Legal sources with official primary sources

Printed ·

Hoppa till innehåll
Hoppa till svaret

When must a personal data breach be reported to the ICO?

A controller must notify the Information Commissioner without undue delay and, where feasible, within seventy-two hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to individuals. Where the risk to individuals is high they must also be told without undue delay. Every breach must be recorded internally, whether or not it is reported.

Dela sidan

Source

Source
UK GDPR Articles 33 and 34, with the Data Protection Act 2018
Acts
Data Protection Act 2018
Area
Data protection and online duties
Checked
2026-09-10

Questions

Färdigt paket

GDPR-incidentpaket

79 €, engångsköp

Det ni behöver när en personuppgiftsincident redan har inträffat: artiklarna om anmälan och underrättelse, riskprofilen och en färdig beviskedja.

Nästa steg

Vill ni använda registret i eget arbete finns tre vägar in.

Börja med din uppgift