Responding to a Personal Data Breach: An Employer Guide

A practical guide for managers, DPOs and incident teams on spotting a personal data breach, meeting the 72-hour ICO reporting rule, and building a response process.

Learnsignal Education Team
7 min read
Updated

A lost laptop, a misdirected email with a spreadsheet of payroll data attached, a phishing attack that exposes employee records — any of these can count as a personal data breach under UK GDPR. When it happens, the first 24 hours matter enormously, and most organisations only discover how prepared they are once it's too late to plan calmly. This guide sets out what counts as a breach, when the 72-hour clock to the Information Commissioner's Office (ICO) actually starts, when you must tell the people affected, and how to build a response process before you need one.

What counts as a personal data breach?

Under UK GDPR, a personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. That definition is broader than most managers assume. It is not limited to hacking or theft. According to the ICO's guidance on personal data breaches, it also covers:

  • Loss or theft of a device, USB stick or paper file containing personal data
  • Sending personal data to the wrong recipient, internally or externally
  • Unauthorised access to an HR or payroll system, including by an employee who should not have had access
  • Alteration of personal data without permission, or its accidental deletion where no backup exists
  • A ransomware or cyberattack that makes personal data unavailable, even temporarily

Availability breaches are the one HR teams most often overlook: if a system holding employee data goes down and you cannot restore access within a reasonable time, that can itself be reportable, even though nobody has stolen anything.

The 72-hour rule: what actually triggers it

This is the detail organisations most often get wrong, so it is worth being precise. Under UK GDPR, a notifiable breach must be reported to the ICO without undue delay and, where feasible, not later than 72 hours after the organisation becomes aware of it. The clock does not start when the breach occurred — it starts from the point the controller (your organisation) becomes aware that a breach has taken place. A device could go missing on a Friday, but if IT only confirms on the following Tuesday that personal data was on it, the 72 hours runs from the Tuesday, not the Friday. This is exactly why documenting the discovery time immediately is so important — it is the fact your 72-hour deadline hinges on.

Not every breach has to be reported. The ICO's guidance sets out one key exception: you do not need to notify the ICO if the breach is unlikely to result in a risk to the rights and freedoms of individuals — for example, a single email sent to the wrong internal colleague who confirms it was deleted unread and never disclosed further. Where you decide not to report, you must document that decision and the reasoning behind it, because the ICO can ask to see it later. If in doubt, the ICO's self-assessment tool for data breaches is designed to help you work through whether a report is required.

When you must notify the individuals affected

Reporting to the ICO and notifying the people whose data was affected are two separate decisions with two separate thresholds. You must tell affected individuals directly, and without undue delay, only when the breach is likely to result in a high risk to their rights and freedoms — a higher bar than the "risk" threshold that triggers ICO reporting. Practical examples in an employment context include exposure of bank details, National Insurance numbers, health information, or data that could lead to identity theft, financial loss, discrimination or significant distress.

When notification to individuals is required, the ICO expects it to include, in clear plain language: a description of the nature of the breach, the name and contact details of your data protection officer or other contact point, a description of the likely consequences, and the measures you have taken or propose to take to address the breach and mitigate its effects, including specific advice on what the individual can do to protect themselves (for example, changing passwords or monitoring bank statements).

Immediate containment: the first hours

Once a breach is suspected, resist the urge to either panic or delay. The ICO's own advice for small organisations frames a calm, structured response as the priority. In practice, that means:

  • Record the discovery time immediately. This single fact determines your 72-hour deadline, so log it before anything else.
  • Contain it. Recover lost data where possible, remotely wipe a lost or stolen device, revoke system access, isolate an affected server, or recall a misdirected email if the platform allows it.
  • Gather the facts. What data was involved, how many people are affected, what categories of data (special category data such as health information raises the risk significantly), and how the breach happened.
  • Assess the risk of harm. Consider identity theft, financial loss, discrimination, reputational damage, safeguarding concerns, or simple distress. This assessment drives both the ICO reporting decision and the individual notification decision.
  • Loop in the right people early. Your data protection officer (DPO), IT/security lead, HR and, for serious incidents, legal counsel and senior leadership.

