We've Had a Data Breach

We've Had a Data Breach. What Should We Do Next?

A helpful guide

💭 Ask yourself...

"If this involved my personal information, what would I need someone to do to protect me?"

That one question often helps you decide what matters most.

 

Short answer

If you've identified a personal data breach, don't panic.

Most breaches can be managed successfully if you act quickly, understand what has happened and make a considered decision about the risks.

Not every breach needs to be reported to the ICO.

However, every breach should be assessed and documented.

 

First things first

Your immediate priority should be to prevent the situation from getting worse.

For example:

  • Recall an email if possible. 
  • Contact the unintended recipient. 
  • Recover any documents. 
  • Disable compromised accounts. 
  • Secure affected systems. 
  • Preserve evidence to help understand what happened. 

The sooner you contain the breach, the more options you may have.

 

Do I need to tell the ICO?

Not always.

You should consider reporting the breach to the ICO if it is likely to result in a risk to the rights and freedoms of individuals.

When making that decision, think about:

  • What information was involved? 
  • How sensitive was it? 
  • How many people were affected? 
  • Who received the information? 
  • Has it been recovered? 
  • Could somebody suffer financial loss, identity theft, discrimination or significant distress? 

If you decide the breach is reportable, you should normally notify the ICO within 72 hours of becoming aware of it.

If you decide not to report the breach, you should still document how you reached that decision.

 

Do I need to tell the people affected?

Sometimes this is the most important question.

If the breach is likely to result in a high risk to the rights and freedoms of individuals, you should consider informing them without undue delay.

The purpose isn't simply to tell them something has gone wrong.

It's to give them the opportunity to protect themselves.

For example:

If a passport, driving licence and proof of address have been disclosed, informing the individual quickly may allow them to:

  • monitor their accounts; 
  • be alert to identity fraud; 
  • contact relevant organisations; 
  • take other steps to protect themselves. 

Good data protection isn't just about reporting to regulators.

It's about helping people reduce the impact of what has happened.

 

Record your decision

Whether you report the breach or not, you should keep a record explaining:

  • what happened; 
  • when it happened; 
  • what information was involved; 
  • who was affected; 
  • the likely risks; 
  • the action you took; 
  • whether you reported it and why. 

A well-documented decision demonstrates accountability and helps identify lessons for the future.

 

Learn from the breach

Every breach is an opportunity to improve.

Ask yourself:

  • Why did this happen? 
  • Was this a one-off mistake or a process issue? 
  • Could additional training help? 
  • Do we need stronger technical controls? 
  • Should we review our procedures? 

The aim isn't to blame individuals.

It's to reduce the likelihood of it happening again.

 

Practical steps

  1. Contain the breach. 
  2. Understand what happened. 
  3. Assess the risk to individuals. 
  4. Decide whether the ICO should be notified. 
  5. Decide whether individuals should be informed. 
  6. Record your decision. 
  7. Review what can be improved. 

 

Common Misconceptions

"Every data breach must be reported to the ICO."

No.

Only breaches that are likely to result in a risk to the rights and freedoms of individuals generally need to be reported. Every breach should be assessed, but not every breach is reportable.

 

"If I don't report the breach, I don't need to record it."

Not correct.

Even where you decide a breach doesn't need to be reported, you should document what happened, your assessment and the reasons for your decision.

 

"The ICO is the first organisation I should think about."

Not necessarily.

Your first priority should be containing the breach and understanding the risk to the people affected. The reporting decision follows from that assessment.

 

"If the individuals don't know, I don't need to tell them."

Not always.

If the breach is likely to result in a high risk to the rights and freedoms of individuals, you should consider informing them without undue delay so they can take steps to protect themselves.

 

"If the information has been recovered, nothing else needs to happen."

Not necessarily.

Recovering the information may significantly reduce the risk, but you should still assess what happened, document your decision and consider whether improvements are needed.

 

Remember...

A data breach isn't about finding blame.

It's a chance to learn.

What matters most is how you respond.

Acting quickly, being honest, protecting the people affected and learning from what happened are often the strongest indicators of a good data protection culture.

 

🤝 Need a little support?

Most organisations don't experience data breaches every day, so it's perfectly normal to be unsure about what to do next.

If you'd like someone to help assess the risks, review whether the breach needs to be reported or simply talk through the situation before making a decision, we're here to help.

Sometimes a calm, independent assessment is all that's needed to turn a stressful situation into a manageable one.

Related Guides

Have We Had a Data Breach?

Information icon

We need your consent to load the translations

We use a third-party service to translate the website content that may collect data about your activity. Please review the details in the privacy policy and accept the service to view the translations.