The rules and principles which apply
Article 33 UK GDPR places a duty on all organisations to report certain types of personal data breach to the relevant supervisory authority. You must do this within 72 hours of becoming aware of the breach, where feasible.
A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This includes breaches that are the result of both accidental and deliberate causes. It also means that a breach is more than just about losing personal data.
Personal data breaches can include examples such as:
- access by an unauthorised third party;
- deliberate or accidental action (or inaction) by a controller or processor;
- sending personal data to an incorrect recipient;
- computing devices containing personal data being lost or stolen;
- alteration of personal data without permission; and
- loss of availability of personal data.
A personal data breach is a security incident that has affected the confidentiality, integrity, or availability of personal data. In practice, there will be a personal data breach whenever any personal data is lost, destroyed, corrupted or disclosed; if someone accesses the data or passes it on without proper authorisation; or if the data is made unavailable, for example, when it has been encrypted by ransomware, or accidentally lost or destroyed.
When a security incident takes place, you should quickly establish whether a personal data breach has occurred and, if so, promptly take steps to address it, including telling the ICO if required.
Article 34 UKGDPR also requires a firm to notify the data subject of the breach where this is likely to result in a high risk to their rights and freedoms, along with any mitigating measures i.e. encryption and any subsequent measures taken to mitigate the impact. If there are multiple individuals affected then a firm may also make a public communication or similar measure but must ensure that all affected data subjects are informed in an equally effective manner.
How this may affect you
Breach notifications to the ICO
When a personal data breach has occurred, you need to establish the likelihood and severity of the resulting risk to people’s rights and freedoms. If it is likely that there will be a risk, then you must notify the ICO, if it’s unlikely then you don’t have to report it. However, if you decide you don’t need to report the breach, you need to be able to justify this decision, so you should document it.
In assessing risk to rights and freedoms, it is important to focus on the potential negative consequences for individuals. Recital 85 of the GDPR explains that:
“A personal data breach may, if not addressed in an appropriate and timely manner, result in physical, material or non-material damage to natural persons such as loss of control over their personal data or limitation of their rights, discrimination, identity theft or fraud, financial loss, unauthorised reversal of pseudonymisation, damage to reputation, loss of confidentiality of personal data protected by professional secrecy or any other significant economic or social disadvantage to the natural person concerned.”
This means that a breach can have a range of adverse effects on individuals, which include emotional distress, and physical and material damage. Some personal data breaches will not lead to risks beyond possible inconvenience to those who need the data to do their job. Other breaches can significantly affect individuals whose personal data has been compromised. You need to assess this case by case, looking at all relevant factors.
On becoming aware of a breach, you should try to contain it and assess the potential adverse consequences for individuals, based on how serious or substantial these are, and how likely they are to happen.
CORE27 is a template that you can use to develop a breaches and issues policy which includes data protection breaches.
When reporting a breach, the UK GDPR says you must provide:
- a description of the nature of the personal data breach including, where possible,
- the categories and approximate number of individuals concerned,
- the categories and approximate number of personal data records concerned,
- the name and contact details of the data protection officer (if your organisation has one) or other contact point where more information can be obtained,
- a description of the likely consequences of the personal data breach; and
- a description of the measures taken, or proposed to be taken, to deal with the personal data breach, including, where appropriate, the measures taken to mitigate any possible adverse effects.
The UK GDPR recognises that it will not always be possible to investigate a breach fully within 72 hours to understand exactly what has happened and what needs to be done to mitigate it, so Article 33(4) allows you to provide the required information in phases, as long as this is done without undue further delay.
However, the ICO expect controllers to prioritise the investigation, give it adequate resources, and expedite it urgently. You must still notify the ICO of the breach when you become aware of it and submit further information as soon as possible. If you know you will not be able to provide full details within 72 hours, you should explain the delay to the ICO and tell them when you expect to submit more information.
If the breach is likely to result in a high risk of adversely affecting individuals’ rights and freedoms, you must also inform those individuals without undue delay.
You should ensure you have robust breach detection, investigation, and internal reporting procedures in place. This will facilitate decision-making about whether or not you need to notify the relevant supervisory authority and the affected individuals.
You must also keep a record of any personal data breaches, regardless of whether you are required to notify. CORE09 is a template breach register which includes the recording of data protection breaches.
To notify the ICO of a personal data breach, please see our pages on reporting a breach.
Consequences of failing to report a breach
Failing to notify a breach when required to do so can result in a heavy fine up to €10m or 2% of your global turnover. The fine can be combined with the ICO’s other corrective powers under Article 58, therefore it is important to make sure you have a robust breach-reporting process in place to ensure you detect, and notify breaches, on time; and to provide the necessary details (unless the personal data breach is unlikely to result in a risk to the rights and freedoms of data subjects). If you decide you don’t need to report the breach, you need to be able to justify this decision and keep a written record of this which should be approved by a Senior Management Function Holder.
Operational Incident Reporting to the FCA
All directly regulated firms are required to report operational and material incidents to the FCA under Principle 11 which states that firms must deal with the FCA in an open and cooperative way and must disclose to the FCA appropriately anything relating to the firm of which it would reasonably expect notice. A significant or systemic data breach may
This can be either a single event or a series of linked events which disrupts the firm’s operations such that it:
- disrupts the delivery of a service to an end user external to the firm; and/or
- impacts the availability, authenticity, integrity or confidentiality of information or data relating or belonging to such an end user.
Only operational incidents that meet certain thresholds need to be reported which are defined as where a firm reasonably believes that an operational incident poses a risk:
- of causing intolerable levels of harm to consumers from which consumers cannot easily recover (‘consumer harm’); and/or
- to the safety and soundness of the firm and/or other market participants (‘safety and soundness’); and/or
- to market stability, market integrity, or confidence in the UK financial system (‘market stability’).
A significant or systemic data breach may trigger one or more of these thresholds and may require notification to the FCA as well as the ICO.
Submitting an Operational Incident Report
There are 2 tiers of incident reporting: ‘standard’ and ‘enhanced’ most SME broking firms will be required to submit standard reports but may choose to submit an enhanced report if they wish (Enhanced SM&CR firms must always complete an ‘enhanced’ report).
Firms should report an incident within 24 hours of determining that it meets one of the reporting thresholds but sooner if practicable.
Standard incident reporting is a single report submitted via Connect, requiring firms to provide basic information about an operational incident. Firms are not required to update a standard incident report once it has been submitted, however in some cases, depending on the severity of the incident and quality of information submitted, the FCA may request more information.
It is important that firms take the time to fully analyse the root cause of significant operational incidents stemming from data security failures or operational resilience relating to system access or failure. You should ensure that these lessons learned are documented and acted on, we cover operational resilience in further detail in Section A.12.