provisions as scheduled, not binding. Nothing in it currently creates a duty. But a 24-hour clock cannot be retrofitted to an organisation that struggles with 72 hours, which is why it belongs in an awareness course now rather than in 2028.
Knowledge check · 02
Your organisation's data protection policy states that PECR breaches must be reported to the ICO within 24 hours. Is this correct?
Section 111 of the Data (Use and Access) Act 2025 amended regulation 5A with effect from 20 August 2025, aligning the PECR clock with UK GDPR Article 33. The reporting duty itself was not abolished — and unlike the UK GDPR it still carries no risk threshold, so every personal data breach connected with the service remains notifiable.
Mid-investigation, a manager deletes a folder of server logs to "clean up before the auditors see the mess". What is the exposure?
Section 148 makes it an offence to destroy, dispose of, conceal, block or falsify information or documents with intent to prevent the Commissioner seeing them. Beyond the criminal risk, destroying evidence removes your own best defence: without logs you cannot demonstrate what happened, when you became aware, or that your measures were appropriate. Preservation is step one of any incident response plan.
Module 03 — of seven

Article 32 and the anatomy of a security failure

Every flagship UK data protection fine from 2024 to 2026 has been an Article 32 security case, not a privacy-policy case. This is the provision that decides whether a breach becomes a penalty.

Art. 32(1) UK GDPR
Security of processing
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:
  1. the pseudonymisation and encryption of personal data;
  2. the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
  3. the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;
  4. a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.
legislation.gov.uk — UK GDPR, Chapter IV, Section 2

Reading it properly

Four things in that text do real work, and each is regularly misread:

Article 32(2) then tells you what to weigh when deciding what is appropriate:

Art. 32(2) UK GDPR
In assessing the appropriate level of security account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed. legislation.gov.uk — UK GDPR, Article 32

Article 32(4) closes a gap people forget: the controller and processor must take steps to ensure that anyone acting under their authority who has access to personal data does not process it except on instructions. That is the insider-access limb — access control, need-to-know, and audit trails on staff activity, not just perimeter security.

Case · ICO penalty, May 2026 — the worked example
South Staffordshire Plc and South Staffordshire Water Plc — £963,900

The ICO fined the companies £963,900 following a Cl0p ransomware attack. The personal information of 633,887 people was published on the dark web in August 2022, including full names, physical addresses, email addresses, dates of birth, gender and telephone numbers.

The timeline: initial access in September 2020 when an employee opened a malicious email attachment. The attackers remained undetected until May 2022, when they began moving across systems using a domain administrator account. The company only identified the intrusion in July 2022, after investigating widespread IT performance problems. Two weeks later staff found a ransom note.

The ICO's findings on the security failings map almost line by line onto Article 32:

  • No routine vulnerability scanning — a failure of 32(1)(d), the testing process
  • Continued use of Windows Server 2003, unsupported for years — a failure of 32(1)(b), ongoing resilience
  • Failure to patch ZeroLogon, a critical flaw publicly disclosed in 2020 — a known, published, unaddressed risk
  • By late 2021, an outsourced security operations centre monitoring only 5% of the IT environment — a control that existed on paper across a twentieth of the estate

Ian Hulme, the ICO's interim executive director for regulatory supervision, made the point that customers cannot choose their water company — they are required to share their personal information and place their trust in that provider. Twenty months of undetected access, discovered by accident through performance complaints, and a fine landing nearly six years after initial access.

What non-compliance costs

Article 83 sets two tiers. Infringements of Articles 25 to 39 — which includes Article 32 and Article 33 — sit in the lower tier: up to £8.7 million or 2% of total worldwide annual turnover, whichever is higher. Infringements of the basic principles in Article 5, which includes the security principle at 5(1)(f), sit in the higher tier: up to £17.5 million or 4%.

In practice the ICO's largest security penalty to date is £14 million against Capita plc and Capita Pension Solutions, issued 15 October 2025 and reduced from a proposed £45 million through a settlement in which Capita waived its right to appeal. The root cause the ICO identified was narrow and instructive: a 58-hour delay in quarantining an infected device after a high-priority security alert had been raised within ten minutes. Personal data belonging to 6.6 million people was exposed.

