Identity admin reviewing MFA enrollments illustrating what is a breach of gdpr

What Is a Breach of GDPR and How It Affects Organisations

A personal data breach under UK GDPR is any breach of security established to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data; the statutory test for notifying the Information Commissioner’s Office is whether the breach is likely to result in a risk to people’s rights and freedoms. The UK General Data Protection Regulation and the Data Protection Act 2018 set the legal definition, and the Information Commissioner’s Office explains what counts as a breach and how controllers should assess risk (Information Commissioner’s Office, PAIR 2025).

The decision to notify the Information Commissioner’s Office depends on the likelihood that the breach will result in a risk to individuals’ rights and freedoms, not on the mere occurrence of an incident; the Information Commissioner’s Office’s incident guidance and the Information Commissioner’s Office’s Data Security Incident Trends dashboard explain notification expectations and recordkeeping requirements (Information Commissioner’s Office, Data Security Incident Trends). The National Cyber Security Centre provides practical response steps for loss of confidentiality, integrity or availability of personal data (National Cyber Security Centre, data breach guidance).

  • Definition: A personal data breach is any breach of security causing accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data (Information Commissioner’s Office, PAIR 2025).
  • Notification test: You must assess whether the breach is likely to result in a risk to people’s rights and freedoms; that assessment governs notifying the Information Commissioner’s Office (Information Commissioner’s Office, Data Security Incident Trends).
  • Response sources: Use the National Cyber Security Centre’s guidance for practical steps on containment, recovery and evidence collection (National Cyber Security Centre, data breach guidance).
  • Practical step: Record your breach assessment, the rationale for any notification decision, and the evidence supporting that decision to meet UK GDPR and the Data Protection Act 2018 expectations.

📘 What is a GDPR breach?

A GDPR breach, under UK GDPR and the Data Protection Act 2018, is any security incident that causes accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data and that is likely to result in a risk to the rights and freedoms of the individuals involved.

How the law treats controllers and processors

Under UK GDPR, a controller determines why and how personal data is processed, while a processor acts on the controller’s instructions. Whether an event is a breach depends on the effect on personal data confidentiality, integrity or availability, not on the label applied to the organisation. Controllers must assess incidents and consider notification obligations to the Information Commissioner’s Office (ICO), following the ICO’s reporting guidance and datasets (Information Commissioner’s Office, 2025).

What counts as personal data, and short examples

Personal data includes any information that identifies a person, such as names, email addresses, IP addresses, and special category data such as health records. Practical breach examples include an unencrypted laptop containing payroll files being lost, a mis-sent email with client personal data, or a ransomware incident that encrypts and makes data unavailable. Each example requires analysis of the scale of data involved and the likely harm to individuals.

Detection, containment and notification

The National Cyber Security Centre’s guidance on handling data breaches sets out sensible immediate steps for containment, recovery and notification (National Cyber Security Centre, 2018). Incident analysis should map what data was affected, how many people were likely impacted, and the probable consequences for those people, so you can decide whether to notify the ICO and the data subjects and meet the UK GDPR expectation of timely reporting.

How we help

At CyPro, we help organisations translate breach definitions into practical checks and playbooks. Our Managed Detection and Response (MDR) service speeds detection and containment, and our ISO 27001 work reduces the chance of accidental loss through better controls and evidence for compliance exercises.

🔎 What constitutes a GDPR breach?

Engineers preparing encrypted key material illustrating what is a breach of GDPR

A breach of UK GDPR occurs when accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data creates a risk to people’s rights and freedoms.

Deciding whether an incident meets that legal test requires assessing the data involved, how likely harm is, and the severity of that harm. The Information Commissioner’s Office’s PAIR dataset and incident trends provide the UK benchmarks that help with this assessment (Information Commissioner’s Office (ICO), 2025, Information Commissioner’s Office, Data security incident trends).

Quick comparison: Common incidents and whether they usually count as a UK GDPR breach

Incident typeTypical exampleUsually reportable under UK GDPR?
Misdirected communicationsEmail sent to the wrong external recipient containing names and NHS numbersYes, if identifiers increase the risk of identity theft or other harm
Stolen or lost deviceUnencrypted laptop containing client personal data taken from a carYes, if data is accessible without strong protection
System intrusionUnauthorised access to a database, with evidence of data exfiltrationYes, almost always reportable because of probable high risk
Operational errorBackups uploaded to a public cloud bucket by mistakeDepends on data sensitivity and likelihood of access by others

Organisational failings, such as missing Data Protection Impact Assessments, weak access controls, or an absent lawful basis for processing, can turn a technical fault into a reportable breach. The European Union Agency for Cybersecurity’s threat environment research shows that system intrusions and human error remain major root causes for incidents across Europe (ENISA, threat environment 2025).

