Actualizado en March 2026

Are data breach deadlines causing sleepless nights? Missing the ICO’s 72‑hour reporting window is a common worry for UK SME owners juggling customers, operations and minimal IT support. This resource explains exactly what can happen, what the ICO typically does next, how insurers may react, and the fastest practical steps to reduce legal, financial and reputational damage.
Key takeaways: what happens if you miss the ICO 72‑hour breach reporting?
- Immediate regulatory risk: Missing the 72‑hour deadline can trigger an ICO inquiry and may be treated as a compliance failure under UK GDPR.
- Fines are possible but not automatic: The ICO assesses breaches case‑by‑case; delay is one factor among severity, harm, and mitigation.
- Insurance responses vary: Some cyber policies cover costs even when reporting was late, but others require timely notification to insurers and regulators, check policy wording.
- Practical mitigation matters most: Rapid, thorough remediation, evidence preservation and a credible explanation for delay significantly reduce enforcement risk.
- Act now: Preserve logs, document timelines and notify stakeholders, the speed and quality of follow‑up usually influences outcomes more than the initial delay.
Who must report within ICO's 72‑hour GDPR deadline
Which organisations are covered
All organisations processing personal data in the UK are subject to UK GDPR and the Data Protection Act; this includes most UK SMEs, sole traders and microbusinesses that handle personal information about customers, employees or suppliers. The ICO expects controllers, the persons or entities that decide how and why personal data is processed, to report notifiable breaches.
Who is responsible inside an SME
Responsibility typically sits with the data controller (often a director, owner or designated DPO if one exists). In small firms the person responsible for IT or operations often handles reporting duties. If an SME acts as a processor for a client, contractual obligations may require the processor to report upwards; the primary duty to notify the ICO remains with the controller.
When is reporting required
A breach must be reported to the ICO without undue delay and, where feasible, within 72 hours of becoming aware if the breach is likely to result in a risk to people’s rights and freedoms (for example, fraud, identity theft, financial loss or significant distress). If reporting is late, the ICO expects an explanation and supporting evidence about the timing.
What the ICO will do first
When the ICO becomes aware of a late report (either via the organisation or third parties), common immediate steps include: acknowledge receipt, open a preliminary assessment, request further information and set a timeline for an investigation. The ICO may also issue urgent remedial instructions if ongoing risk persists.
Possible enforcement measures
Missing the deadline alone does not automatically produce a fine. The ICO’s enforcement options include:
- informal advice or warnings
- enforcement notices requiring remedial action
- monetary penalty notices (fines) under the Data Protection Act 2018
- publicity orders or reprimands
The ICO weighs the reason for delay, the harm caused, whether the organisation took reasonable steps to mitigate the breach, and the quality of cooperation.
Criminal or civil exposure
Late reporting does not usually lead to criminal prosecution unless other offences are involved (for example, wilful obstruction of the ICO). A delayed report may increase exposure in related civil claims (e.g. compensation claims by affected individuals) because it can be used as evidence that the controller failed to manage risk.
Practical timeline: what to expect after the ICO is told about a late report
- 0–7 days: ICO acknowledges report, requests further details. External communications often begin (e.g. notification to affected individuals) depending on severity.
- 7–30 days: ICO conducts preliminary assessment; may request root‑cause, logs and remediation evidence.
- 30–90 days: ICO decides whether to open full investigation. Full investigations can last many months.
- 90+ days: If enforcement action is warranted, the ICO issues notices or fines; otherwise it may close the case with guidance.
How regulators assess fines for missed ICO data‑breach reports
Legal framework and criteria
The ICO assesses penalties under UK GDPR and the Data Protection Act 2018. Key factors considered include:
- nature, gravity and duration of the breach
- number of people affected and severity of harm (financial, emotional, identity theft)
- cause of the breach (systemic failure vs isolated human error)
- controller’s level of cooperation and speed of remediation
- previous breaches or non‑compliance history
- the organisation’s size and financial position
Delay as an aggravating factor
A late notification can be an aggravating factor where it: obstructs the ICO’s ability to protect individuals, indicates poor governance, or prevents timely mitigation. However, the ICO routinely accepts reasonable explanations (for example, needing to confirm facts) if a credible timeline is provided and mitigation was rapid once the breach was discovered.