Ten minutes to detect. Fifty-eight hours to act. Article 32 is not only about the controls you buy — it is about whether your organisation does anything when they fire.
Knowledge check · 03
A small charity argues it cannot afford multi-factor authentication and so cannot be expected to have it. How does Article 32 treat this?
Article 32(1) expressly requires the costs of implementation to be taken into account, alongside the state of the art and the risk of varying likelihood and severity for the rights and freedoms of natural persons. So cost is genuinely relevant. What it never does is switch the duty off: the higher the risk to people, the less weight cost carries, and an organisation that identified a control, costed it and then did nothing has documented its own failure.
Which Article 32 limb does an untested backup most directly fail?
Both limbs, and they work together. Paragraph (c) requires the ability to restore availability and access to personal data in a timely manner in the event of a physical or technical incident. Paragraph (d) requires a process for regularly testing, assessing and evaluating effectiveness. A backup nobody has ever restored from is an assumption, not a capability — and (d) exists precisely to convert assumptions into evidence.
Module 04 — of seven

The clock: what you must do, and when

Seventy-two hours is the number everyone knows. Almost nobody can say when it starts, what it is a deadline for, or what happens if you miss it.

Art. 33(1) UK GDPR
Notification to the Commissioner
In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the Commissioner, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the Commissioner is not made within 72 hours, it shall be accompanied by reasons for the delay. legislation.gov.uk — UK GDPR, Article 33

Four things that sentence actually says

The 72 hours run on calendar time, including weekends and bank holidays. A breach discovered at 4pm on the Friday before a bank holiday expires on the Monday.

00:00Awareness

Clock starts. Log the date and time you found out, who is involved and what you know. Preserve evidence — do not delete or overwrite logs. Begin containment.

24:00Assess

Contain what you can. Assess severity and likelihood of harm to individuals: identity theft, financial loss, safeguarding risk, distress. Decide whether the risk is unlikely.

48:00Decide

Confirm the notification decision and who else must be told: NCSC, Action Fraud, competent authority under NIS, Ofcom, insurers, affected controllers if you are a processor.

72:00Deadline

Report to the ICO if notifiable, using the Article 33(3) content. If you cannot supply everything, report anyway in phases under Article 33(4), with reasons for any delay.

What must be in the report

Article 33(3) sets the minimum content, and it is worth knowing because it shapes what your incident log needs to capture from hour zero:

Art. 33(3) UK GDPR
The notification referred to in paragraph 1 shall at least:
  1. describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
  2. communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
  3. describe the likely consequences of the personal data breach;
  4. describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
legislation.gov.uk — UK GDPR, Article 33

You are not expected to have finished investigating. Article 33(4) permits phased reporting: where it is not possible to provide the information at the same time, it may be provided in phases without undue further delay. The ICO's own guidance is explicit that it expects controllers to prioritise the investigation, resource it adequately and expedite it urgently — and to explain the delay and say when more will follow.

The duty that applies even when you don't report

Art. 33(5) UK GDPR
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the Commissioner to verify compliance with this Article. legislation.gov.uk — UK GDPR, Article 33

Any personal data breach. Not the notifiable ones — all of them. If you assess a breach as not notifiable, the reasoning behind that decision is exactly what the last sentence exists to let the Commissioner check. A breach register with no entries is not evidence of a clean record; to a regulator it reads as evidence that nothing is being detected or assessed.

If you are a processor

Article 33(2) is one sentence: the processor must notify the controller without undue delay after becoming aware of a personal data breach. There is no 72-hour figure attached to the processor — the reporting duty to the ICO stays with the controller. Which means your Article 28 contract has to set the processor's timescale, because the statute does not.

Parallel clocks

Case · July–August 2026 — the reporting pattern done right
Department for Education, and the Police National Legal Database

The DfE confirmed a security incident affecting its online Customer Help Portal and the Turing Scheme portal after claims appeared over the weekend of 25 and 26 July 2026. Its official notice says affected data could include names, job titles, email addresses, phone numbers and business addresses submitted through those services. The Department temporarily took both portals offline, remediated the vulnerability and notified the ICO. The DfE notice does not confirm a final number of affected records or identify the attacker.

Weeks later the Police National Legal Database was hit by the same group, leaking names, organisations and email addresses of more than 100,000 police officers, staff and criminal justice professionals. PNLD notified the ICO and worked with the National Crime Agency and specialist cybersecurity organisations.

Both went to the regulator promptly and named the law enforcement bodies they were working with. Neither had full victim counts at the point of disclosure — and neither waited for one. That is Article 33(4) working as designed.

