A breach: when does 72 hours apply?

Some incidents must be reported quickly. First establish what happened and the risk to people.

By GDPRFix · Published · 2 min read
AI-assisted reporting and commentary · Official sources linked below.
Practical explainer

General incident-response explainer; reporting depends on the facts and risk assessment.

What happened

The ICO’s small-organisation guidance explains the obligation to report a personal data breach without undue delay and within 72 hours where it meets the reporting threshold. The clock relates to awareness of the breach. Not every technical incident requires the same notification, and informing affected people is a separate assessment.

Source: ICO — original source ↗

What it means for your website

Prepare the response route before you need it. Your developer should know whom to contact if an exposed form, compromised account or misdirected export is discovered. Preserve relevant evidence, restrict further exposure and involve the person responsible for data protection. Do not wait for a complete forensic report before assessing whether a notification is required. Equally, do not assume that every cookie warning is a reportable personal data breach. Those are different findings. GDPRFix’s public scan is not an incident-response service; a suspected breach needs the appropriate operational and professional support.

Three useful next steps

  1. Name an incident contact and an out-of-hours backup.
  2. Record discovery times and the facts known so far.
  3. Assess reporting duties promptly using the official guidance.

Sources & context

Official sources consulted on 1 October 2026. A regulator’s announcement records its findings at that time; it is not proof of payment or the outcome of every later appeal.

ICO — original source

Our practical suggestions are GDPRFix commentary. A public website scan cannot establish your full legal position. For advice on a specific obligation or enforcement matter, use a suitably qualified adviser.

Keep reading