When you assess an incident, document: What personal data was involved, how many people were affected, the ease of identification, and the likely consequences such as identity theft, financial loss, discrimination or reputational harm. If the assessment points to likely risk, the ICO expects notification and timely communication to affected individuals. Strengthening detection and response through Managed Detection and Response (MDR) and aligning to ISO 27001 risk assessments (ISO 27001) speeds accurate decision making and reduces regulatory uncertainty.

Download Your Free Cyber Incident Response Plan.
Download our free cyber incident response plan (including Ransomware runbook) just in case the worst happens.
Download
Playbook explaining how to survive a ransomware attackPlaybook explaining how to survive a ransomware attack

🔍 Is a ‘disposable breach’ a data breach?

Yes. A ‘disposable breach’ is a data breach under UK GDPR when improper disposal of personal data causes unauthorised access, loss or theft, or creates a realistic risk to people. When assessing whether what is a breach of GDPR occurred, focus on the data exposed, the likelihood of harm and the scale of exposure.

UK GDPR requires controllers to notify the Information Commissioner’s Office (ICO) about personal data breaches that are likely to result in a risk to individuals’ rights and freedoms. Practical examples include discarded devices with unencrypted personal data, shredded documents dumped publicly, or improperly decommissioned cloud storage containing personal records.

When disposal becomes a reportable personal data breach

Disposal becomes reportable if the incident meets the ICO threshold: A realistic risk of harm to individuals. The ICO’s Data Security Incident Trends and reports show personal data incidents remain frequent, so organisations must document assessments and mitigation. Technical guidance from the National Institute of Standards and Technology (NIST) explains secure disposal and recovery options for breached data, which helps when proving you took reasonable steps (NIST SP 1800-29, 2024).

In our experience, clear evidence of what was disposed, why it was disposable, and the controls you had in place speeds decision-making. If disposal involved data exfiltration or theft the event is a breach that must be contained and likely reported. Industry data shows system intrusions and misconfiguration remain common causes of breaches, underlining the need to treat disposal incidents with the same rigour as other breaches (Verizon DBIR, 2025).

Practical steps to reduce regulatory risk include documented retention schedules, secure wiping, verified destruction, and evidence of chain of custody. For organisations seeking a fit-for-purpose plan, our Cyber Resilience service maps disposal controls to retention policy and incident response, so you can answer the question what is a breach of GDPR confidently.

📣 When and how must you report a GDPR breach to the ICO?

Close-up of analyst hands at SIEM console inspecting alerts about what is a breach of GDPR

Under UK GDPR you must notify the Information Commissioner’s Office (ICO) of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to individuals. This is the baseline for deciding whether and when to notify.

What the ICO expects in your report

The ICO expects a concise description of the nature of the personal data breach, categories of personal data involved, likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Include dates, numbers of data subjects affected, and contact details for a Data Protection Officer or other point of contact. If you cannot provide full details within 72 hours, submit what you have and update the ICO later with the missing information.

When to notify data subjects and exceptions

You must notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms. If you can show you implemented appropriate technical and organisational protection measures, notification to individuals may not be necessary. Record your risk assessment and why you decided whether to notify individuals, because the Data Protection Act 2018 requires detailed record-keeping of breaches and decisions.

Practical evidence and follow-up

When preparing an ICO report, include evidence of your investigation, timeline of discovery, containment steps, and remediation plans. In our experience, documenting who discovered the event, the systems and data involved, and the likely harm accelerates the ICO review and supports defensible responses to affected parties and regulators. For organisations that want external support with investigations and evidence capture, our Cyber Security Consultants service can help produce the technical evidence and statements the ICO expects.

IBM Report: UK Sees Drop in Breach Costs as AI Speeds Detection shows trends in breach discovery that affect reporting timelines. IBM: 13% of organisations reported breaches of AI models highlights newer data types you must consider when deciding what is a breach of GDPR.

⚖️ What happens if a company breaches GDPR?

Identity lifecycle manager leading access review illustrating identity and access governance

A breach of UK GDPR means personal data has been accidentally or unlawfully destroyed, lost, altered, disclosed or accessed without authorisation, and the incident creates a risk to people’s rights and freedoms. If you ask what is a breach of GDPR, the answer is an event where personal data security is compromised.

