Skip to content
Amrani Academy

3. Assessing and notifying

The 72-hour clock and notifying the ICO

UK GDPR requires organisations to report certain breaches to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach. In plain English: once your organisation knows it has a breach on its hands, a 72-hour countdown starts on telling the regulator.

When does the clock start?

The clock runs from awareness: the point at which the organisation has a reasonable degree of certainty that a security incident has occurred and that personal data is affected. It does not wait for a full investigation to finish, and it does not restart when the incident reaches the right person. This is exactly why immediate internal reporting matters. If a colleague sits on an incident for a week, that week may already have burned through the deadline before the response team ever hears about it.

72 hours means 72 hours

The clock runs through evenings, weekends, and bank holidays. A breach discovered at 5pm on Friday does not politely pause until Monday morning. Organisations need a reporting route that works out of hours, and staff need to use it.

The exception

Not every breach has to be reported to the ICO. Notification is required unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. That "unlikely to result in a risk" judgement comes from the assessment in the previous lesson, and it must be made honestly and documented. A misdirected internal email, fully contained, with deletion confirmed, may well fall on the "no notification" side. A stolen unencrypted laptop full of client records almost certainly does not.

Reporting in stages, and reporting late

If the full picture is not clear within 72 hours, organisations can and should notify in phases: an initial report with what is known, followed by updates as the investigation progresses. Waiting for perfect information is not an acceptable reason to miss the deadline. If notification happens after 72 hours, it must be accompanied by the reasons for the delay. Late reporting, and especially unreported breaches that come to light later, are treated far more seriously than imperfect early reports.

Course contents