Knowledge check · 04
You discover on Friday at 16:00 that a laptop holding unencrypted resident records was stolen on the previous Sunday. When does the 72-hour clock expire?
Article 33(1) runs from "having become aware of it", not from the incident. The clock starts Friday at 16:00 and runs on calendar time, so it expires Monday at 16:00. A police investigation does not pause it. And note the underlying problem: an unencrypted device is the kind of fact that turns an Article 33 question into an Article 32 finding.
Seventy hours in, you still cannot say how many people are affected. What should you do?
Article 33(3)(a) asks for the approximate number "where possible" and Article 33(4) expressly permits phased notification. The ICO's guidance says to notify when you become aware and submit further information as soon as possible, explaining the delay and when you expect to provide more. A complete report submitted late is worse than an incomplete report submitted on time.
You assess a breach as unlikely to result in a risk and decide not to notify the ICO. What must you still do?
Article 33(5) requires documentation of any personal data breach, not just notifiable ones — the facts, its effects and the remedial action taken — and states that the documentation must enable the Commissioner to verify compliance. Your reasoning for not notifying is the single most important thing in that record, because it is what the ICO will ask to see.
Module 05 — of seven

Telling the people it happened to

Notifying the regulator and notifying individuals are two separate decisions, on two different thresholds. Organisations routinely confuse them in both directions.

Art. 34(1) UK GDPR
Communication to the data subject
When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay. legislation.gov.uk — UK GDPR, Article 34

Two thresholds, not one

Tell the ICOTell the individuals
ProvisionArticle 33(1)Article 34(1)
ThresholdUnless a risk is unlikelyWhere a high risk is likely
DeadlineWithout undue delay, within 72 hours where feasibleWithout undue delay — no fixed hours

So there is a middle band: breaches you must report to the ICO but need not communicate to individuals. That band is large, and treating every reportable breach as requiring mass notification causes real harm — it exhausts people's attention and dilutes the warnings that matter.

What the message must contain

Article 34(2) requires the communication to describe, in clear and plain language, the nature of the personal data breach, and to provide at least the information listed in points (b), (c) and (d) of Article 33(3) — the contact point, the likely consequences, and the measures taken or proposed, including measures to mitigate adverse effects.

"Clear and plain language" is a legal requirement, not a communications preference. A notification written to minimise reputational damage rather than to help people protect themselves does not satisfy Article 34.

When you don't have to tell individuals

Article 34(3) sets out three exceptions. Communication is not required if:

Note the shape of the first exception. Encryption does not stop a breach being a breach, and it does not remove the Article 33 duty to consider reporting to the ICO. What it can do is remove the Article 34 duty to tell individuals, because the data is unintelligible to whoever now holds it. That is one of the strongest practical arguments for encrypting data at rest.

Article 34(4) adds a backstop: if you have not communicated the breach to individuals, the Commissioner may require you to do so, or may decide that one of the exceptions applies. The decision is not finally yours.

Case · 27 August 2026 — a worked Article 34 communication
Manchester Airports Group

MAG contacted affected customers directly by email. The message stated plainly what had happened, identified the specific data accessed — email addresses, phone numbers, vehicle registration numbers and postcodes — and stated clearly that neither MAG nor the affected system held bank or payment details.

It then did the thing Article 34(2)(d) is for: it told people what to do. Remain alert for suspicious emails, text messages and phone calls; avoid clicking links or opening unexpected attachments. It confirmed that existing bookings remained valid and that no action was needed on those, and explained that the online Manage My Booking service had been suspended as a precaution, directing anyone needing changes within 72 hours to the customer services team.

Why this is a good model: it separates what people must do from what they need not do. Most breach notifications fail on the second half — they alarm without directing, and leave every recipient to work out for themselves whether they are in danger. The likely consequence here is targeted phishing using real travel details, and the letter names it.

Local authority note. Once you have communicated a breach publicly, expect Freedom of Information requests. Exemptions under FOIA 2000 — such as section 31, law enforcement, or section 43, commercial interests — may apply to specific technical detail while an investigation is live, but they must be applied and justified request by request. A blanket refusal to say anything is not a position FOIA supports, and it tends to be overturned.
Knowledge check · 05
A backup drive holding 40,000 customer records is lost. The drive was fully encrypted with a strong key that was not stored on it. What are your duties?
A loss is a breach under Article 4(12) regardless of encryption. Article 34(3)(a) is the relevant exception: where you have applied protection measures that render the data unintelligible to anyone unauthorised, communication to individuals is not required. That is an Article 34 exception, not an Article 33 one — you still assess reportability and you still document under Article 33(5). Waiting to see if it turns up is not a strategy; the clock started at awareness.
Which describes the relationship between the two notification thresholds?
High risk is a higher bar than "not unlikely to result in a risk". So Article 34 sits inside Article 33: anything meeting the high-risk test necessarily clears the reporting threshold, while a large middle band of breaches is reportable to the ICO without needing to be communicated to individuals. Telling individuals never substitutes for telling the regulator.
Module 06 — of seven

When it wasn't you — it was your supplier

Across UK incidents in 2026, the single most common entry point was not the breached organisation's own systems. It was somebody they had contracted with.