Typical fine ranges (indicative, current at time of writing)
- Lower tier: warnings or small administrative penalties for minor, well‑mitigated breaches.
- Mid tier: tens of thousands of pounds where negligence or poor controls are clear but harm is limited.
- High tier: up to several million pounds for large‑scale or severe breaches, particularly where inadequate security or systemic failures are present.
Examples and precedents are available on the ICO enforcement pages; each decision explains how delay and mitigation affected the outcome. For a list of past actions see ICO enforcement register.
Insurance cover: will cyber policies respond to late ICO reports
Key principle: read the policy wording
Cyber insurers typically require prompt notification of incidents to both the insurer and relevant regulators. Policy response to a late ICO report depends on specific clauses such as:
- notification conditions, some policies insist on immediate notification of incidents to the insurer; late insurer notification can prejudice cover.
- cooperation clauses, insurers may require reasonable cooperation and evidence preservation.
- material change/warranty clauses, failure to maintain agreed security measures can void cover.
Common insurer positions
- many cyber policies cover regulatory fines, legal costs and response costs even if the ICO report was late, provided the insurer was notified promptly about the incident itself and the insurer’s appointment of panel counsel was not obstructed.
- some policies exclude cover where the insured failed to comply with statutory reporting duties; others limit or dispute cover if the delay worsened loss.
Practical implications for SMEs
- always notify the insurer immediately when an incident is discovered, even if the ICO report is being prepared.
- retain evidence of attempts to investigate and notify (email timestamps, call logs). This documentation often persuades insurers to proceed with claims.
- expect insurers to request full incident timelines, root cause analysis and a statement explaining the reporting delay.
Comparison: insurer response to late reporting (illustrative table)
| Scenario |
Likely insurer response |
Key required evidence |
| Incident discovered and insurer notified immediately; ICO notified after 72 hours with explanation |
Often covered for response costs and fines if policy includes fines; insurer will investigate |
Discovery logs, notification timestamps, remediation records |
| Insurer not told until after ICO contacted; reporting was late |
Coverage may be disputed; insurer may limit payment for escalation of loss due to delayed notification |
Full incident timeline, reason for late insurer notification, evidence of prejudice |
| Failure to maintain security warranties or known weaknesses ignored |
High risk of repudiation; insurer may decline cover |
Records of security testing, previous communications, patch logs |
Table: illustrative scenarios showing typical insurer reactions to reporting timing. This is not legal advice, check specific policy wording.
Real SME case studies: missed 72‑hour reports and outcomes
Case study 1: a local accounting firm (anonymised)
Situation: A small accountancy practice discovered unauthorised access to client emails but took five days to confirm scope before notifying the ICO. Outcome: The ICO issued a reprimand and required improved controls; no fine, partly because the firm provided a clear timeline, cooperated fully, and offered free credit monitoring to affected clients. Insurer covered response costs after being notified as soon as the incident was discovered.
Case study 2: an e‑commerce SME (anonymised)
Situation: Payment details were suspected compromised; the owner delayed both ICO and insurer notification to avoid panic while investigating. Outcome: The ICO opened a full investigation and issued a monetary penalty for inadequate security and late reporting; insurer disputed the claim citing late notification and breach of warranty on payment security controls. Result: significant legal fees and a reduced insurance payout.
Lessons from cases
- immediate documentation of discovery and steps taken is crucial
- transparent cooperation with the ICO frequently reduces sanctions
- insurer relationships and prompt insurer notification often determine whether costs are covered
Practical checklist: steps to take if you miss ICO reporting
- Preserve evidence: do not alter logs, back up affected systems, and record timestamps of discovery.
- Notify internal decision‑makers: inform director, data lead and insurer contact (if contractually required).