Regulatory powers and likely enforcement

The Information Commissioner’s Office (ICO) can investigate, require remedial steps, and issue fines under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. The ICO can impose corrective orders, audits and monetary penalties depending on breaches and harm. Organisations should expect regulatory action where systemic failures or poor governance contributed to the breach. The National Cyber Security Centre’s annual review highlights how complex incidents involving wide exposure often attract deeper scrutiny from regulators and sectors with higher privacy risk, such as financial services and healthcare (NCSC, 2025).

Financial and commercial consequences

Fines are only one consequence. A company can face contract terminations, claims for compensation from affected people, and higher insurance premiums. The commercial fallout often includes lost customers and supplier trust, and increased due diligence from partners. Data breaches that start with system intrusions are a major cause of large-scale exposures in EMEA, and Verizon’s 2025 findings show system intrusions account for a large share of breaches, which informs how insurers and counterparties view post-breach risk (Verizon DBIR, 2025).

Practical remediation steps

When answering what is a breach of GDPR in practice, firms must contain the incident, assess affected data, notify the ICO within 72 hours when required, and inform data subjects if there is high risk. In our experience, timely evidence capture and a clear remediation plan reduce enforcement severity. For help with preparing remediation and board-ready statements, our Cyber Strategy and Roadmap service and IT Disaster Recovery Plan service can provide practical, testable playbooks (Cyber Strategy and Roadmap, IT Disaster Recovery Plan).

Case Study IconCase Study, Mid-market fintech, faster ICO closure

A mid-market UK fintech suffered a credentials-based intrusion exposing customer PII across a payments platform. The incident team needed rapid evidence, containment and regulator-ready reporting to avoid prolonged enforcement.

We ran a 48-hour incident assessment, produced a technical timeline and remediation plan, and supported the ICO report using our Cyber Security Consultants service and our Cyber Strategy and Roadmap documentation.

Within six weeks the ICO closed its assessment with no fine and the client restored partner confidence, reducing contract remediation time by 60%.

🚑 How should you respond to a GDPR breach right now?

Contain the incident, assess which personal data is affected, notify the Information Commissioner’s Office (ICO) within 72 hours when required, inform affected people where there is a high risk, preserve forensic evidence and start remediation immediately.

Immediate containment and scope

Containment first: Isolate affected systems, revoke exposed credentials and block outbound data flows. When asking “what is a breach of GDPR”, remember the UK GDPR and Data Protection Act 2018 define a personal data breach as a security incident established to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. Containment reduces ongoing risk to data subjects and limits regulatory exposure.

Assess the data and risk

Map the data involved, the categories of personal data, and the number of people affected. The ICO expects a risk assessment that shows likely consequences for data subjects and the technical root cause. Document who discovered the incident, timestamps of detection and containment steps, and the evidence trail for investigators and potential legal review.

Notify the ICO and data subjects

Under UK GDPR, notify the ICO without undue delay and, where feasible, within 72 hours if the breach is likely to result in a risk to individuals’ rights and freedoms. If the breach poses a high risk, inform affected people with clear advice on what they should do. Follow ICO guidance when preparing your report and communications; practical templates and expectations are on the Information Commissioner’s Office.

Preserve evidence and start forensic triage

Preserve logs, disk images and chain-of-custody notes for forensic review. If you use an external provider, notify processors immediately and request their logs and evidence. For technical containment, Managed Detection and Response (MDR) platforms and incident responders can speed triage and rollback; see NIST for practical playbooks and recovery steps in published guidance from the National Institute of Standards and Technology (NIST SP 1800-29).

Remediate, review and learn

Apply fixes, rotate exposed secrets and strengthen access controls. Update your incident report, record lessons learned and revise your playbooks. If you need third-party help with evidence capture, reporting or accelerating remediation, our Due Diligence as a Service and Cyber Security Project Management services can assist with evidence collection, documentation and stakeholder communications.

Free Cyber Capability Maturity Model.
Use this to strategically measure your cyber security posture and transformation.
Download
Download our cyber security capability maturity model.

🛡️ How to prevent GDPR breaches and improve governance?

Still life of sealed comms and blurred device suggesting encrypted communication protocols

Start with clear technical and organisational controls that stop incidents becoming reportable breaches: Encryption at rest and in transit, strong access controls, reliable backups and regular incident testing. These measures reduce the chances that a security event meets the legal test for a reportable incident, answering the practical side of what is a breach of GDPR and helping you decide whether to notify the Information Commissioner’s Office (ICO).

