Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

When must you notify a UK GDPR personal data breach?

Updated

UK GDPR Article 33(1): notify the Commissioner without undue delay and, where feasible, not later than 72 hours after having become aware, unless unlikely to result in a risk. Article 34 is a separate high-risk duty. Not legal advice; does not start a clock.

UK GDPR jurisdiction guide, last verified 8 September 2026 against UK GDPR Articles 33 and 34 (legislation.gov.uk, assimilated Regulation (EU) 2016/679 as amended), Data Protection Act 2018 including section 157 maxima, ICO personal-data-breach pages and self-assessment tool, ICO PECR security-breach guidance, and the Data (Use and Access) Act 2025 as commenced. ICO pages are regulator guidance, not the UK GDPR. It is not legal advice, not a filing, not a determination that UK GDPR applies, and not a substitute for counsel.

This is UK GDPR Articles 33–34, not YOUR determination

Audience: a controller, a processor, a DPO, a CISO, or counsel triaging a personal-data incident that may sit under the UK GDPR. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that UK GDPR applies, that you have become aware, that a risk or high-risk threshold is met, or that you must file.

Articles 33 and 34 are legal requirements only if UK GDPR applies to YOUR facts. Territorial scope is UK GDPR Article 3 — the which-jurisdictions-apply page on this site is that applicability map. This page does not run Article 3. The GDPR breach-notification guide on this site is Regulation (EU) 2016/679 Articles 33–34, a separate leaf. Filing one never discharges the other. Last verified 8 September 2026. Not legal advice.

  • Statute versus guidance: UK GDPR Articles 33 and 34 are legal requirements only if UK GDPR applies. ICO personal-data-breach pages, the ICO self-assessment tool, and Article 29 Working Party Guidelines WP250 rev.01 (which the ICO still cites for awareness and risk) are regulator guidance; they are not the UK GDPR. This page quotes which kind of text it is relying on.
  • This page does not start 72 hours, does not convert 'without undue delay' into a number of hours, and does not round 72 hours to three days.
  • The reporting-deadlines page on this site is the statute table of clocks. The how-regulators-determine-knowledge page on this site is the clock-start analysis. The regulator-customer-individual page on this site is the three-stream comparison. The GDPR breach-notification guide on this site is the EU leaf.
  • The signed-in CRA ladder tracks recorded awareness for findings the organisation classified as CRA-in-scope. That tracker is not a UK GDPR Article 33 clock, and it does not file with the ICO. The CRA Article 14 reporting guide on this site is that ladder's statute.

72-hour ICO notification — Article 33(1)

Article 33(1) is the controller's notice to the Commissioner. Quote the article's words. This page does not find that you have become aware, and it does not start the 72 hours. The how-regulators-determine-knowledge page on this site is the clock-start analysis. Last verified 8 September 2026. Not legal advice.

Article 33(1) clock (legal requirement only if UK GDPR applies — not YOUR start time; not legal advice; does not start a clock)
ElementWhat the text saysKind of textLast verified
DutyIn the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the Commissioner, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons.Legal requirement — UK GDPR Article 33(1). Only if UK GDPR applies. The recipient is the Commissioner, not an EU supervisory authority.8 September 2026
Clock-startAfter having become aware of it. Article 33(1) itself does not say 'should have known' or 'reasonable diligence'. Recital 87: it should be ascertained whether all appropriate technological protection and organisational measures have been implemented to establish immediately whether a personal data breach has taken place.Legal requirement (the start word) plus Recital 87. Not a finding that YOU became aware.8 September 2026
Awareness (how 'aware' is described)The ICO personal-data-breaches guide points to Section II of the Article 29 Working Party Guidelines on personal data breach notification (WP250 rev.01) for when a controller can be considered to have become aware. That is the same awareness description the EDPB later restated in Guidelines 9/2022 paragraph 31: a reasonable degree of certainty that a security incident has occurred that has led to personal data being compromised. The ICO cites WP29, not EDPB 9/2022, as the guidance it points organisations to.Regulator guidance, not the UK GDPR. The guidelines do not invent a second clock. They are not a finding that YOU have a reasonable degree of certainty.8 September 2026
Delay beyond 72 hoursWhere the notification under this paragraph is not made within 72 hours, it shall be accompanied by reasons for the delay. Article 33(4) then allows information in phases without undue further delay — that is not a licence to skip the first notice.Legal requirement — Article 33(1) second sentence, and Article 33(4).8 September 2026
Exception (no ICO notice)Unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. That exception is Article 33(1), not Article 34. Article 33(5) still requires documentation even when you do not notify. The ICO self-assessment tool is regulator guidance on that assessment; it is not the article.Legal requirement — Article 33(1) exception. Counsel applies the test. This page does not.8 September 2026

