# Personal data breach notification obligations

> **Key takeaway:** 72 hours from awareness to notify ICO unless unlikely to risk individuals' rights; notify individuals directly (without undue delay) only if likely to cause high risk, subject to encryption/mitigation/disproportionate-effort exceptions. Document every breach and every decision, notified or not.

- **Jurisdiction:** England & Wales
- **Practice area:** Commercial
- **Last reviewed:** 2026-09-05
- **Interactive page:** https://www.kttclegal.info/library/notes/Commercial/personal-data-breach-notification
- **Keywords:** data breach, breach notification, Article 33, Article 34, 72 hours, ICO notification, high risk, UK GDPR

## What is this about?

A personal data breach triggers a fast-moving assessment: whether the ICO must be told, whether affected individuals must be told, and how quickly. Both duties turn on the level of risk the breach poses to people's rights and freedoms, assessed at the point the controller becomes aware of it.

## What is the core rule?

Article 33 requires a controller to notify the ICO of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. If notification is not made within 72 hours, reasons for the delay must be given. Article 34 requires notification to the affected individuals themselves, without undue delay, only where the breach is likely to result in a high risk to their rights and freedoms — a higher threshold than the ICO trigger — subject to exceptions where appropriate protective measures (e.g. encryption) were already applied to the affected data, or notification would involve disproportionate effort (in which case a public communication may suffice). Processors must notify their controller without undue delay on becoming aware of a breach (Art 33(2)), starting the controller's own clock.

## What are the elements or test?

1. Has a 'personal data breach' occurred — a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data?
2. When did the controller become 'aware' of the breach (this starts the 72-hour clock, not the date the breach occurred)?
3. Risk assessment: is it likely to result in a risk to individuals' rights and freedoms (ICO notification threshold)?
4. Higher risk assessment: is it likely to result in a high risk (individual notification threshold)?
5. If individual notification threshold met: do any Art 34(3) exceptions apply (prior protective measures, subsequent risk mitigation, or disproportionate effort justifying public communication instead)?
6. Document the breach, the assessment, and the decision even where no notification is made (Art 33(5) record-keeping duty)

## Which authorities matter?

- **UK GDPR, Art 33** — Sets the 72-hour ICO notification duty (subject to a low-risk exception) and requires reasons for late notification.
- **UK GDPR, Art 34** — Sets the higher 'high risk' threshold for notifying affected individuals directly, subject to specific exceptions.
- **UK GDPR, Art 33(5)** — Requires the controller to document all breaches, including those not notified, sufficient for the ICO to verify compliance.
- **ICO guidance on personal data breaches** — Sets out the ICO's practical expectations for the risk assessment and the 72-hour timeline, and its self-reporting tool.

## How does this apply in practice?

This note covers the notification decision framework, not incident response or forensic/technical breach management, and does not address sector-specific breach reporting duties that can run in parallel (e.g. under NIS regulations for certain digital service providers). 'Awareness' is a fact-sensitive trigger — it is when the controller has a reasonable degree of certainty a breach has occurred, not necessarily the first suspicion of an anomaly.

## What are common pitfalls?

- Calculating the 72 hours from when the breach occurred rather than from when the controller became aware of it
- Treating the ICO notification threshold (risk) and the individual notification threshold (high risk) as the same test
- Failing to document a decision not to notify, leaving no evidence of the risk assessment if later challenged
- Assuming a processor's notification to the controller discharges the controller's own Art 33/34 obligations
- Overlooking that encryption or other protective measures already in place can remove the need to notify individuals under Art 34(3)(a)

## When would a practitioner use this?

Time-critical advice in the immediate aftermath of a suspected data breach, and in post-incident review of whether notification obligations were properly discharged.

## Quick reference

72 hours from awareness to notify ICO unless unlikely to risk individuals' rights; notify individuals directly (without undue delay) only if likely to cause high risk, subject to encryption/mitigation/disproportionate-effort exceptions. Document every breach and every decision, notified or not.

---

*Reference material from [KTTC Legal](https://www.kttclegal.info/), not legal advice. Work product supports instructing solicitors and barristers under their supervision. England & Wales.*
