Software guide

Respond to a personal data breach in a small business

Contain a data breach, assess the risk to the people affected, decide whether to report it to the ICO and tell individuals, and record what happened.

Estimated time: first actions within hours, full review over daysUpdated: 28 September 2026

Use this guide if personal data your business holds has been lost, stolen, sent to the wrong person, accessed without permission or deleted by mistake. Act quickly, because reporting deadlines are short. This is general information; for serious breaches get advice from a qualified professional.

Step by step

  1. Contain the breach

    Stop it getting worse. Ask a wrong recipient to delete an email and confirm they have, change passwords, disable compromised accounts, or lock a lost device remotely. Preserve evidence such as emails and logs rather than deleting them.

  2. Work out what happened

    Record when and how it happened, when you found out, what data was involved and how many people are affected. Note whether the data was protected, for example encrypted or password protected.

  3. Assess the risk to people

    Think about the likely harm to the individuals, such as fraud, identity theft, distress or embarrassment. Sensitive information, such as health or financial details, usually raises the risk. Be honest; underestimating risk causes bigger problems later.

  4. Decide whether to report to the ICO

    If the breach is likely to result in a risk to people's rights and freedoms, you must report it to the ICO without undue delay and, where feasible, within 72 hours of becoming aware. The ICO has a self-assessment tool and a helpline. If you decide not to report, record why.

  5. Tell affected people if the risk is high

    If there is likely to be a high risk to individuals, tell them without undue delay. Explain in plain language what happened, what data was involved, what you are doing and what they can do to protect themselves.

  6. Record and learn

    Log every breach, including minor ones you did not report, with the facts, effects and actions taken. Identify the cause and fix it, such as adding two-step verification, changing a process or giving staff training.

Ready-to-use checklist

  • Breach contained
  • Evidence preserved
  • Timeline and data involved recorded
  • Risk to individuals assessed
  • ICO reporting decision made within 72 hours
  • Affected people told if high risk
  • Breach log updated
  • Cause fixed and staff briefed

Practical tips

  • Keep a simple breach log template ready so you are not designing one in a crisis.
  • If the breach involves fraud or hacking, also report it to Report Fraud.
  • Check whether your business insurance includes cyber or data breach cover and tell the insurer promptly if required.

Common problems

We are not sure if it counts as a breach.

A personal data breach covers accidental or unlawful loss, destruction, alteration, disclosure or access. An email to the wrong customer counts. Use the ICO's online guidance and self-assessment to decide next steps.

We do not yet have all the facts and 72 hours is nearly up.

You can report what you know and provide further information in phases. Do not delay the report just to complete the investigation.

A supplier had the breach, not us.

Your processor must tell you without undue delay. As the controller you usually decide on reporting, so get the facts from them quickly and follow the same steps.