Data Breach Response: Your First 72 Hours Under GDPR

It’s 8am on a Monday and someone tells you an email containing customer records went to the wrong recipient, or a laptop full of client files has gone missing. Your stomach drops — but what actually happens next matters far more than how the breach occurred. Under UK GDPR, the clock starts ticking the moment you become aware of it, and how you respond in the following 72 hours can be the difference between a manageable incident and a serious regulatory and reputational problem.

This guide walks through exactly what to do, in order, when you discover a personal data breach — plus the mistakes that turn a bad day into a much worse one.

In this article:
– What actually counts as a “breach” under GDPR
– Hour 0–1: immediate containment
– Hour 1–24: assess and investigate
– Hour 24–72: the notification decision
– When (and how) to tell the people affected
– Common mistakes that make things worse
– Building a breach-ready business

What Actually Counts as a “Breach” Under GDPR

A data breach isn’t just hacking or theft. It covers any incident affecting the confidentiality, integrity, or availability of personal data — an email sent to the wrong person, a lost phone with client contacts on it, a ransomware attack, or even accidentally deleting customer records with no backup all qualify. Many small business owners assume a breach must involve malicious intent or a cyberattack; it doesn’t. Human error is one of the most common causes.

Hour 0–1: Immediate Containment

The first priority is stopping the situation getting worse, not documenting it perfectly.

– Contain it. Revoke access, recall the email if possible, disable a compromised account, or retrieve the lost device remotely if you can.
– Preserve evidence. Don’t delete logs, emails, or systems data — you’ll need this to understand scope and, if required, to demonstrate your response to the ICO.
– Alert the right people internally. Whoever handles data protection in your business (even if that’s just you) needs to know immediately, not at the end of the day.
– Start a written timeline. Note the time you became aware, what you did, and when — this record becomes essential later.

Hour 1–24: Assess and Investigate

Once the immediate bleeding is stopped, you need to understand what actually happened:

– What data was involved? Names and email addresses are lower risk than financial details, health information, or passwords.
– How many people are affected? One customer or a full database export are very different situations.
– What’s the likely impact on those people? Could this lead to identity theft, financial loss, discrimination, or distress?
– Is it ongoing or contained? A breach still actively exposing data is more urgent than one that’s fully stopped.

This assessment directly determines your legal obligations in the next stage — so it’s worth being thorough rather than rushed, even under time pressure.

Hour 24–72: The Notification Decision

This is the stage most business owners are unsure about, and it hinges on one key legal test: risk to the individuals involved, not to your business.

You must notify the ICO within 72 hours of becoming aware of the breach, unless it’s unlikely to result in a risk to people’s rights and freedoms. If you decide it doesn’t meet that threshold, you should still document your reasoning — this decision itself needs to be justifiable if ever questioned.

If notification is required:

– Report to the ICO via their online reporting tool as soon as possible, and within 72 hours
– Include what happened, what data was affected, roughly how many people, what you’ve done to contain it, and what you’re doing next
– If you don’t have all the details within 72 hours, you can provide information in phases — the ICO does not expect a fully completed investigation in that window, but does expect you to have started the process

When (and How) to Tell the People Affected

There’s a second, higher threshold for telling the individuals themselves: this is only legally required when the breach is likely to result in a high risk to their rights and freedoms — for example, exposed financial details, health data, or passwords that could enable fraud or identity theft.

When you do need to tell people:

– Use clear, plain language — explain what happened, what data was involved, and what they should do (e.g., change a password, watch for suspicious activity)
– Explain what you’re doing to fix it and prevent recurrence
– Give them a contact point for questions
– Don’t bury the notification in vague corporate language — clarity here protects both them and your reputation

Common Mistakes That Make Things Worse

– Treating “72 hours” as 72 hours to decide whether it’s serious, rather than 72 hours to report if it is. The clock starts at awareness, not at the end of your internal investigation.
– Trying to fully investigate before reporting anything. Phased reporting is allowed — waiting for complete certainty often blows the deadline.
– Not documenting the “no notification needed” decision. If you decide the risk threshold isn’t met, write down why — an unrecorded judgement call looks far worse in hindsight.
– Downplaying the breach to affected customers rather than being transparent — this tends to damage trust more than the breach itself.
– No breach log at all. Even breaches you don’t report to the ICO must still be recorded internally as part of your accountability obligations.

Building a Breach-Ready Business

The businesses that handle breaches well are rarely the ones with no incidents — they’re the ones with a plan already in place before anything happens:

– Keep a simple, written breach response procedure so no one is improvising under pressure
– Maintain an internal breach log, even for minor or non-reportable incidents
– Know in advance who in your business is responsible for making the call
– Run a basic annual review of what personal data you hold and where, so you can assess impact quickly if something goes wrong
– Revisit your GDPR basics regularly — if you haven’t already, our earlier guide on GDPR fundamentals for small businesses is a good place to start

Staying Calm Under Pressure

A data breach is stressful, but the legal expectation isn’t perfection — it’s a prompt, honest, and proportionate response. Businesses that act quickly, document their reasoning, and communicate clearly tend to come through these incidents with their reputation, and their regulatory standing, intact.

If you’d like support building a data breach response plan or reviewing your wider GDPR compliance, CAW Consultancy works with UK business owners to put practical, audit-ready processes in place.

Get in touch with CAW Consultancy today for a free, no-obligation consultation — visit https://www.cawconsultancy.co.uk to find out how we can help you stay compliant and confident.

Leave a comment

I’m Craig

Meet Craig Willetts

Welcome to the ISO and Compliance Blog, I have spent over 20 years in compliance specialising in accreditation and business growth, I own a number of compliance related businesses including CAW Consultancy, Global ISO Services, CAW Digital, Screen my staff and fusion consultancy worldwide and this blog is designed to help SME’s on their journey to top notch compliance, any questions feel free to drop me an email at Craig@CAWConsultancy.co.uk

Let’s connect