How do I report a breach?

If your organisation has experienced a data breach our personal data breach helpline staff can offer you advice about what to do next, including how to contain it and how to stop it happening again. We can also offer advice about whether you need to tell the data subjects involved.  

To report a breach, call our helpline. Our normal opening hours are Monday to Friday between 9am and 5pm. When you call we will record the breach and give you advice about what to do next. If you would like to report a breach outside of these hours, you can report online. For more information about how we use your personal information, see our privacy notice

 Call us, 0303 123 1113

What information will I need to provide?

When you phone, we'll ask you questions about:

  • what has happened;
  • when and how you found out about the breach;
  • the people that have been or may be affected by the breach;
  • what you are doing as a result of the breach; and
  • who we should contact if we need more information and who else you have told.

We'll send you a copy of the information you give us. 

Can I report a breach online?

If you have experienced a data breach and need to report it to the ICO but you’re confident you have dealt with it appropriately, you may prefer to report it online. You may also want to report a breach online if you are still investigating and will be able to provide more information at a later date. The online form can also be used to report breaches outside our normal opening hours.

Personal data breach reporting form (Right click on the link and select 'Save Link As' or 'Save Target as' to download the form before you begin to edit it.)

If you are reporting online please make sure you include the telephone number of someone familiar with the breach, in case we need to follow up with you about any of the information provided.

If you are unsure about any of the questions within the form, or if have any concerns about how to manage the breach please call us, 0303 123 1113.

Health sector breaches in England

Health and care organisations should report breaches using the Data Security and Protection Incident Reporting tool. For guidance on how to use the tool, see the toolkit help pages.

What we do with the information you provide

When reporting a breach, you should give as much detail as possible and be as accurate as you can. We will use the information you provide to decide what should happen next. We may use it to take regulatory action, or to identify data security incident trends. Where appropriate, we may share it with law and cybercrime agencies or other regulators. This may include the National Cyber Security Centre, the National Crime Agency or the National Fraud Intelligence Bureau. We may also share information with other regulators, such as the Financial Conduct Authority. Where an incident is relevant to another country, we may also share the information with appropriate regulatory representatives in that country. Let us know if you’d like more information about this.

For more about how we use your information, see our privacy notice