3. Assessing and notifying
Telling individuals, and keeping the breach register
When individuals must be told
Where a breach is likely to result in a high risk to the rights and freedoms of individuals, the organisation must also tell the affected individuals themselves, without undue delay. Note the higher bar: "risk" triggers the ICO report, "high risk" triggers telling the people affected. The purpose is practical, not ceremonial: warned individuals can protect themselves by changing passwords, watching bank statements, or being alert to scam calls that use the leaked details.
There are exceptions. Individual notification may not be required where the data was protected in a way that makes it unintelligible to others, for example strong encryption with the keys kept safe, or where measures taken after the breach mean the high risk is no longer likely to materialise, or where contacting everyone individually would involve disproportionate effort, in which case a public communication can be used instead.
What a notification includes
A notification, whether to the ICO or to individuals, covers broadly the same ground, in clear and plain language:
- The nature of the breach, and for the ICO the categories and approximate numbers of individuals and records concerned
- A contact point, such as the DPO, where more information can be obtained
- The likely consequences of the breach
- The measures taken or proposed to address the breach and limit its effects, including, for individuals, practical advice on protecting themselves
The breach register
Separately from any notification, UK GDPR requires organisations to document every personal data breach: the facts, its effects, and the remedial action taken. This applies even to breaches that were assessed as unlikely to result in a risk and were never reported to anyone.
This internal breach register serves two purposes. It is how an organisation demonstrates to the ICO, if ever asked, that its "no notification needed" decisions were made properly rather than by wishful thinking. And it is the raw material for spotting patterns: five near-identical misdirected email entries in three months is a training and tooling problem announcing itself. An empty breach register in a busy organisation is rarely a sign of perfection. It is usually a sign of under-reporting.
Check your understanding
A short, optional 5-question quiz on this section. It doesn't block your progress, it's just a quick self-check.
Try the section quiz →› Course contents
What counts as a breach
First response
Assessing and notifying
Learning and prevention