Resources · United Kingdom
United Kingdom · UK GDPR

How to manage data breaches

How to record a personal-data breach, classify the risk, notify the ICO and affected people when you must, and evidence the steps you took to contain it.

1 Obligations under the regulations

A personal-data breach is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. For an insurer or intermediary that is often a misdirected claims pack, a lost laptop, an email to the wrong broker, or a ransomware event — not only a cyber-attack.

UK GDPR Articles 33 and 34 · Data Protection Act 2018

Notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to people’s rights and freedoms (Article 33). If you miss 72 hours, the notification must explain the delay. Where the breach is likely to result in a high risk, tell the affected individuals without undue delay, in clear language, with the nature of the breach and the steps they can take (Article 34). Article 33(5) requires you to document every breach — the facts, effects and remedial action — whether or not you notified.

A breach that also harms customers, or that is a significant failure of systems and controls, may need a separate notification to the FCA under Principle 11 and SUP 15. Dual-regulated insurers should consider the PRA as well. If customers complain about the breach, DISP time limits apply on top. See errors and incidents where the same event is also an operational incident.

2 What do I need to do

Start the record the hour you become aware. Classification and notification decisions are faster when the facts are already in one place.

1. Record the breach as soon as you are aware

Date and time of awareness, what happened, which systems, and a first view of whose data is involved. Do not wait for a complete forensic report before the entry exists. Regzact can assist: record the breach on the Data Breaches register immediately, with the awareness time that starts the 72-hour clock.

2. Contain it and classify the risk

Stop further disclosure, preserve logs, and classify: unlikely to result in a risk, risk (ICO notification), or high risk (ICO and the individuals). Special-category data — health information on a claim is the usual insurance example — pushes the assessment up. Regzact can assist: classify the breach and assign owners and tasks for containment.

3. Notify the ICO and, where required, the people affected

If there is a risk, notify the ICO within 72 hours with the nature of the breach, categories and approximate numbers, likely consequences, and measures taken. Tell individuals where the risk is high, unless an Article 34 exception applies and you have recorded why. Assess FCA or PRA notification separately. Regzact can assist: track notification tasks, deadlines and the record of what was sent.

4. Mitigate, then close with a lesson

Reset access, recover data where you can, support affected customers, and change the control that failed. Document facts, effects and remedial action even when you decided not to notify. Regzact can assist: track mitigation through to close-out, and keep the assessment of why you did or did not notify.

3 What records do I need to keep

Article 33(5) is explicit. The ICO will ask for the file, including breaches you assessed as not notifiable.

  • Facts: what happened, when you became aware, and how it was discovered
  • Categories of data and of people affected, with approximate numbers
  • The risk classification and the reasons, including any decision that notification was not required
  • Containment steps and who carried them out
  • ICO notification, the time it was sent, and any late-notification explanation
  • Communications to individuals, or the Article 34 exception you relied on
  • FCA or PRA notifications where those were also required
  • Remedial action, root cause, and the control change that followed

Keep breach files with your UK GDPR accountability records. Match retention to your record of processing and any legal hold or ICO inquiry.

4 Using AI to streamline the process

The 72-hour decision stays with the firm. AI can prepare the assessment:

  • Turn a first report into a structured record: data types, systems and a draft timeline
  • Flag language that suggests special-category data, a high risk, or a complaint
  • Draft an ICO notification or a customer notice for a person to approve
  • Cluster similar breaches so repeat causes are visible

Do not let a model decide whether to notify the ICO or customers. Use it to assemble the file; keep the risk decision with the data-protection lead.

5 How Regzact can help

The Data Breaches register is built to record, classify, notify and mitigate: from the first report through containment, notification and close-out.

  • Immediate capture, including the time you became aware
  • Classification of risk and tasks for containment and notification
  • A record of ICO, customer, FCA or PRA notifications and of decisions not to notify
  • Mitigation tracked to close-out, with reporting and file export

Subject access requests, errors and complaints sit on the same platform when a breach triggers a second process.

Open the Registers solution · Book a demo

This is a practical how-to for compliance managers. It is not legal advice. Always check the current text of the regulations and your own policies before you act.

Keep going

Other how-tos for United Kingdom compliance teams.

Start Your Trial Today.

Join insurers, MGAs, and brokers across the UK and Ireland who have made compliance a strategic advantage. Book a personalised demo and see Regzact working with your own network.

No credit card required All regulatory frameworks included Set up in under a day

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.