Something has happened to personal data and the clock may already be running. Answer these questions to see whether it is reportable, how long you have left, and what to write down either way.
Start the assessment now, not after the incident is over. The 72 hours runs from the moment anyone in your organisation became aware — not from when you finish investigating, and not from when the incident is resolved.
1. What happened
Is personal data involved?
Personal data is involvedAnything identifying a living person — including a name in an email address
What kind of breach (tick all that apply)
Seen by the wrong peopleMisdirected email, wrong attachment, unauthorised access, theft
Lost or unavailableRansomware, deletion, failed backup, destroyed records
Altered or corruptedData changed without authorisation
2. What data, and whose
Types of data involved
Names and contact details
Financial — bank or card details
Identity documentsPassport, driving licence, NI number
Login credentials or passwords
Health or medical information
Other special category dataRace, religion, politics, trade union, sex life or orientation, biometrics
Criminal offence data
Children's data
Vulnerable people are affectedSafeguarding, domestic abuse, care recipients
Confidential business or HR records
3. What reduces the risk
Only tick what you can actually evidence. Assuming a mitigation you cannot prove is how organisations end up reporting late.
Data was strongly encryptedAnd the key was not compromised
Recipient is known and trustedAnd has confirmed permanent deletion
Data fully recoveredFrom backup, quickly, with no copies taken
No evidence it was accessed or takenLogs reviewed and checked, not just assumed
Affected people already told
Why
The factors behind that answer. Check each one against what you actually know — the assessment is only as good as the answers above.
What to do now
For your breach log
Every breach must be recorded, including the ones you decide not to report. The ICO can ask to see this log, and the reasoning for a decision not to notify is exactly what they will look for.
In the middle of one right now?
Hamilton Group helps Yorkshire businesses contain incidents, work out what was actually taken, and produce the evidence the ICO and your insurer will ask for. The sooner we are involved, the more of that evidence still exists.
Guidance only — this is not legal advice, and it is not a substitute for your own assessment. It applies UK GDPR principles to the answers you gave and cannot see the facts of your incident. The decision to notify is yours as controller, and it must be documented either way. If you are genuinely unsure, report it: the ICO would far rather receive a notification that turns out not to have been needed than find out later that one was missed. You can report within 72 hours with incomplete information and follow up in phases. ICO breach helpline 0303 123 1113.