United Kingdom flag

United Kingdom

UK Data Breach Reporting: The 72-Hour ICO Rule

Independently fact-checked against primary sources (last audited September 30, 2026). · Law checked current as of September 30, 2026. · 10 primary sources cited on this page. How we verify our legal content

UK Data Breach Reporting: The 72-Hour ICO Rule

Updates

We updated the regulator name (the ICO became the Information Commission on 30 September 2026 and is still known as the ICO), clarified that the turnover-based fine maximums apply only to undertakings, and added the separate PECR breach duty for telecoms and internet providers.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Sources and References

  1. UK GDPR Article 33, Notification of a personal data breach to the supervisory authority (the Commission from 30 September 2026, SI 2026/386)(legislation.gov.uk).gov
  2. UK GDPR Article 34, Communication of a personal data breach to the data subject(legislation.gov.uk).gov
  3. ICO, Personal data breaches: a guide(ico.org.uk).gov
  4. ICO, 72 hours: how to respond to a personal data breach(ico.org.uk).gov
  5. ICO, Personal data breach examples(ico.org.uk).gov
  6. ICO, Self-assessment for data breaches(ico.org.uk).gov
  7. ICO, The maximum amount of a fine under UK GDPR and DPA 2018(ico.org.uk).gov
  8. Data Protection Act 2018(legislation.gov.uk).gov
  9. ICO, ICO governance changes confirmed for 30 September 2026 (transition to the Information Commission; still known as the ICO)(ico.org.uk).gov
  10. Privacy and Electronic Communications (EC Directive) Regulations 2003, regulation 5A (personal data breach notification by communications providers; 72 hours since 20 August 2025)(legislation.gov.uk).gov
Share: