Data Protection Atlas

Personal data breach notification (UK)

Tier 1 Override

UK deltas to the GDPR breach archetype. The two-threshold architecture (risk to the ICO under Art 33; high risk to individuals under Art 34) is inherited unchanged from the UK GDPR. What differs: the recipient is the ICO and its reporting channel; a specific criminal offence under s.173 DPA 2018; the separate PECR reg 5A 24-hour regime for public electronic communications service providers; and DUAA 2025 changes, with commencement status as at 2026-07-26.

Applies to

Jurisdiction: United Kingdom

Instruments: UK GDPR , DPA 2018

Mechanics

Item Position vs archetype
Recipient authority Information Commissioner's Office (ICO) Changed
Reporting channel ICO online breach report / breach helpline Changed
Regulator/individual thresholds Risk (ICO) / High risk (individuals) — unchanged from UK GDPR Unchanged
Criminal exposure s.173 DPA 2018 (altering/destroying records to prevent disclosure) Changed

Steps that change

  1. Notify the ICO within 72 hours Replaces the archetype step

    The recipient supervisory authority is the Information Commissioner's Office. Report via the ICO's personal data breach reporting service (online form) or its breach helpline. The Art 33 content requirements are identical to the archetype. The 72-hour clock and "awareness" trigger are unchanged under the UK GDPR.

    See UK GDPR

    Use the ICO online report; the helpline is for urgent or out-of-hours matters. Keep the reference number in the internal register entry.
  2. Internal breach register plus s.173 records-integrity offence Adds to the archetype step

    The Art 33(5) register duty is inherited unchanged. In addition, s.173 of the Data Protection Act 2018 makes it a criminal offence to alter, deface, block, erase, destroy or conceal information with the intention of preventing disclosure of that information to a person who would have been entitled to it under a subject access or similar right — once a request has been made. This bites on breach handling because the instinct to "clean up" records after an incident, or in the face of an imminent access request, can convert an administrative failure into a criminal one.

    See DPA 2018

    Criminal offence s.173 DPA 2018 is a criminal offence. Never delete, edit or "tidy" records relating to a breach or a pending data subject request. Preserve everything; take legal advice before any remediation that touches the affected data.

Steps that do not change

Inherited from the archetype exactly as written there.

Step Title Archetype position
1 Detect and record the breach A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data (Art 4(12)). It is not limited to confidentiality breaches: loss of availability (e.g. ransomware, accidental deletion with no backup) and integrity breaches count. Log every suspected breach in the internal register the moment it is identified, before you know whether it is notifiable.
2 Establish the point of awareness (start the clock) The 72-hour clock in Art 33(1) runs from when the controller becomes "aware" of the breach — i.e. has a reasonable degree of certainty that a security incident has occurred and compromised personal data, not from the moment of the incident itself. A short investigation to confirm is permitted, but awareness is not indefinitely deferrable. Document the moment of awareness and the reasoning.
3 Assess whether the regulator must be notified (the RISK test) Notify the competent supervisory authority UNLESS the breach is unlikely to result in a risk to the rights and freedoms of natural persons (Art 33(1)). This is a low threshold: mere "risk" (not high risk) triggers the duty. Assess severity and likelihood by reference to the nature, sensitivity and volume of data, ease of identification of individuals, and potential consequences. If in genuine doubt, the defensible course is usually to notify.
5 Assess whether individuals must be told (the HIGH RISK test) Communicate the breach to affected individuals without undue delay where it is likely to result in a HIGH risk to their rights and freedoms (Art 34(1)). The communication must be in clear and plain language and contain the Art 33(3)(b)-(d) information. No individual notification is required if (a) appropriate technical/organisational protections were applied to the affected data (e.g. strong encryption rendering it unintelligible); (b) subsequent measures ensure the high risk is no longer likely to materialise; or (c) it would involve disproportionate effort, in which case a public communication or equally effective measure suffices (Art 34(3)).
6 Phased and incomplete notification Where it is not possible to provide all information at once, information may be provided in phases without further undue delay (Art 33(4)). Making an initial notification within 72 hours with details to follow is expressly permitted and is preferable to missing the deadline while investigating.
8 Processor-to-controller notification (Art 33(2)) A processor must notify the controller without undue delay after becoming aware of a personal data breach. The processor has no direct duty to notify the supervisory authority or individuals; the controller carries those duties and its 72-hour clock effectively depends on prompt processor reporting. Build the notification trigger, timescale and content into the Art 28 processing contract.

Additions not in the archetype

PECR regulation 5A — 24-hour regime for communications providers

Providers of public electronic communications services have a SEPARATE and stricter breach regime under PECR reg 5A: notify the ICO of any personal data breach without undue delay and, where feasible, within 24 hours of detection, and notify affected subscribers/users where the breach is likely to adversely affect their personal data or privacy. This sits alongside, not instead of, the UK GDPR duties for such providers and is unchanged in substance by the DUAA. As at 2026-07-26 the reg 5A 24-hour regime remains in force.

DUAA 2025 changes and commencement status (as at 2026-07-26)

The Data (Use and Access) Act 2025 (Royal Assent 2025-06-19) does not dismantle the UK GDPR two-threshold breach architecture, which remains in force. Section 111 DUAA amends the PECR personal data breach notification to align it more closely with UK GDPR and was commenced early (in force 2025-08-20 under Commencement No. 1). The main data-protection tranche commenced 2026-02-05 (Commencement No. 6 and Transitional and Saving Provisions Regulations 2026), which raised the PECR maximum penalty from GBP 500,000 to GBP 17.5m / 4% of global turnover — materially increasing the stakes of any PECR breach failure. A new statutory data-subject COMPLAINTS-handling duty (new s.164A DPA 2018) commences 2026-06-19 (so is in force as at 2026-07-26) and interacts with breach handling where a breach generates complaints. Do not treat any DUAA provision not yet commenced as live.

Sources

Never independently verified.