High-risk individual notification — Article 34 versus Article 33

Article 34 is a separate duty from Article 33. The threshold is higher. The clock is 'without undue delay' with no 72-hour outer mark in that article. Do not paste Article 33(1)'s 72 hours onto the data-subject stream. Last verified 8 September 2026. Not legal advice.

Risk-threshold decision tree (Article 33 versus Article 34 — not a determination; not legal advice; ICO and WP29 labelled as guidance)
QuestionIf the facts point that wayWhat this page does not doSource
Is there a personal data breach (Article 4(12))?A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed. The ICO guide (regulator guidance) groups types as confidentiality, integrity, and availability. All personal data breaches are security incidents; not all security incidents are personal data breaches.Does not decide that YOUR incident is a personal data breach. Does not start a clock.Article 4(12). ICO personal-data-breaches guide is regulator guidance.
Is the breach unlikely to result in a risk to the rights and freedoms of natural persons?Article 33(1) exception may take the ICO notification off the table — counsel applies that test. Article 33(5) still requires documentation of the facts, effects, and remedial action. The ICO says you do not need to report every breach to the ICO; if you decide not to report, you need to be able to justify that decision.Does not find 'unlikely to result in a risk' on YOUR facts. Does not skip Article 33(5).Article 33(1) exception; Article 33(5). ICO guide is regulator guidance.
If a risk is not unlikely — Article 33(1) ICO noticeThe controller notifies the Commissioner, without undue delay and, where feasible, not later than 72 hours after having become aware. Content: Article 33(3). Phased: Article 33(4).Does not start the 72 hours. Does not convert 72 hours into three days. Does not file.Article 33(1) and 33(3)–(4). Legal requirement only if UK GDPR applies.
Is the breach likely to result in a high risk to the rights and freedoms of natural persons?Article 34(1): the controller shall communicate the personal data breach to the data subject without undue delay. High risk is a higher bar than Article 33(1)'s 'risk'. Recital 85 names kinds of damage (physical, material, non-material).Does not find high risk on YOUR facts. Does not convert Article 34's 'without undue delay' into 72 hours.Article 34(1). Recital 85. ICO guide on informing individuals is regulator guidance.
Article 34(3) — communication not required if a listed condition is met(a) appropriate technical and organisational protection measures were applied to the personal data affected, in particular those that render the personal data unintelligible to any person who is not authorised to access it, such as encryption; (b) subsequent measures ensure that the high risk is no longer likely to materialise; (c) it would involve disproportionate effort — in that case a public communication or similar measure instead, whereby the data subjects are informed in an equally effective manner.Does not decide that encryption, subsequent measures, or disproportionate effort applies to YOUR facts. A public communication under (c) is not the Article 33(1) filing.Article 34(3)(a)–(c). Legal requirement only if UK GDPR applies.
Article 34(4) — the Commissioner may still require communicationIf the controller has not already communicated the personal data breach to the data subject, the Commissioner, having considered the likelihood of high risk, may require it to do so or may decide that any of the conditions in paragraph 3 are met.Does not predict what the ICO will require. Does not start a clock.Article 34(4). The actor is the Commissioner, not an EU supervisory authority.

Controller versus processor — Article 33(2) is not Article 33(1)

Different actor, different recipient, different content, different outer mark. A processor's Article 33(2) notice to the controller is not the controller's Article 33(1) notification to the Commissioner. Last verified 8 September 2026. Not legal advice.

