What Is The 72-Hour Rule Under GDPR?

If your organisation suffers a personal data breach, you will need to know about the 72-hour rule. It refers to the requirement under UK GDPR to notify the Information Commissioner's Office within 72 hours of becoming aware of a breach, where that breach is likely to pose a risk to the rights and freedoms of individuals. It is one of the tightest compliance deadlines in data protection law, and missing it, or having no clear process for meeting it, can result in regulatory action on top of the underlying breach itself.

A personal data breach is any security incident that leads to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of, or access to, personal data. Not every breach needs to be reported to the ICO. The notification duty applies where the breach is likely to result in a risk to individuals, for example where personal data has been accessed by someone who should not have had access to it, where sensitive information has been sent to the wrong person, or where data has been lost in a way that could expose people to harm.

The ICO's breach reporting guidance explains how to assess whether a breach is notifiable and what information you will need to provide when you report.

The clock starts when the organisation becomes aware of the breach. In practice, this means the moment a responsible person within the organisation has enough information to know that a breach has occurred or is likely to have occurred. It does not require certainty about the full scope of what happened, but it does require prompt action once you have reasonable grounds to believe a breach has taken place.

Your notification needs to include a description of what happened, the categories and approximate number of individuals and records affected, the likely consequences of the breach, and the measures you have taken or plan to take in response. If you cannot provide all of this within 72 hours, you can notify in phases, provided there is a good reason for the delay and you explain it clearly.

Next
Next

What Is A DPIA And When Is It Needed For Workplace AI Tools?