- Contain the incident: isolate affected systems to prevent further data loss.
Next 24–72 hours
- compile a clear discovery timeline including when the breach was first suspected and reasons for reporting delay
- complete the ICO reporting form as soon as possible and include the explanation for delay
- communicate with affected individuals where required and provide practical advice (password resets, credit monitoring)
- brief insurer with initial facts and request their incident response panel where applicable
Evidence and reporting checklist (what to include when reporting late)
- exact discovery time and first actions taken
- reason for delay (for example, needing to confirm scope to avoid false alarms)
- mitigation steps and any remediation already completed
- sample logs, forensic reports and communications with third parties
- copy of communications to affected individuals (if sent)
🔁 Quick process flow
Step 1 ⚡ discovery → Step 2 📝 preserve evidence → Step 3 ☎ notify insurer/board → Step 4 🧾 complete ICO report with timeline → ✅ mitigation & follow up
Timeline: what the ICO expects after a late report
Within 72 hours
Assess risk, preserve evidence, notify ICO if possible.
Day 4–14
Provide ICO with full timeline and mitigation; cooperate with insurer.
Week 3–12
Potential ICO preliminary assessment; prepare for investigation.
Strategic balance: assessing what is gained and what is risked by late reporting
✅ When a delayed notification is understandable (scenarios of lower risk)
- where immediate notification would confirm yet‑unverified scope and produce unnecessary alarm
- when remediation is rapid, and no material harm to individuals occurred
- when the organisation documents every step and communicates transparently once facts are clear
⚠️ Red flags that increase enforcement risk
- systemic security failures or ignored known vulnerabilities
- concealment or misleading information to the ICO or affected individuals
- failure to notify the insurer promptly or to follow policy notification conditions
- repeated breaches or poor historic cooperation with regulators
What others ask: common questions about what happens if you miss the ICO 72‑hour breach reporting?
How soon must an SME report a data breach to the ICO?
An SME must report a notifiable breach without undue delay and where feasible within 72 hours of becoming aware; the obligation applies if the breach is likely to result in a risk to individuals’ rights and freedoms. Context: immediate, practical steps and mitigation can affect whether the incident meets the threshold.
Why does the 72‑hour clock start on discovery?
The 72‑hour period starts when the organisation becomes aware of the breach because that is when the controller can reasonably begin mitigation and notification processes. Context: discovery may be delayed in complex incidents; explaining why is essential.
What happens if the ICO is told later than 72 hours?
The ICO may investigate the reason for delay and consider it when deciding on enforcement; a credible explanation and evidence of prompt mitigation often reduce the likelihood of a fine. Context: delay alone is rarely the sole cause of a penalty.
Can a late report void cyber insurance cover?
A late ICO report does not automatically void cover, but failure to notify the insurer promptly or breach of policy conditions (security warranties) can lead to repudiation or reduced payment. Context: always notify insurers as soon as the incident is discovered.
How should the reason for delay be documented?
Provide a clear, verifiable timeline, including discovery timestamps, investigation steps, reasons for the delay and mitigation actions taken; include logs and communications where possible. Context: the ICO and insurers rely on documentary evidence when assessing a late report.
Which regulators besides the ICO might take interest?
Depending on sector, regulators such as the Financial Conduct Authority (FCA) or sectoral bodies may become involved, particularly if regulated services or payments were affected. Context: sectoral rules can impose additional reporting duties.
Final thoughts: moving from panic to control
Missing the ICO’s 72‑hour window is stressful, but it is not necessarily catastrophic if handled correctly. The ICO places weight on honesty, cooperation and credible mitigation. Insurers will examine timelines, so early notification to insurers and rigorous evidence preservation are crucial. The most effective outcome stems from calm, documented action rather than delay or concealment.
- Preserve evidence now: secure logs, screenshots and timestamps. (5–10 minutes)
- Notify the insurer and document that notification (phone note or email). (5 minutes)
- Complete the ICO breach report with a clear timeline and reasons for delay; include remediation steps. (10 minutes)