  • Article 33(1): the controller notifies the Commissioner — without undue delay and, where feasible, not later than 72 hours after having become aware — unless the breach is unlikely to result in a risk. Content: Article 33(3).
  • Article 33(2): the processor shall notify the controller without undue delay after becoming aware of a personal data breach. That paragraph has no 72-hour outer mark. The ICO guide (regulator guidance): if your organisation uses a data processor and this processor suffers a breach, then under Article 33(2) it must inform you without undue delay as soon as it becomes aware; you in turn notify the ICO, if reportable.
  • Do not paste 72 hours onto the processor. Do not treat the processor's 'without undue delay' as starting the controller's 72 hours by itself — awareness is a legal and factual test for each actor. This page does not find it on YOUR facts.
  • Article 28: the processing contract shall stipulate processor assistance with Articles 32 to 36. Assistance is not the Article 33(1) filing. The legal responsibility to notify the Commissioner remains with the controller.
  • Article 34 is a third duty. The processor does not become the Article 34 sender by sending Article 33(2) notice. High risk is not the same test as Article 33(1)'s 'risk'.

Content — Article 33(3) fields and phased Article 33(4)

Article 33(3) is the controller's ICO-notice content list. Article 34(2) pulls a subset for the data-subject communication. Article 33(4) allows phases. Last verified 8 September 2026. Not legal advice.

  • Article 33(3) says 'shall at least'. Extra detail is allowed.
  • Article 33(4): where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
  • A phased notice is not a skipped notice. Reasons for delay still accompany a notification made after 72 hours (Article 33(1) second sentence).
  • ICO guidance (28 May 2025 update, not the article): report early, update later. The ICO recognises that a full picture may not be available within 72 hours and says you can provide additional details later without undue delay. That is ICO process guidance on how to work with the ICO; it is not a second statutory clock.
  • The prepare-regulatory-report page on this site is the field checklist across regimes. Do not file an Article 33(3) form as a HIPAA Secretary notice, a Form 8-K Item 1.05, or an EU GDPR DPA notice and treat that as the ICO filing.
Article 33(3) minimum fields (legal requirement only if UK GDPR applies — not a blended form; not legal advice)
FieldArticle 33(3) ICO noticeArticle 34(2) data-subject communication
(a) NatureDescribe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned.Describe in clear and plain language the nature of the personal data breach. Article 34(2) does not copy Article 33(3)(a)'s approximate numbers into the data-subject letter.
(b) Contact pointCommunicate the name and contact details of the data protection officer or other contact point where more information can be obtained.Pulled in: at least the information in Article 33(3)(b).
(c) Likely consequencesDescribe the likely consequences of the personal data breach.Pulled in: at least the information in Article 33(3)(c).
(d) MeasuresDescribe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.Pulled in: at least the information in Article 33(3)(d).

Documentation — Article 33(5) even when there is no notice

Article 33(5): the controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the Commissioner to verify compliance with this Article. The duty is not limited to breaches you notified. Last verified 8 September 2026. Not legal advice.

  • Document the facts, the effects, and the remedial action — including a no-notification decision and the reasons. The ICO guide (regulator guidance) restates that you must keep a record of any personal data breaches, regardless of whether you are required to notify.
  • The document-your-decision page on this site is the decision record. The supporting-evidence page on this site is the evidentiary record. This page does not keep YOUR Article 33(5) register.
  • The signed-in app does not keep an Article 33(5) register and does not file one with the ICO.

EU GDPR versus UK GDPR — they are separate leaves

EU GDPR and UK GDPR are separate legal requirements. Filing one never discharges the other. This table is a divergence map for breach notification, not a determination that either instrument applies. Last verified 8 September 2026. Not legal advice.

