Home / The first 72 hours after a personal data breach – what organisations should do
5th October 2026
Laura Crowe, Senior Associate
When a personal data breach occurs, prompt action is essential.
In the immediate aftermath, organisations must quickly establish what happened, what data is affected, whether the incident is ongoing, and who needs to be informed. With information often incomplete and decisions required at pace, roles, escalation routes, and ownership can easily become unclear.
The first 72 hours are often critical.
A structured response helps contain the incident, assess risk, meet regulatory obligations, and maintain stakeholder confidence. Delays and uncertainty, however, can increase both operational disruption and regulatory exposure.
So, if a breach happened tomorrow, would the right people know what to do first, or would valuable time be spent working that out?
A personal data breach is defined by Article 4(12) UK GDPR as a security breach resulting in the accidental or unlawful loss, destruction, alteration, disclosure of, or access to personal data.
While not every breach is reportable, every incident should be assessed and documented. Organisations must evaluate the level of risk and, where required:
Notify the ICO** without undue delay and, where feasible, within 72 hours of becoming aware of the breach (Article 33).
Notify affected individuals where there is a high risk to their rights and freedoms (Article 34).
Article 33(5) also requires organisations to maintain records of all personal data breaches, including their effects and any remedial action taken, reflecting the accountability principle in Article 5(2). Robust detection, investigation, and reporting procedures are therefore essential to support timely decision-making and compliance.
For organisations reviewing their existing processes, the ICO’s guidance on personal data breaches provides a useful starting point: Personal data breaches: a guide | ICO
The immediate priority is to understand and contain the incident. Organisations should quickly establish what happened, whether the breach is ongoing, what data and individuals may be affected, and what steps are needed to prevent further compromise.
Incident response plans should be activated promptly, with legal, privacy, security and other key stakeholders engaged as required. Clear ownership is essential to coordinate actions, oversee decision-making and maintain records.
A breach log should be created from the outset to support risk assessments, notification decisions, and accountability, in line with ICO guidance on effective breach management.
Once the incident is contained, the focus shifts to assessing its scope and impact. Organisations should establish what personal data is affected, how many individuals may be impacted, whether special category or criminal offence data is involved, and the likely risk to individuals’ rights and freedoms.
The assessment should focus on potential harm to individuals, such as financial loss, reputational damage, discrimination, or loss of confidentiality, rather than solely the impact on the organisation. Initial findings may change as investigations progress, so risk assessments and decisions should be kept under review as further information becomes available. Personal data breaches | ICO
By this stage, organisations should be in a better position to determine whether notification requirements under Articles 33 and 34 UK GDPR are triggered.
Under Article 33 UK GDPR, organisations must notify the ICO where a personal data breach is likely to result in a risk to individuals’ rights and freedoms. Notification must be made without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Additional information can be provided as investigations progress. ICO guidance on personal data breaches
An ICO notification should summarise:
Notifications can be submitted via the ICO personal data breach reporting portal.
Under Article 34 UK GDPR, organisations must notify affected individuals where a breach is likely to result in a high risk to their rights and freedoms.
Notifications should clearly explain what happened, the potential consequences, any protective steps individuals should take, and how to obtain further support. The ICO recommends providing practical advice to help individuals reduce the impact of the breach.
• Activate response plan
• Confirm personal data involvement
• Contain the breach
• Secure evidence
• Assign ownership
• Escalate internally
• Log the incident
• Identify third-party involvement
• Define scope and impact
• Identify affected individuals
• Confirm sensitive data involvement
• Assess and document risk
• Gather notification information
• Review reporting obligations
• Update records and decisions
• Decide on ICO notification (Art. 33)
• Decide on individual notification (Art. 34)
• Prepare notifications
• Brief senior leadership
• Implement remediation
• Document lessons learned
• Maintain audit trail
Key reminder: Assess and record every breach. Even where notification is not required, Article 33(5) UK GDPR requires organisations to document the incident, its effects and any remedial action taken.
A strong breach response starts long before a breach occurs. Clear escalation routes, defined ownership, tested processes, and effective record-keeping enable organisations to respond quickly and confidently when it matters most.
The aim of the first 72 hours is not to have every answer. It is to contain the incident, assess the risks, make defensible decisions, and demonstrate accountability.
The real test is not whether a breach occurs, but how effectively the organisation responds. And if the ICO asked to see your breach records tomorrow, could you clearly demonstrate what happened, what decisions were made, and why? That answer often separates prepared organisations from those relying on hope rather than process.
** Note: as of 30 September 2026, the Information Commissioner’s Office has formally transitioned to the Information Commission.