When you suspect a personal data incident, you may need to tell customers, employees or other affected people. You may need to act before every detail is confirmed.
An unclear message can cause needless worry, miss useful next steps or conflict with a later ICO report. Use wording that is calm, accurate and easy to prove.
Report to the ICO within 72 hours when risk is likely
Report a personal data breach to the Information Commissioner’s Office when it is likely to risk people’s rights and freedoms. A breach occurs when personal data is lost, changed, shared, accessed or unavailable without permission.
Think of it like losing house keys. The loss matters, but the risk rises if the key tag shows the home address.
Apply the two risk thresholds
Report to the ICO at the lower threshold of likely risk. Tell affected people at the higher threshold of likely high risk.
High risk can arise when stolen data could enable fraud or account takeover. It can also cause discrimination, physical harm or serious distress.
One email sent to the wrong person may be contained quickly. A file with names, bank details and birth dates may require direct contact.
Log the moment you became aware
Follow this decision path: confirm whether personal data is involved. Assess likely risk. Report to the ICO within 72 hours where risk is likely. Then assess whether the risk is high enough to tell people directly. Update the ICO if later findings materially change the picture.
UK GDPR breach decision path
1. Data involved?
Names, emails, payroll or other personal data
2. Likely risk?
Report to ICO, where possible, within 72 hours
3. High risk?
Tell affected people clearly and without undue delay
Use separate notices for people, ICO and records
A customer letter, an ICO report and an internal log have different jobs. They should not be copies of one another.
The letter explains the practical impact in plain English. The ICO report gives the regulator factual detail and your risk assessment. The internal log keeps the evidence behind both decisions.
Each document should match its own purpose and reader.
| Document | Trigger | Timing | Keep as evidence |
|---|
| Notice to individuals | Likely high risk | Without undue delay | Final text, list, send date |
| ICO report | Likely risk | Where possible, within 72 hours | Report reference and updates |
| Internal breach record | Every personal data breach | From discovery onwards | Facts, reasoning, approvals |
Copyable notice for an affected person
Subject: Notice about your personal information
Dear [Name], on [date] we found [plain description of event]. The data that may be involved is [data categories].
We have [confirmed containment action]. We are investigating [unconfirmed point].
This may create a risk of [specific risk]. Please [practical action, such as changing a password or watching for suspicious messages].
We will update you by [date] if material facts change. Contact [Data Protection Officer or named contact], [email], [telephone].
We are sorry this has happened.
Use the same checked facts, but change the format for the reader and urgency. A formal breach notification letter gives you a lasting record.
It can suit an employee, a vulnerable customer or a matter likely to lead to a complaint. An email notification should put the practical action first.
Use the subject line and opening paragraph for this action. For example, write: “Action requested: change your account password”.
A follow-up message should not repeat guesses. It should name the first notice and state what is now confirmed. It should correct any material point and explain any change to the recommended action.
Keep one approved master version in editable Word format. Keep a locked PDF copy and plain copyable text.
This helps you evidence the final breach notification letter across each channel.
Say what is known, then protect the evidence
When facts are unclear, separate confirmed facts from matters still under investigation. Give a clear date for the next update.
Do not say nobody will suffer harm unless you can prove it. Do not say data was deleted unless you can prove it. Do not promise credit monitoring unless you can deliver it.
Clear uncertainty is safer than false reassurance.
Check the notice before it leaves
Before release, ask the Data Protection Officer or responsible director to check these points:
- Facts match the incident log and forensic findings available that day.
- Each recipient can receive the notice, and their contact details are current.
- The wording explains data types, likely risks, protective steps and a monitored contact route.
- Save the final version, approval name, send time and delivery evidence.
Send a follow-up only when it matters
These templates do not replace legal, forensic or regulatory advice for serious, complex or cross-border incidents. Do not use them as a notice to affected people where no personal data is involved. Do not use them instead of an ICO report where one is required. Escalate at once where fraud, physical harm, extortion, contractual loss or a relevant cyber insurance claim is possible.
Match the wording to the incident
For an email sent to the wrong person, explain whether the message was recalled or deleted. State what personal data it contained. State whether the recipient confirmed deletion.
Do not call the incident contained without that confirmation. This wording matters because an unconfirmed deletion leaves a real risk.
After phishing or ransomware, state whether systems were unavailable. State whether there is evidence of unauthorised access or copying. Explain which logins or accounts people should protect.
If a laptop or paper file is lost, say whether it was encrypted or password-protected. Say whether it can be recovered. Do not imply these controls remove all risk.
For unauthorised account access, state the access period if known. State which information was viewed or changed. Explain the security steps already taken.
Tell affected people the exact action they should take. These details make the risk assessment and notice more credible.
Common questions
Do I need to report a data breach to the ICO?
Report it when the personal data breach is likely to risk people’s rights and freedoms. Where possible, file the report within 72 hours of becoming aware. Record the reason if it is late.
Do I have to tell customers about a breach?
Tell customers or other affected people when the breach is likely to create a high risk. The notice should explain the data involved and likely effects. It should also give practical actions and a contact route.
What should a breach notification letter include?
Include what happened and when it happened or was found. Include the data categories involved and possible effects. Add containment steps and contact details.
State clearly which facts are confirmed. State which facts remain under investigation.
Can I wait for all forensic results before reporting?
No, not if waiting could miss the 72-hour ICO reporting window. Send the facts you have and explain what remains under investigation. Update the ICO or affected people if material facts change.
Does ransomware always mean I must notify the ICO?
No, but ransomware always needs a written privacy assessment if personal data may be affected. This includes data accessed, copied, lost or made unavailable. No evidence of theft on day one does not prove there was no breach.
Should I tell my cyber insurer before sending a notification?
Usually yes, if your policy has a notification clause or may cover response costs. Check the policy wording promptly. Insurer consent may be needed before you appoint lawyers, forensic firms or customer support services.