EU GDPR versus UK GDPR on breach notification (not a determination; not legal advice; does not start a clock)
TopicEU GDPRUK GDPRKind of text
Recipient of Article 33(1)The supervisory authority competent in accordance with Article 55. Cross-border processing may engage a lead supervisory authority (Articles 56 and 60) and one-stop-shop.The Commissioner. UK GDPR Article 33(1) names the Commissioner, not an EU DPA. There is no EU one-stop-shop that files the UK notice for you.Legal requirement on each leaf. Filing an EU DPA notice is not an ICO notice.
Territorial scopeArticle 3: Union establishment, or targeting / monitoring of data subjects who are in the Union.Article 3: United Kingdom establishment, or targeting / monitoring of data subjects who are in the United Kingdom (including Article 3(2A) 'relevant processing'). Substituting the UK for the Union is not a copy-paste of the EU analysis.Legal requirement only if that instrument applies. The which-jurisdictions-apply page on this site is the Article 3 map. This page does not run it.
Article 33(1) clock wordsWithout undue delay and, where feasible, not later than 72 hours after having become aware, unless unlikely to result in a risk.The same words, pointing at the Commissioner. Last verified 8 September 2026, the Data (Use and Access) Act 2025 had not rewritten this clock.Legal requirement. 72 hours is not three days on either leaf.
Article 33(2) / 33(3) / 33(4) / 33(5) / Article 34Processor-to-controller without undue delay; authority-notice fields; phases; documentation even with no notice; high-risk individual communication without undue delay.The same structure. Article 34(4) names the Commissioner as the actor who may still require communication.Legal requirement only if that instrument applies. Parallel structure is not a merged filing.
Guidance on awareness and riskEDPB Guidelines 9/2022 (Version 2.0) are EU regulator guidance, not the regulation.The ICO personal-data-breaches guide points to WP29 WP250 rev.01 for awareness and risk. That is ICO-cited regulator guidance, not the UK GDPR, and it is not EDPB 9/2022.Regulator guidance on each leaf. Do not treat an EDPB paragraph as an ICO determination.
Fine maxima (not typical fines)Article 83: up to EUR 10 million or 2% (standard) and EUR 20 million or 4% (higher), as the article lists.Article 83 as retained and amended, read with DPA 2018 section 157: standard maximum £8,700,000 or 2 percent of worldwide annual turnover; higher maximum £17,500,000 or 4 percent of worldwide annual turnover. Article 83(4) lists Articles 25–39 among the standard-maximum provisions — Articles 33 and 34 sit there. These are maxima, not typical ICO fines, and not a prediction of YOUR penalty.Legal requirement (maxima). ICO Data Protection Fining Guidance restates those sterling figures as ICO policy on how it applies the maxima; it is not the article.
PECR overlayePrivacy is a separate EU instrument. Do not paste GDPR Article 33 onto it from this page.PECR is a different UK regime for public electronic communications service providers. ICO PECR guidance: PECR reporting takes the place of UK GDPR breach reporting for those providers; use the PECR form, not the UK GDPR form. DUAA aligned the PECR ICO-notice mark to 72 hours (ICO, 20 August 2025).Different legal requirement. Do not paste UK GDPR Article 33 onto every PECR incident.

ICO process notes — self-assessment, portal, and who files

These rows are ICO process guidance unless a cell says otherwise. They are not the UK GDPR, not a determination that YOU must file, and not a claim that ShipReady submits anything through ico.org.uk. Last verified 8 September 2026. Not legal advice.

ICO process as the ICO currently publishes it (regulator guidance unless labelled otherwise — not a filing; not legal advice; does not start a clock)
StepWhat the ICO currently publishesKind of textWhat this page does not do
Self-assessmentThe ICO publishes a self-assessment for data breaches at ico.org.uk/for-organisations/report-a-breach/personal-data-breach-assessment/. It is a tool to help you decide whether to notify. Completing it is not the Article 33(1) filing and is not a legal determination that a risk or high-risk threshold is met.ICO guidance, not the UK GDPR.Does not run the self-assessment. Does not treat a self-assessment result as YOUR legal conclusion. The product does not submit through this tool.
Online reportThe ICO's UK GDPR reporting page is ico.org.uk/for-organisations/report-a-breach/personal-data-breach. The online form is linked from there (personal-data-breach-reporting). The ICO says the form takes approximately 30 minutes, cannot be saved and returned to later, and that you should have the details ready. A named human still submits.ICO process guidance, not the UK GDPR.Does not file. Does not start 72 hours. Does not invent an ICO API or claim that ShipReady submits this form.
Report early, update laterICO update 28 May 2025: more emphasis on report early, update later. You are legally required to meet the 72-hour timeframe and should provide whatever relevant information you have; additional details can follow without undue delay. That restates Article 33(1) and 33(4); the 'report early' slogan is ICO guidance on working with the ICO.Mix: the 72-hour mark is Article 33(1); the working practice is ICO guidance.Does not convert ICO 'report early' into a shorter statutory clock.
Health and care in EnglandThe ICO self-assessment results page tells health and care organisations in England to report breaches using the Data Security and Protection Incident Reporting tool. That is ICO process guidance for that sector. It is not a different Article 33 clock, and it is not a ShipReady integration.ICO guidance, not the UK GDPR.Does not file through DSPT. Does not invent that DSPT replaces Article 33 as a legal matter.
Other parties the ICO mentionsThe ICO says you should also consider notifying your insurer, law enforcement, and the NCSC if a malicious actor caused the breach, and that reporting a cyber incident to the ICO is not the same as reporting to the NCSC or to Action Fraud / Police Scotland. Those are different recipients.ICO guidance. NCSC and police reporting are not Article 33.Does not start those other clocks. Does not file with the NCSC.