Many breaches in an HR context arise from exactly the everyday situations covered in Learnsignal's guide to secure remote and hybrid working policies — a personal device used for work, a file synced to the wrong cloud folder, or a laptop left on a train. Getting those policies right is genuinely preventative work, not just compliance box-ticking.

Building an internal breach-response process

The organisations that handle breaches well are the ones that decided what to do before anything went wrong. A workable internal process should cover:

  • A single, well-publicised reporting channel so any employee who spots a possible breach knows exactly who to tell and how fast
  • A named incident lead (often the DPO) with clear authority to coordinate the response across IT, HR and legal
  • A breach log or register recording every incident, however minor, with discovery time, actions taken, risk assessment and outcome — the ICO provides a template breach log that many organisations adapt for this purpose
  • A pre-agreed decision tree for the ICO reporting threshold and the individual notification threshold, so the risk assessment is not improvised under pressure
  • Draft communication templates for notifying individuals, so you are not writing from scratch inside a 72-hour window
  • A post-incident review to identify what allowed the breach to happen and what changes — technical, procedural or training — will reduce the chance of a repeat

Keeping a record of every breach, even ones you decide not to report to the ICO, is itself a legal requirement under UK GDPR's accountability principle. It is also one of the first things the ICO will ask to see if it ever investigates your organisation.

Why this matters beyond compliance

Getting breach response wrong carries real financial exposure: UK GDPR allows the ICO to issue fines of up to £17.5 million or 4% of annual global turnover, whichever is higher, for the most serious infringements. But for most employers the bigger day-to-day risk is trust — from employees whose payroll or health data has been exposed, and from customers whose records were involved. A fast, well-documented, transparent response does far more to protect that trust than a fine ever will. It also connects directly to how you handle related data rights requests: see Learnsignal's guide to data subject access requests in HR for how individual rights and breach notifications often intersect when someone asks what data you hold on them after an incident.

FAQ

Does the 72-hour clock start when the breach happens or when we find out?

It starts when your organisation becomes aware of the breach, not when it actually occurred. This is why logging the exact discovery time is the first thing your team should do.

Do we have to report every breach to the ICO?

No. You only need to report a breach that is likely to result in a risk to individuals' rights and freedoms. If you assess a breach as unlikely to cause harm, you can decide not to report it — but you must document that decision and the reasoning behind it in your internal breach log.

What's the difference between reporting to the ICO and notifying individuals?

They use different thresholds. ICO reporting applies where there is a risk to individuals; direct notification to the affected individuals is only required where there is a likely high risk to their rights and freedoms. A breach can therefore be reportable to the ICO without requiring you to contact everyone affected.

Who should manage a data breach response internally?

Typically your data protection officer or a named incident lead coordinates the response, working with IT/security, HR and legal. Having this role and a documented process agreed in advance — rather than decided during the incident — is what separates a controlled response from a chaotic one.

Breach response is a skill that improves with structure and practice, not panic. Building the checklist, training the people who will use it, and rehearsing the decision points now is the best insurance you can put in place before you ever need to use it. For managers and DPOs who want to build this knowledge more formally, Learnsignal's CPD courses cover data protection and workplace compliance topics in more depth.

This page was last updated:

Learnsignal Education Team

Expert Tutor at Learnsignal

Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.

View all posts by Learnsignal Education Team

Subscribe to Our Newsletter

Join over 30,000+ Learnsignal students and get regular insights delivered to your inbox.

Ready to Start Your Workplace & HR Compliance Journey?

Join thousands of successful students who have achieved their qualifications with Learnsignal.

Ready to get started?

Join 100,000+ students across 130 countries. Choose a plan that fits your goals — cancel anytime.

View plans