Data breach
Personal data lost, stolen or exposed. Seventy-two hours to report.
Please note: This page explains what a term means. It is general information, not legal, financial, tax or investment advice, and it does not know anything about your business. Before you sign, file or commit to anything, check it with an accountant, a solicitor, or the official guidance we link to.
What it means
A personal data breach is a security incident leading to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to personal data.
Why it matters
Where it risks people's rights and freedoms it must be reported to the ICO within 72 hours of becoming aware, and to the individuals themselves where the risk is high.
What it looks like in practice
It is not only hacking: an email sent to the wrong person, a lost laptop, a misconfigured folder, and a bin bag of paper all qualify.\n\nKeep a breach log of every incident including those not reported, with the reasoning. The ICO expects it.
What to watch out for
The clock starts at awareness, not at investigation. Businesses lose the window deciding whether it is serious.\n\nAnd notifying customers badly — see crisis communications.
Where to get proper advice
The ICO's breach reporting service and helpline, both free. Your insurer, because cyber policies have notification conditions.
Where to read more
Last reviewed 2026-08-28 by Fiducia Together · Next review due 2027-08-28
Please note: This page explains what a term means. It is general information, not legal, financial, tax or investment advice, and it does not know anything about your business. Before you sign, file or commit to anything, check it with an accountant, a solicitor, or the official guidance we link to.
Fiducia Together