Lightbulb Icon Key Takeaway

Make breaches less likely and easier to prove non-reportable by combining encryption, least privilege, data mapping and DPIAs, and by testing incident processes regularly.

Technical controls that cut breach risk

Encryption, multifactor authentication and role based access control stop unauthorised exposure of personal data and limit scope if an account is compromised. Regular backups and segregated recovery plans limit business impact and support timely notification to the ICO where needed. Network monitoring and endpoint detection reduce dwell time; industry reports find system intrusions remain a major cause of breaches in 2025, underlining the need for detection and containment 2025 Data Breach Investigations Report. Practical controls make the legal test for a reportable incident easier to answer when considering what is a breach of GDPR.

Governance, DPIAs and evidencing decisions

Data Protection Impact Assessments (DPIAs), published retention policies and an up to date data map show due diligence when you must answer “what is a breach of GDPR” for the ICO or for customers. Documented incident decision trees and a single incident owner speed the 72 hour assessment window under UK GDPR. In practice, organisations using automation and clear playbooks detect and escalate faster, shrinking remediation time IBM, 2025. Regular tabletop exercises and post-incident reviews make the governance record credible to boards, insurers and the ICO.

How ISO 27001 and supplier checks help

ISO 27001 aligns controls to risk and creates auditable evidence of due diligence for boards, insurers and the ICO. Our ISO 27001 service pages explain the practical audit trail that decision makers expect. Use security questionnaire automation and supplier DPIAs to manage third party risk, because many breaches trace to suppliers or cloud misconfiguration. Where a breach involves a processor, documented contracts and supplier due diligence speed notification and limit liability.

❓ Frequently asked questions

Is insecure disposable breach a data breach?

The key fact: Insecure disposal of personal data can be a data breach if it affects confidentiality, integrity or availability under UK General Data Protection Regulation (UK GDPR). The Information Commissioner’s Office (ICO) expects reporting where the disposal creates a likely risk to individuals. Secure shredding, data sanitisation and disposal logs reduce risk and support breach assessments.

What constitutes a GDPR breach?

The key fact: A GDPR breach is any incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data, affecting confidentiality, integrity or availability under UK General Data Protection Regulation (UK GDPR). Examples include lost laptops, misdirected emails and unauthorised access, and failures in lawful basis or Data Protection Impact Assessments can aggravate regulatory findings.

What happens if a company breaches GDPR?

The key fact: Consequences range from enforcement notices and monetary penalties by the Information Commissioner’s Office (ICO) to reputational damage and civil claims. The ICO can issue fines, corrective orders and bans under UK General Data Protection Regulation (UK GDPR). Outcomes depend on scope, negligence and mitigation; common remediation steps include containment, notification, root cause fixes and improved governance.

When do I have to tell the ICO about a breach?

The key fact: Organisations should notify the Information Commissioner’s Office (ICO) of personal data breaches without undue delay and, where feasible, within 72 hours under UK General Data Protection Regulation (UK GDPR). Notifications must include the breach nature, scope, likely consequences and mitigation. If the breach is unlikely to result in risk to individuals, external reporting may not be required, but internal records must be kept.

Can a data processor be fined for a GDPR breach?

The key fact: Yes, data processors can face enforcement under the Data Protection Act 2018 and UK General Data Protection Regulation (UK GDPR) where they breach their obligations. The Information Commissioner’s Office (ICO) may act against processors for inadequate security or contractual failures. Processors should follow contracts, support controllers, keep processing records and implement technical and organisational measures to limit exposure.

Contact Us

Share this post

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Author
Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

Category
Published
Sep 15 - 2026
Cypro firewall showing robust network security
Secure your business.
Elevate your security, accelerate your growth. We take care of cyber security for high-growth companies, at every stage of their journey.
Get in touch
Related Posts
View All Posts
  • Forensic analyst creating disk images for cyber due diligence investigation
    How to Conduct Cyber Due Diligence for UK Tech Deals in 2026

    Cyber due diligence is the process of assessing an organisation’s cyber risk before a transaction, investment or major contract, focusing…

  • Two specialists configuring encrypted storage media for incident response planning
    How to Create an Incident Response Planning Process for Your Organisation in 2026

    Incident response planning is a repeatable process to detect, contain, eradicate and recover from cyber incidents, and every UK organisation…

  • Email security analyst mentoring during technology due diligence review
    7 Key Insights on Technology Due Diligence

    Technology due diligence is a structured review of a target’s technology, cyber security, compliance and operations carried out for M&A,…

CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call