PECR is a different regime

The Privacy and Electronic Communications (EC Directive) Regulations 2003 are not the UK GDPR. Do not paste Article 33 onto every PECR incident. Last verified 8 September 2026. Not legal advice.

  • Who: ICO PECR guidance addresses public electronic communications service providers (for example telecoms providers or internet service providers) under PECR regulation 5A.
  • ICO guidance (not the UK GDPR): if you are subject to PECR and you experience a personal data breach, continue to report under PECR. There is no need to report under the DPA 2018 (UK GDPR) too. Use the PECR breach-notification form, not the UK GDPR form. The PECR portal is ico.org.uk/for-organisations/report-a-breach/data-security-breach-pecr.
  • Clock: ICO PECR guidance, updated 20 August 2025, states the Data (Use and Access) Act changed PECR reporting timescales from 24 hours to 72 hours after becoming aware of the breach. The ICO PECR security-breaches page says you must notify the ICO within 72 hours of becoming aware of the essential facts of the breach. That is PECR as the ICO currently restates it, not UK GDPR Article 33(1). Do not treat the two 72-hour marks as one filing.
  • Customer notice: ICO PECR guidance uses 'likely to adversely affect the personal data or privacy of subscribers or users' and 'without unnecessary delay' — not Article 34's 'high risk' / 'without undue delay'. Encryption that makes the data unintelligible is the ICO-stated PECR exception for customer notice.
  • Breach log: ICO PECR guidance requires a log of facts, effects, and remedial action, and asks providers to submit that log monthly. That monthly log is not the UK GDPR Article 33(5) register, even though the fields look similar.
  • PECR fixed penalty: the ICO PECR page states that failure to submit breach notifications can incur a £1,000 fine. That is an ICO-stated PECR figure, not a typical UK GDPR Article 83 fine, and not a prediction of YOUR penalty.
  • This page does not decide that YOU are a PECR service provider. Counsel applies PECR on YOUR facts.

Legal requirement versus ICO guidance

Breach-notification text comes in different kinds. Mixing them invents duties. Last verified 8 September 2026. Not legal advice.

Legal requirement vs ICO guidance vs this page (not a determination; not legal advice)
TextKindWhat this page does not do
UK GDPR Articles 33 and 34 (legislation.gov.uk)Legal requirement only if UK GDPR applies. Operative controller/processor duties: ICO notice, processor notice, content, phases, documentation, high-risk individual communication.Does not decide that UK GDPR applies. Does not start 72 hours. Does not file.
UK GDPR Article 3, Article 4(12), Article 28, Article 83; DPA 2018 section 157Legal requirements (only if they apply): territorial scope, definition of a personal data breach, processor contract assistance, administrative-fine maxima.Does not run Article 3. Does not compute YOUR fine. Maxima are not typical ICO fines.
DPA 2018 Part 3 sections 67–68 (law-enforcement processing)A different legal requirement for competent authorities processing for law-enforcement purposes: notify the Commissioner without undue delay and, where feasible, not later than 72 hours. Not UK GDPR Article 33.Does not decide that Part 3 applies. Does not paste Part 3 onto a commercial controller.
PECR regulation 5A as the ICO currently restates itA different legal requirement for public electronic communications service providers. ICO guidance says PECR reporting takes the place of UK GDPR breach reporting for those providers.Does not decide that PECR applies. Does not paste Article 33 onto PECR, or the reverse.
ICO personal-data-breaches guide; ICO self-assessment; ICO report-a-breach pages; WP29 WP250 rev.01 as the ICO cites itRegulator guidance. How the ICO currently explains awareness, risk, the portal, and working with the ICO. Not the UK GDPR. The ICO report-a-breach page states that, because of the Data (Use and Access) Act, this guidance is under review and may be subject to change.Does not treat an ICO example as YOUR facts. Does not treat the self-assessment as the Article 33(1) test.
This pageA jurisdiction guide. Not the law, not ICO guidance, not a filing, not a determination.Does not start a clock. Does not file. Is not legal advice.