This does not divide the duty. It multiplies it. Article 32 binds controller and processor alike, and Article 24 puts the burden of proof on you:

Art. 24(1) UK GDPR
Responsibility of the controller
Taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation. Those measures shall be reviewed and updated where necessary. legislation.gov.uk — UK GDPR, Article 24

"To be able to demonstrate" is the operative phrase. You cannot demonstrate a supplier's security by having once received a completed questionnaire.

What Article 28 requires in the contract

Article 28(1) sets the selection duty: a controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures. Article 28(3) then requires a written contract that, among other things, binds the processor to:

The audit right is the one most often written in and never exercised. An unexercised audit right is not evidence of oversight.

The gap the statute leaves you to close

Article 33(2) requires the processor to notify the controller "without undue delay" — with no hours attached. Your 72-hour clock, meanwhile, generally runs from when you become aware. So the practical exposure is the space between your supplier knowing and you knowing. The statute does not close that gap. Your Article 28 contract has to, with a specific figure — 24 hours is common — and a named contact who is reachable outside office hours.

Cases · 2026 — three shapes of supplier failure
One supplier, many victims

Group GTI / CareerConnect, May–June 2026. The careers platform was breached on 28 May, exposing first and last names, email addresses and encrypted passwords for users not signing in through Single Sign-On. Oxford disclosed; the same platform is used by King's College London and the University of Manchester. One supplier compromise, multiple institutions notifying at once.

CEVA Logistics, August 2026. A breach at the shipping and logistics giant put customer names, home addresses, phone numbers and email addresses at risk across organisations that had no relationship with each other — Dutch retailer Bol, De Bijenkorf, football club Ajax, ING, Ace & Tate, Valve, and Pokémon Center customers in the UK and Germany, notified separately weeks later. Trezor's customers were exposed through a different logistics provider, ShipMonk, in the same period.

Synnovis, June 2024 to June 2026. The Qilin ransomware attack on the NHS pathology provider was still generating patient notifications two years later — around 35,000 records across Bedfordshire and Essex trusts, following an 18-month forensic review, with a court injunction in place and NCSC support ongoing. Both trusts notified the ICO.

The Synnovis case is the one to sit with. Two years after an attack on a supplier, individual NHS trusts were still writing to patients and still notifying the regulator. A supplier incident does not end when the supplier says it has ended.

Local authority note. Shared service arrangements between councils are efficient and they concentrate risk. In November 2025 an attack exploiting shared IT infrastructure hit Westminster, Kensington & Chelsea, and Hammersmith & Fulham together; by January 2026 Kensington & Chelsea was writing to hundreds of thousands of households. Where infrastructure is shared, the incident response plan, the notification decision and the breach register need to be worked out in advance across all parties — not negotiated during the 72 hours.

Five questions to ask before you sign

  1. How quickly, in hours, will you notify us of a personal data breach affecting our data — and who makes that call at your end, out of hours?
  2. Who are your sub-processors, and how will we be told when that list changes?
  3. When were your restore procedures last tested end to end, and can we see the result?
  4. What would you actually give us within 24 hours of an incident, so we can meet our own Article 33(3) duty?
  5. Will you accept an audit or inspection, and when was the last one you underwent?
Knowledge check · 06
Your payroll processor is breached. They tell you nine days after they became aware. Who is answerable to the ICO?
The Article 33(1) duty to notify the Commissioner stays with the controller. The processor's own duty under Article 33(2) is to notify you without undue delay, and nine days will not meet that. But the question the ICO will put to you is Article 28: did your contract set a notification timescale, did you select a processor providing sufficient guarantees, and did you ever verify them? A contract silent on hours is your failure, not only theirs.
A supplier tells you an incident is "contained" and closed. What does the 2026 record suggest?
The Canvas breach is the clearest illustration. Instructure declared the incident contained on 6 May 2026; the attacker struck again the next day, replacing the login page with a ransomware message. Synnovis makes the longer-range version of the point: patient notifications were still going out two years after the original attack. Vendor notifications are the start of your assessment, not the end of it.
Module 07 — of seven

Holding the standard between incidents

The regulator does not assess you on the day of the breach. It assesses the years before it. Nearly everything that determines the outcome is decided while nothing is happening.

