There are certain incidents that organisations need to tell us about. Use this page if you are an organisation that has experienced one of the following types of incident and need to report it to the ICO:

You can also report if your organisation has been affected by the Typeform data breach.

You can also report if your school has been affected by the Capita SIMS data breach.

GDPR or DPA 2018 personal data breach

From 25 May 2018, if you experience a personal data breach you need to consider whether this poses a risk to people. You need to consider the likelihood and severity of any risk to people’s rights and freedoms, following the breach. When you’ve made this assessment, if it’s likely there will be a risk then you must notify the ICO; if it’s unlikely then you don’t have to report it. You do not need to report every breach to the ICO.

A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This includes breaches that are the result of both accidental and deliberate causes. It also means that a breach is more than just about losing personal data.

For more information about what a personal data breach is and when you need to report it to us, please see the personal data breach pages of our Guide to the GDPR or if you are processing personal data for law enforcement purposes please see our Guide to Law Enforcement Processing.

You can also voluntarily report data security breaches that occurred before 25 May 2018, following the same process for reporting breaches of the DPA 2018.

 Report a data security breach

PECR security breach (for telecoms and internet service providers)

Under the Privacy and Electronic Communications Regulations (PECR), organisations who provide a service allowing members of the public to send electronic messages (eg telecoms providers or internet service providers) are required to notify us if a personal data breach occurs. If you are subject to PECR and you experience a personal data breach, you should continue to report under PECR. There is no need to report under the DPA 2018, too.

 Report a data security breach (PECR)

Notifiable incident under the NIS Regulations

This form is for Relevant Digital Service Providers to notify the ICO of an incident under the NIS Regulations.

Report a NIS incident

Notifiable breaches of the eIDAS Regulation

This form is for Trust Service Providers and Qualified Trust Service providers to report notifiable breaches of the eIDAS regulation, pursuant to Article 19 (2) of the Regulation.

Report an eIDAS breach 


For information about what we do with personal data see our privacy notice.