What Makes A Data Breach ‘Reportable’?
18th December 2025
Any organisation can experience a data breach, whether accidentally or due to a malicious attack by threat actors. But how do we know if a data breach is serious enough to report to the ICO? Any data breach, regardless of size or cause, should be carefully assessed to decide if it needs reporting or not.
What is the definition of a data breach?
A personal data breach is any breach of security that leads to “the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.” (source: ico.org.uk) This is quite a broad definition that could apply to many scenarios. Different kinds of data breaches could include:
Access to personal data by an unauthorised third party
This is very broad but covers several scenarios, such as a team member accidentally emailing a list of customer names and addresses to a supplier instead of a colleague, a contractor working in an office seeing employee salary information on an unlocked computer screen, or a cyber criminal exploiting a weak password and downloading customer account details from a company’s network.
Unauthorised or accidental disclosure of personal data
This is known as a confidentiality breach. An example of this could be a hospital receptionist giving a caller the wrong patient’s test results because the names sounded similar, a school sending out a group email using CC instead of BCC, thus exposing every parent’s email address to all recipients, or a social worker printing off notes and leaving them in a cafe.
With the rise of remote working, especially in cafes and on public transport, sensitive data being overheard or information being read on a laptop screen is an ever-increasing risk.
Accidental loss of access to, or destruction of, personal data
This is when the organisation cannot access their data, either temporarily or permanently, and is known as an availability breach. This could be due to a laptop containing personal data being corrupted so the data cannot be accessed, a hard drive containing employee files being left on a train, or ransomware locking all files within a company’s system, preventing staff from accessing them.
Unauthorised or accidental alteration of personal data
Also known as an integrity breach, this involves data being changed, tampered with or incorrectly updated. For example, an HR assistant could type the wrong salary for an employee during a database update, a shared spreadsheet could be overwritten with incorrect data or a single column of data sorted, corrupting the whole file. Or a cyber attack could result in customer delivery addresses being altered on an eCommerce platform.
To find out if a data breach is reportable, the Controller must investigate further.
What constitutes a reportable data breach?
Every breach or incident must be reported to your DPO or Compliance Lead; however, not every personal data breach is reportable to the data protection authority. Article 33 GDPR states that a Controller MUST report a personal data breach unless the breach is “unlikely to result in a risk to the rights and freedoms of individuals”. (Source: ico.org.uk) The ICO gives examples of risks to individuals, such as discrimination, damage to reputation, financial loss, loss of confidentiality or other significant economic or social disadvantage.
If the personal data breach fulfils any or all of the following factors, then you should consider it reportable:
Discrimination
Discrimination refers to unfair or unequal treatment of individuals based on their personal data, especially when that data is used to make decisions that affect their opportunities, access to services, or treatment. For example, if a bank accidentally shares a customer’s rating with an external company, it could be used against them to deny access to services such as loans or housing.
Damage to reputation
An individual could suffer damage to their personal, social or professional reputation, e.g. a person’s social media account being hacked could result in potentially damaging content, such as personal opinions or sensitive discussions being exposed, leading to public humiliation or social backlash.
Financial loss
This is when a data breach can lead to direct financial damage involving fraud, ID or monetary theft or other monetary loss – e.g. if a bank data breach exposes customers’ bank details, leading to fraudulent transactions or theft from their accounts.
Loss of confidentiality
This refers to the unauthorised exposure or sharing of personal data that should remain private, such as medical records, legal information, or business secrets. For example, A law firm inadvertently exposes case-sensitive documents, revealing privileged information about clients or cases that could compromise their legal standing.
Other social or economic disadvantage
This category encompasses any other harm to an individual that may result from a data breach, such as mental distress, loss of job opportunities, or difficulties in accessing essential services due to compromised data. A good example of this is a government department data breach, causing the loss of important personal identification information, preventing affected individuals from accessing social services or healthcare.
Notably, the breach does not have to involve a malicious third party – accidentally deleting data, losing files, or misplacing documents could all be considered data breaches.
Another interesting factor is the nature of the data involved. Non-personal data, e.g. corporate information, is not subject to the GDPR; therefore, if a breach only involves this kind of data and no personal details about employees, customers or other individuals, then there is no obligation to report it to the ICO.
When to report a data breach
The ICO’s guidance states that all data breaches should be reported within 72 hours of the breach being discovered. A data breach report should include the following:
- A description of the nature of the data breach
- The name and details of the data protection officer, or other contact from the organisation
- A description of the potential consequences of the data breach
- What measures you have taken, or will take, to deal with and potentially mitigate the adverse effects of the data breach
The ICO acknowledges that it may take some time for all the details of a data breach to be uncovered, e.g. if the breach is complex or still ongoing. In cases like this, you should still endeavour to report the breach within 72 hours and follow up as soon as more details are discovered. The ICO website includes a self-assessment tool that can help you determine if a breach is reportable, and allows you to report a breach online. If you are still unsure, always err on the side of caution and report any suspected data breaches, as not reporting or delaying your report could result in a fine. If you decide not to report a data breach, you should still perform a risk assessment of the incident and record the results in your breach log to comply with the UK GDPR.
Should you tell the affected individuals about a data breach?
Article 34 of the GDPR states that if a data breach could result in “a high risk to the rights and freedoms of individuals”, then you should inform them as soon as possible. This could include incidents that involve sensitive or special category personal data, i.e. their health, sexual orientation, political opinions, racial or ethnic origins, genetic or biometric data, trade union membership or religious beliefs. A breach involving financial information such as bank details is also considered high risk, as this could result in financial loss. Other high-risk factors include large quantities of data being exposed, breaches that impact a group of vulnerable people, or a risk of identity theft or fraud.
If this is the case, affected individuals should be given a description of the data breach, a description of the potential consequences of said breach, contact details of the DPO or other contact where they can obtain more information, plus measures you have taken to contain or mitigate the adverse effects of the breach.
If your organisation has experienced a data breach, you should contact the ICO in the first instance. If you would like some advice or support about data breaches, including how to reduce the risk or train your team members on identifying potential breaches and how to avoid them, we can help – get in touch using the form below or call us for a chat on 01673 885533.
Author: Mike Martin LLM
Mike is an information governance specialist and one of the founder Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.
Sources