BLS Stay Compliant
Frequently Asked Questions
Data Breaches

What Are the Timescales for Reporting a Data Breach?

The UK GDPR mandates that organisations report qualifying data breaches to the ICO within 72 hours of becoming aware of them. “Becoming aware” means the point at which an organisation has sufficient evidence to believe a breach has occurred.

Delays must be justified and documented, explaining why timely reporting was not possible. For breaches involving individuals’ data, affected persons must be informed “without undue delay” if their rights or freedoms are at significant risk.

Compliance with these timelines demonstrates accountability and helps reduce the reputational and legal impact of a breach.

Share this post