ICO explains steps for people concerned about a personal-data breach

United Kingdom
Aug 21, 20261 sources
  • 01The ICO updated its guidance on suspected personal-data breaches on 20 August 2026.
  • 02A breach can include unauthorised access or disclosure, loss, destruction, or alteration of personal information, whether caused deliberately or accidentally.
  • 03Individuals should raise the matter with the organisation first and seek details of the incident, affected information, and protective measures.
  • 04Organisations must report qualifying breaches to the ICO without undue delay and, where feasible, within 72 hours; high-risk breaches may also require notice to affected people.
  • 05Organisations should maintain documented breach-assessment and response procedures to meet UK data-protection obligations.

The UK Information Commissioner’s Office (ICO) has updated guidance for people who believe an organisation has not kept their personal information secure. The guidance was updated on 20 August 2026.

A personal-data breach is a security incident that leads to personal information being lost, destroyed, altered, disclosed, or accessed without authorisation. It can result from a cyberattack, an accidental disclosure, lost paperwork or devices, or inadequate access controls.

The guidance is intended to help individuals identify a possible breach, raise concerns with the organisation involved, and escalate the matter to the ICO where appropriate. Individuals should first contact the organisation, explain what information may have been affected, and ask what happened, what data was involved, and what protective steps it is taking.

Organisations subject to UK data-protection law must assess breaches and, where a breach is likely to create a risk to people’s rights and freedoms, report it to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the risk is high, the organisation must also tell affected people without undue delay, unless an exception applies.

For organisations, the guidance reinforces the need for an incident-response process that can promptly contain an event, establish what personal data is affected, assess the risk to individuals, document the decision-making, and make any required ICO and individual notifications. For individuals, a report to the ICO may be appropriate if the organisation has not addressed the concern or if the person remains dissatisfied with its response.

Sources (1)

ico.org.ukAug 21, 2026

ICO explains steps for people concerned about a personal-data breach