What the ICO actually looks for

Read across the enforcement record and a consistent pattern emerges. In every major UK security case, the finding was not that the organisation lacked a security team or a budget. It was one of four things:

FindingWhere it showed up
A known risk left unaddressedSouth Staffordshire: ZeroLogon, publicly disclosed in 2020, unpatched. The Legal Aid Agency had rated its cyberattack risk "extremely high" on its own register since 2021, and the Ministry of Justice had spent £50m on improvements there before the breach still happened.
A control that existed on paper onlySouth Staffordshire: an outsourced SOC monitoring 5% of the estate
Detection without responseCapita: a high-priority alert raised within ten minutes, the infected device not quarantined for 58 hours
Legacy systems nobody ownedSouth Staffordshire: Windows Server 2003, years past support

None of those is a sophisticated attack. All four are visible from inside the organisation, in advance, for free.

Five things to be able to produce on demand

  1. A breach register with entries in it — Article 33(5) requires documentation of any personal data breach, including the ones you decided not to report and why. The ICO publishes a log template; use it or something better.
  2. An incident response plan that names people, not roles — with out-of-hours contacts for your DPO or equivalent, your processors, your insurers and your regulator, and with the first action being preserve evidence and start the clock.
  3. Evidence that you test — Article 32(1)(d) requires a process for regularly testing, assessing and evaluating effectiveness. Restore tests with dates and outcomes. Tabletop exercises with a written debrief.
  4. A current record of processing and suppliers — you cannot notify within 72 hours if it takes two days to establish whose data was in the affected system.
  5. A decision trail on risk — where you accepted a risk, the note saying who accepted it, on what basis, and when it is due for review. An accepted risk with a name against it is a defensible position; an unaccepted risk that nobody looked at is not.

Frameworks worth mapping to

For local authorities specifically: internal control and risk management duties under the Accounts and Audit Regulations 2015 mean cyber risk belongs on the corporate risk register and in the annual governance statement, not solely in an IT service plan. That is the mechanism by which a known-and-unaddressed risk becomes visible to members.

Where this is heading

Three changes are already fixed or close to it. The Data (Use and Access) Act 2025 is being commenced in stages: document-notice powers commenced two months after Royal Assent, while specified data-protection and PECR enforcement provisions commenced on 5 February 2026. The ICO applied a 40% settlement reduction in the South Staffordshire case; its draft enforcement procedural guidance proposes tiered discounts of 40%, 30% and 20% depending on when a case settles. And the Cyber Security and Resilience Bill, expected to receive Royal Assent in late 2026, brings a 24-hour initial notification duty for in-scope organisations, phased in through secondary legislation to around 2028.

The through-line across all three is the same: less tolerance for delay, more weight on evidence, and a shorter gap between knowing and acting.

Knowledge check · 07
Your organisation holds ISO/IEC 27001 certification. What does that do for you if the ICO investigates a breach?
Article 32(3) says adherence to an approved code of conduct or certification mechanism "may be used as an element by which to demonstrate compliance". An element. It is useful and it is worth having — but the question remains whether your measures were appropriate to the risk your processing actually created. A certified organisation running an unmonitored legacy server has certification and a finding against it.
Your breach register has no entries for the last two years. What is the most likely regulatory reading of that?
Article 33(5) requires documentation of any personal data breach. Given that misdirected emails, lost devices and staff accessing records without a business reason are near-universal, a register with nothing in it does not suggest an organisation with no breaches. It suggests one that is not detecting or recording them — which is itself a failure of the Article 5(2) accountability principle.
Course complete

The five things worth keeping

  1. A breach is wider than a hack. Article 4(12) covers accidental destruction, loss and alteration, not just unauthorised access. Ransomware with no exfiltration is still a breach.
  2. The clock starts at awareness — reasonable certainty that a security incident has occurred and compromised personal data — and runs on calendar time. Seventy-two hours is a backstop, not an allowance.
  3. Report on time and incomplete, rather than late and complete. Article 33(4) exists for exactly this.
  4. Document everything, including what you decided not to report. Article 33(5) applies to any breach, and your reasoning is what the Commissioner will ask to see.
  5. Article 32 is judged on the years before the breach. Known risks, paper controls, detection without response, and unowned legacy systems are what enforcement actually turns on.

Legislation cited in this course

Where to go next

This course is awareness training. It is not legal advice, and it does not replace advice from your DPO, your legal team or a qualified solicitor on a specific incident. Legislation cited is current as at 27 August 2026; the Cyber Security and Resilience Bill was before the House of Lords at that date and is not law.