Skip to main content

SponsoredBuild your website with Vincony

Disclaimer: This is not legal advice. Legislation and case law change. Always consult a qualified solicitor for your specific situation.

UK Law Reference
โ† All Templates
Data Protection
Data Protection Law
Updated 2026-06-16

ICO Data Breach Notification Letter

Letter to the Information Commissioner's Office (ICO) reporting a personal data breach under UK GDPR Article 33 / DPA 2018.

This template was not drafted by a solicitor.

It is an editorial reference based on the official sources we cite. You are responsible for any document you send. For high-stakes matters (court proceedings, large sums, deportation, criminal allegations, child welfare), have a regulated solicitor review or draft your document.

When to use this template

Use within 72 hours of becoming aware of a personal data breach where there is a risk to the rights and freedoms of natural persons. This is a statutory obligation on data controllers under UK GDPR Article 33. Failure to report a notifiable breach is itself a serious infringement.

When NOT to use this template

Do not use if the breach is unlikely to result in a risk to data subjects (no notification required โ€” but you should still keep an internal record). Do not use as a substitute for notifying affected data subjects directly under Article 34 where required.

Legal Basis

UK GDPR Article 33 (notification to supervisory authority); UK GDPR Article 34 (communication to the data subject); Data Protection Act 2018 s.67. 72-hour clock runs from becoming aware of the breach, not from the breach itself.

Before you send

  • Waiting for full information before reporting โ€” initial notifications can be progressive
  • Forgetting to notify the affected data subjects under Article 34 where the breach is likely to result in a high risk
  • Not keeping an internal breach register (mandatory under Article 33(5))

Common Mistakes to Avoid

  • โœ—Waiting for full information before reporting โ€” initial notifications can be progressive
  • โœ—Forgetting to notify the affected data subjects under Article 34 where the breach is likely to result in a high risk
  • โœ—Not keeping an internal breach register (mandatory under Article 33(5))
  • โœ—Treating containment / forensic investigation as a substitute for ICO notification
  • โœ—Failing to identify the breach DPO contact for the ICO to follow up

Build Your Letter

Fill in your details

Complete the fields below. Required fields are marked with *.

Optional fields

Letter preview

[ORGANISATION NAME]
[ORGANISATION REGISTERED ADDRESS]
ICO Registration Number: [ICO REGISTRATION NUMBER]

[TODAY'S DATE]

The Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF

---

**PERSONAL DATA BREACH NOTIFICATION โ€” UK GDPR Article 33**

Reference: [INTERNAL BREACH REFERENCE]

**1. Data controller details**

Organisation: [ORGANISATION NAME]
ICO Registration: [ICO REGISTRATION NUMBER]
Data Protection Officer / contact: [DPO OR DATA-PROTECTION CONTACT NAME], [DPO EMAIL], [DPO PHONE]

**2. Nature of the breach**

Date and time of breach (or first awareness): [DATE/TIME YOU BECAME AWARE OF THE BREACH]
Date and time of containment (if applicable): [DATE/TIME OF CONTAINMENT (IF KNOWN)]

Description of the breach:

[FACTUAL DESCRIPTION OF THE BREACH]

Categories of personal data affected:

[CATEGORIES OF PERSONAL DATA AFFECTED]

Approximate number of data subjects affected: [APPROXIMATE NUMBER OF DATA SUBJECTS AFFECTED]
Approximate number of personal data records concerned: [APPROXIMATE NUMBER OF RECORDS CONCERNED]

**3. Likely consequences**

We assess the likely consequences for affected data subjects as follows:

[LIKELY CONSEQUENCES FOR AFFECTED SUBJECTS]

**4. Measures taken or proposed**

Containment measures already taken:

[CONTAINMENT MEASURES TAKEN]

Remediation measures planned:

[REMEDIATION MEASURES PLANNED]

**5. Communication to data subjects**

[PLAN FOR NOTIFYING AFFECTED DATA SUBJECTS (ARTICLE 34)]

**6. Cross-border element**

[CROSS-BORDER DATA FLOW INVOLVED?]

**Additional information**

[ANY ADDITIONAL INFORMATION]

We will provide further information as the investigation progresses. The point of contact for any follow-up is [DPO OR DATA-PROTECTION CONTACT NAME] at [DPO EMAIL].

Yours faithfully,

[SIGNATORY NAME]
[SIGNATORY ROLE]
[ORGANISATION NAME]

Unfilled fields appear as [FIELD NAME]. Review the letter carefully before sending. This template is a starting point โ€” adapt it to your specific circumstances.

Related Guides

Frequently asked questions

How long do I have to report a data breach to the ICO?
You must notify the ICO within 72 hours of becoming aware of a personal data breach if there is a risk to the rights and freedoms of natural persons. This is a statutory obligation under UK GDPR Article 33. The 72-hour clock starts when you become aware of the breach, not when the breach itself occurred. Failure to report a notifiable breach is a serious infringement.
Do I have to tell the ICO about every data breach?
You do not need to notify the ICO if the breach is unlikely to result in a risk to data subjects. However, you must still keep an internal record of the breach. Additionally, this notification to the ICO is separate from the requirement to notify affected data subjects directly under Article 34 if the breach poses a high risk to them.
Can I send the notification before I have all the facts?
Yes, you can submit an initial notification and provide further information as your investigation progresses. You should not wait for full details before reporting. The letter template includes a section for additional information and confirms that you will provide updates. This progressive approach is acceptable as long as the initial notification is made within the 72-hour window.
Is fixing the breach enough, or do I still need to notify the ICO?
No, taking steps to contain the breach or conducting a forensic investigation does not replace the legal requirement to notify the ICO. Treating these actions as a substitute for formal notification is a common mistake. You must still submit the statutory notification under UK GDPR Article 33 if the breach poses a risk to individuals, regardless of your internal containment efforts.
Do I need to keep a record of breaches that I don't report to the ICO?
Yes, keeping an internal breach register is mandatory under UK GDPR Article 33(5). You must record all personal data breaches, even those that do not require notification to the ICO because they are unlikely to result in a risk to data subjects. Failing to maintain this register is a compliance failure.