In-flight reform — Data (Use and Access) Act 2025

The Data (Use and Access) Act 2025 (c. 18) received Royal Assent on 19 June 2025. It does not replace the UK GDPR, the Data Protection Act 2018, or PECR; it amends them. Last verified 8 September 2026 against legislation.gov.uk and GOV.UK commencement plans. A Bill is not law; an uncommenced provision is not in force. This page does not invent what DUAA changed about Articles 33 and 34.

  • Articles 33 and 34 clock: last verified 8 September 2026 on legislation.gov.uk, UK GDPR Article 33(1) still reads 'without undue delay and, where feasible, not later than 72 hours after having become aware', pointing at the Commissioner. This page does not treat DUAA as having rewritten that clock.
  • PECR clock: ICO PECR guidance, 20 August 2025, states DUAA changed PECR breach-reporting timescales from 24 hours to 72 hours after becoming aware. That is a PECR change, not an Article 33 change.
  • Part 5 data-protection provisions: The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82) brought the majority of Part 5 data-protection and privacy provisions into force on 5 February 2026 (GOV.UK commencement plans, last updated 5 February 2026). Those commenced changes include other UK GDPR simplifications and ICO enforcement-power modernisation. This page does not restate every Part 5 amendment. It flags that they are in force as of that commencement, and that they are not a rewrite of Article 33(1)'s 72-hour words as last verified.
  • Complaints by data subjects: SI 2026/82 regulation 3 commenced DUAA section 103 (and Schedule 10) on 19 June 2026. That is a complaints-handling duty, not Article 33.
  • Information Commission rename: The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026 (SI 2026/386) would substitute wording that currently says 'the Commissioner' once DUAA section 119 (transfer of functions to the Information Commission) is fully brought into force. Last verified 8 September 2026, legislation.gov.uk still listed those Article 33 wording substitutions as changes yet to be applied. This page continues to say 'the Commissioner' because that is the in-force UK GDPR text as last verified. It does not treat the rename as commenced.
  • ICO guidance status: the ICO UK GDPR reporting page states that, due to DUAA coming into law on 19 June 2025, that guidance is under review and may be subject to change. Last verified 8 September 2026. If a later ICO revision changes process notes on this page, the date above is how you can see we have not re-checked yet.

Checklist

This is a question list, not a filing, and not YOUR notice. Walk it with counsel. The first-72-hours page on this site is the operational 72-hour plan. The reporting-deadlines page on this site is the statute table. The how-regulators-determine-knowledge page on this site is the clock-start analysis. The document-your-decision page on this site is the decision record.

  • Does UK GDPR apply? Article 3 is the territorial test. The which-jurisdictions-apply page on this site is that walk. This page does not run it. The GDPR breach-notification guide on this site is the EU leaf — a separate filing.
  • Are you the controller or the processor for this processing? Article 33(1) is not Article 33(2).
  • Are you a PECR public electronic communications service provider for this incident? If ICO PECR guidance applies, that is a different form and a different regime. Do not paste Article 33 onto it.
  • Awareness (UTC): the minute you currently believe the organisation became aware, in Article 33(1)'s words. Do not treat reading this page as becoming aware. This page does not find that minute.
  • Risk: is the breach unlikely to result in a risk (Article 33(1) exception)? High risk for Article 34 is a separate, higher test. Quote which test you applied. The ICO self-assessment is guidance on that assessment, not the article.
  • ICO notice: quote Article 33(3) fields. If information is incomplete, Article 33(4) phases, with reasons for delay if past 72 hours. Do not round 72 hours to three days. A named human files on ico.org.uk. The product does not.
  • Individual communication: only if Article 34(1) high risk, unless an Article 34(3) condition is met. Do not convert 'without undue delay' into 72 hours.
  • Article 33(5) record: facts, effects, remedial action — including a no-notification decision. The document-your-decision page on this site is that field list.
  • EU leaf: if EU GDPR may also apply, that is a separate Article 33 to a Union supervisory authority. Filing the ICO notice never discharges it. The GDPR breach-notification guide on this site is that leaf.
  • Who is authorised to file, and who is not. A named human files. The product does not. This page does not file.

