Under UK GDPR Article 33, you must notify the ICO within 72 hours of becoming aware of a personal data breach — but only if it is "likely to result in a risk to the rights and freedoms of individuals". Not every breach requires notification.
Notification is required when the breach is likely to result in a risk to individuals, such as:
Under Article 34, if a breach is likely to result in a HIGH risk to individuals (more severe than "risk"), you must also notify the affected individuals "without undue delay". This is a higher threshold than ICO notification.
The 72 hours runs from when you become "aware" of the breach. For organisations, this is when a staff member with authority (not every employee) becomes aware. A junior employee's suspicion does not start the clock — it starts when you have reasonable certainty that a breach has occurred.
If you cannot report within 72 hours, you can still notify — but you must explain why the notification is late. Late notification is better than no notification, and the ICO takes promptness into account when considering enforcement.
Need more help with this?
Contact support