Calculate: Discovery date/time + 72 hours
Use this checklist to assess whether a personal data breach is reportable to the ICO and/or affected individuals, and to document your decision-making process.
Under Article 33 of the UK GDPR, you must report a notifiable breach to the ICO within 72 hours of becoming aware of it. Use this checklist as soon as a potential breach is identified. Document your assessment even if you decide the breach is not reportable.
Calculate: Discovery date/time + 72 hours
A personal data breach can involve confidentiality, integrity, and/or availability. Select all that apply:
If any special category or criminal conviction data is involved (marked with ⚠️), this significantly increases the likelihood that the breach is reportable and that individuals should be notified.
Consider the potential consequences for affected individuals. Check all risks that may apply:
Are there any factors that reduce the risk of harm? Check all that apply:
This documentation is essential for demonstrating accountability to the ICO
You must document all breaches, regardless of whether they are reported to the ICO. Keep this completed assessment securely for at least 6 years. The ICO may request to see your breach records during an audit or investigation.