Glossary

These are teaching labels for this page. They are not legal conclusions about YOUR facts.

Terms used on this page (teaching labels — not a determination)
TermHow this page uses it
UK GDPRAssimilated Regulation (EU) 2016/679 as amended and in force in the United Kingdom (legislation.gov.uk). A separate legal requirement from EU GDPR. Filing one never discharges the other.
The CommissionerThe Information Commissioner. UK GDPR Article 33(1) names the Commissioner as the recipient of the controller's notice. Last verified 8 September 2026, DUAA's Information Commission rename was not yet applied to that article.
ICOThe Information Commissioner's Office — the UK supervisory authority. ICO pages linked from this guide are regulator guidance unless a cell says they restate an article.
Personal data breachArticle 4(12): a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. Not every security incident.
Article 33(1)Controller → the Commissioner. Without undue delay and, where feasible, not later than 72 hours after having become aware, unless unlikely to result in a risk. Not three days. Not an EU DPA filing.
Article 33(2)Processor → controller, without undue delay after becoming aware. Not Article 33(1). No 72-hour outer mark in that paragraph.
Article 33(3)Minimum content of the controller's ICO notice: nature (including categories and approximate numbers where possible), DPO or contact point, likely consequences, measures.
Article 33(4)Phased provision of Article 33(3) information without undue further delay, where it is not possible to provide it at the same time.
Article 33(5)Document any personal data breaches — facts, effects, remedial action — even when you do not notify. Enables the Commissioner to verify compliance with Article 33.
Article 34Controller → data subject when the breach is likely to result in a high risk. Without undue delay — not 72 hours. Content: Article 34(2). Exceptions: Article 34(3). Article 34(4): the Commissioner may still require communication.
Risk versus high riskArticle 33(1) uses 'risk' (notify unless unlikely to result in a risk). Article 34(1) uses 'high risk' (communicate to the data subject when likely to result in a high risk). They are not the same threshold.
PECRPrivacy and Electronic Communications (EC Directive) Regulations 2003. A different regime from UK GDPR. ICO PECR guidance currently restates a 72-hour ICO notice for public electronic communications service providers, on a different form.
DUAAData (Use and Access) Act 2025 (c. 18). Royal Assent 19 June 2025. Amends UK GDPR, DPA 2018, and PECR. Commenced in stages. Last verified 8 September 2026, it had not rewritten Article 33(1)'s 72-hour words.

Where this shows up in ShipReady Metrics

The signed-in app does not decide that UK GDPR applies, does not start an Article 33 clock, does not start an Article 34 clock, does not assess risk or high risk, does not keep an Article 33(5) register, and does not file with the ICO. None of the surfaces below is an Article 33 notice, an Article 34 communication, a PECR notification, or an instruction to submit a filing.

If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour and 72-hour stages from recorded awareness, and the 14-day final-report mark from recorded measure availability, for findings the organization has classified as CRA-in-scope. That is one product tracker for the CRA actively-exploited ladder. It is not a UK GDPR Article 33 clock, not an Article 34 communication, and not an ICO filing. It tracks a clock the organization already recorded. It is not a determination that CRA applies. The CRA Article 14 reporting guide on this site is that ladder's statute. A named human still submits.

There is no UK-only GDPR framework key and no UK-only reporting ladder. GDPR is a bundled framework in the catalog (`gdpr`, labelled GDPR (2016/679) readiness — a starter subset, not the full EU regulation and not the UK GDPR). The obligation map lists frameworks the organization has marked in-scope. That in-scope mark is not a determination that UK GDPR applies, not an Article 3 territorial analysis, not an Art. 3 / UK GDPR applicability opinion, and not a legal opinion that Articles 33–34 have been triggered. The GDPR starter control set is crosswalked to canonical controls; evidence collection and the evidence-review overlay record control-mapped artifacts for that starter subset. Those rows are not an Article 33(3) pack, not an Article 33(5) register, and not an ICO form. The cyber risk register lives under Security. None of those surfaces files a UK GDPR Article 33 notice, an Article 34 communication, a PECR notification, or an EU GDPR DPA notice.

Primary sources (last verified 8 September 2026)

Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.

