General incident-response explainer; reporting depends on the facts and risk assessment.
What happened
The ICO’s small-organisation guidance explains the obligation to report a personal data breach without undue delay and within 72 hours where it meets the reporting threshold. The clock relates to awareness of the breach. Not every technical incident requires the same notification, and informing affected people is a separate assessment.
Source: ICO — original source ↗
What it means for your website
Prepare the response route before you need it. Your developer should know whom to contact if an exposed form, compromised account or misdirected export is discovered. Preserve relevant evidence, restrict further exposure and involve the person responsible for data protection. Do not wait for a complete forensic report before assessing whether a notification is required. Equally, do not assume that every cookie warning is a reportable personal data breach. Those are different findings. GDPRFix’s public scan is not an incident-response service; a suspected breach needs the appropriate operational and professional support.
Three useful next steps
- Name an incident contact and an out-of-hours backup.
- Record discovery times and the facts known so far.
- Assess reporting duties promptly using the official guidance.
Sources & context
Official sources consulted on 1 October 2026. A regulator’s announcement records its findings at that time; it is not proof of payment or the outcome of every later appeal.
ICO — original sourceOur practical suggestions are GDPRFix commentary. A public website scan cannot establish your full legal position. For advice on a specific obligation or enforcement matter, use a suitably qualified adviser.