Brightstar Law
INSIGHTS· DATA & GDPR · 5 MIN READ

Responding to a data breach in the first 72 hours

What every employer should plan before consultation begins — the thresholds that catch businesses out, and how to protect morale and reputation while you do it.

The first 72 hours after discovering a data breach are decisive. Under UK GDPR you may be required to notify the ICO within that window, so the clock starts the moment you become aware — not when the investigation is complete.", "Start by containing the incident and preserving evidence. Establish what data was affected, how many individuals are involved, and the likely risk to their rights and freedoms. That risk assessment determines whether the ICO, the affected individuals, or both need to be told.", "Document every decision as you go, including the reasoning where you decide notification is not required. A clear, contemporaneous record is your best protection if the regulator later reviews how you handled the breach.