UK GDPR Articles 33 and 34 (legislation.gov.uk, assimilated Regulation (EU) 2016/679 as amended) are legal requirements only when UK GDPR applies. Article 33(1) is controller-to-Commissioner (72 hours from becoming aware, unless unlikely to result in a risk). Article 33(2) is processor-to-controller (without undue delay). Article 33(3) is the ICO-notice content list. Article 33(4) allows phases. Article 33(5) is the documentation duty even when there is no notice. Article 34 is controller-to-data-subject when likely high risk, with Article 34(3) exceptions; Article 34(4) names the Commissioner. Recitals 85–87 sit with those articles. Articles 3, 4(12), 28, and 83, and DPA 2018 section 157, are cited where this page names territorial scope, the definition of a personal data breach, processor assistance, and fine maxima. DPA 2018 Part 3 sections 67–68 are a different law-enforcement duty. ICO personal-data-breach pages, the ICO self-assessment, and WP29 WP250 rev.01 as the ICO cites them are regulator guidance, not the UK GDPR. ICO PECR security-breaches guidance is PECR guidance. Data (Use and Access) Act 2025 (c. 18), SI 2026/82, and SI 2026/386 are cited only for commencement status last verified above. The GDPR breach-notification guide on this site is the EU leaf. The CRA Article 14 reporting guide on this site is a different instrument. These are the UK articles this page treats, not a complete world list of breach laws. Not legal advice.

The reporting-deadlines page on this site is the statute table of clocks. The regulator-customer-individual page on this site is the three-stream comparison. The which-jurisdictions-apply page on this site is the Article 3 applicability map. The how-regulators-determine-knowledge page on this site is the clock-start analysis. The prepare-regulatory-report page on this site is the field checklist. The document-your-decision page on this site is the decision record. The supporting-evidence page on this site is the evidentiary record. The failure-to-report-consequences page on this site is the maxima table. The GDPR breach-notification guide on this site is Articles 33–34 of EU GDPR. The NIS2 incident-reporting guide on this site. The DORA incident-reporting guide on this site is the jurisdiction treatment of Articles 18–19. The CRA Article 14 reporting guide on this site. The US-state-laws guide on this site is the representative high-variance comparison. The SEC cyber-disclosure guide on this site is Form 8-K Item 1.05 and Item 106. A dedicated HIPAA, Canada PIPEDA, Australia NDB, India DPDP / CERT-In, and UAE/Dubai guide is not on this site yet. Naming them is not a link.

Frequently asked questions

When must you notify a UK GDPR personal data breach?

Article 33(1): the controller notifies the Commissioner without undue delay and, where feasible, not later than 72 hours after having become aware, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Article 34 is a separate high-risk communication to the data subject, without undue delay — not 72 hours. Last verified 8 September 2026. Not legal advice.

Is this legal advice?

No. It is a UK GDPR jurisdiction guide distilled from UK GDPR Articles 33 and 34, the Data Protection Act 2018, ICO personal-data-breach pages (regulator guidance, not the UK GDPR), and ICO PECR guidance. Whether UK GDPR applies, whether you have become aware, and whether a risk or high-risk threshold is met are legal questions for counsel on your facts. This page does not start a reporting clock.

Does ShipReady file with the ICO?

No. The signed-in app does not file Article 33 with the ICO, does not send Article 34 communications, does not submit the ICO self-assessment or online form, and does not start those clocks. Compliance → CRA reporting tracks the Article 14 ladder from recorded awareness for findings the org classified as CRA-in-scope — one product tracker, not Article 33. The obligation map is frameworks marked in-scope, not a determination that UK GDPR applies. There is no UK-only GDPR filing surface.

Does an EU GDPR filing discharge UK GDPR?

No. EU GDPR and UK GDPR are separate leaves. Article 33(1) EU GDPR points at the supervisory authority competent under Article 55; UK GDPR Article 33(1) points at the Commissioner. Filing one never discharges the other. The GDPR breach-notification guide on this site is the EU leaf. Not legal advice.

Is PECR the same 72-hour duty as UK GDPR Article 33?

No. PECR is a different regime for public electronic communications service providers. ICO PECR guidance currently restates a 72-hour ICO notice on a different form, and says PECR reporting takes the place of UK GDPR breach reporting for those providers. Do not paste Article 33 onto every PECR incident. Counsel applies YOUR facts. Not legal advice.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.