When do I need to report a data breach?
15th July 2023
When do I need to report a data breach?
To report, or not to report. That is the question.
One of the crucial aspects of GDPR compliance is understanding when to report a personal data breach to the Information Commissioner’s Office (ICO).
Before delving into reporting obligations, it is essential to be aware of what constitutes a personal data breach. According to UK GDPR, a personal data breach is any security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access to personal data. This definition encompasses both intentional and unintentional incidents.
Article 33 of the GDPR makes the position on reporting personal data breaches very clear; it states:-
‘the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority’ … ‘unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons’.
The default position is that you will report a personal data breach unless you can demonstrate that it is unlikely that any harm will be caused to individuals.
The first step in determining whether to report a breach to the ICO is assessing its severity. UK GDPR distinguishes between two types of personal data breaches: “minor” and “serious.” Minor breaches are incidents that do not pose a significant risk to the rights and freedoms of individuals, while serious breaches may result in high risks for the affected data subjects.
If it is likely that there is a risk to individuals, then you should report the breach.
The ICO has some useful tools to help. One is a self-assessment tool that walks you through some questions and gives you an outcome.
They also paint some scenarios using case studies to give examples of what does or does not need reporting as not every breach needs reporting. Here is an example of one of the case studies from the ICO website :-
Case study 2: Emailing a file in error
What happened?
A debt insolvency agent emailed a vulnerable new client’s file in error to a colleague in a different department. The colleague who received the file immediately deleted the email and informed the sender of the error.
Why was this a problem?
The file contained a list of the client’s outstanding debts, their contact details, basic financial history, information about their mental health and reasons for seeking support with their financial situation. The client was vulnerable due to their mental state.
What did the data controller do?
The sender and recipient work for the same organisation in similar roles, but in different departments. Both work to the same data security measures and have completed training on working with vulnerable people.
The recipient correctly deleted the email and informed the sender. As a result, it is very unlikely that there would be any risk of harm or detriment to the data subject, despite special category personal data being involved. Therefore, there is no legal obligation to report the breach to the ICO or inform the affected data subject.
The organisation documented the breach internally and provided guidance to staff about checking contact details when sending emails to minimise the risk to their data subjects. If the email had been sent to a member of the public, the risk to the data subject would have been higher.
Reporting decision: Documenting the breach on your internal breach log only
When do I need to report a data breach? Checklist
The 72-Hour Rule
The UK GDPR mandates that you report serious personal data breaches to the ICO without undue delay and at the latest within 72 hours of becoming aware of the incident. This tight window emphasizes the importance of promptly identifying and addressing breaches to ensure compliance.
If you believe a breach has taken place which may cause harm or distress to Data Subjects it is better to register a preliminary report with the ICO stating that a breach ‘may have occurred’ advising that further details will follow, than miss the 72-hour window.
Understanding the Risks to Individuals
When deciding whether a breach is serious enough to report, carefully evaluate the potential risks to the affected individuals. Consider factors such as the sensitivity of the compromised data, the number of affected individuals, and the potential consequences of the breach. Document your risk assessment thoroughly to support your decision-making process.
Internal Reporting Mechanisms
Establishing clear and efficient internal reporting mechanisms is crucial for your organisation to handle data breaches effectively. Ensure that all employees understand their roles and responsibilities in reporting and escalating potential breaches. Conduct regular training sessions to keep your team up-to-date with GDPR requirements. Having an easily located centralised resource such as an intranet, SharePoint site or folder with all of the policies, forms and guidance is vital when time is of the essence.
Notifying Affected Individuals
In addition to reporting the breach to the ICO, and any other relevant overseas Data Protection Authorities, the UK GDPR may also require you to inform the affected individuals if the breach poses a high risk to their rights and freedoms. Transparency is key in maintaining trust with your customers and clients.
No timescale is specified when notifying individuals as the notification period will be directly related to the potential harm. If bank details are stolen or the breach may give rise to a safeguarding issue, you should contact the affected individuals immediately.
Documenting the Breach
Detailed documentation is crucial in the event of a data breach. Maintain a comprehensive record of the breach, including its nature, the date and time of discovery, the actions taken to address it, and any communications with the ICO or affected individuals. These records will prove invaluable during regulatory investigations.
Following any actual or potential breach you should also undertake a post-incident review. This will allow you to assess if your policies and procedures worked and were followed, if any remedial risks need to be addressed, from the lessons learnt it will offer an opportunity to provide further training.
If you aren’t sure whether to report a data breach – do use the ICO’s self-assessment tool and check out the rest of their case studies. Remember that the decision usually comes down to whether there is an actual or potential risk to the individual Data Subject. If there is, report it. If you are still unsure, you are welcome to take advantage of your thirty-minute complimentary consultation with one of our specialists. Request yours here.