What Should a Business Do After a Data Breach?
A data breach rarely announces itself politely. One missing laptop, one clicked phishing link, and suddenly a small business is facing a legal deadline it never planned for. The first few hours set the tone for everything that follows.
Preparation is what separates a scare from a disaster. A clear step-by-step guide to the first 72 hours of a data breach turns panic into process. Every UK organisation that handles personal data should know the drill before it needs it.
Why Do the First 72 Hours Matter So Much?
The clock is not a metaphor here. Under UK law, certain breaches must be reported to the regulator within 72 hours of discovery. That single rule shapes the entire response.
A personal data breach is a security incident that leads to personal data being lost, stolen, or exposed. Not every incident qualifies, but many do. Knowing the difference quickly is the first real test.
Speed also limits the damage. Fast containment reduces how much data is exposed and how many people are affected. The sooner you act, the smaller the problem stays.
What Are the First Steps to Take?
The opening moves should be calm and deliberate. A short checklist keeps a stressful moment on track.
- Contain it. Isolate affected systems and revoke compromised access at once.
- Assess the scope. Identify what data, and whose, may be involved.
- Preserve evidence. Log actions and keep records for the investigation.
- Convene the team. Bring in IT, management, and legal support fast.
- Start the clock. Note the discovery time, since the 72 hours run from it.
How Do You Know If You Must Report It?
Not every incident needs a regulator’s attention. The test is whether the breach risks people’s rights and freedoms. A lost, encrypted laptop differs sharply from an exposed customer database.
The regulator sets the threshold. The Information Commissioner’s Office is the UK’s independent data protection authority, and its breach reporting hub is where you confirm what must be reported and when. When in doubt, its resources help you decide.
Documentation matters even when you do not report. A data subject is any individual whose personal data you hold, and you must record breach decisions affecting them. Regulators expect a clear reasoning trail either way.
What About Telling the People Affected?
Sometimes the regulator is not the only party to inform. When a breach is likely to result in a high risk to individuals, you must tell them too. Honesty here protects both people and reputation.
Clear communication beats legal jargon. Explain what happened, what data was involved, and what steps people should take. A calm, specific message reassures far more than silence.
Timing is a balance. You should not delay a warning that helps people protect themselves, but you also need accurate facts. Underpinning data protection rules give the framework for getting that balance right.
How Do You Prevent the Next One?
The best breach response starts long before the breach. Prevention is cheaper, calmer, and far less public than a cleanup. A few habits do most of the work.
- Train staff. Most breaches start with human error, not hacking.
- Limit access. Only give data access to those who genuinely need it.
- Encrypt devices. A stolen encrypted laptop is a scare, not a breach.
- Test your plan. Rehearse the response before you ever need it.
Good governance links to good business generally. The same discipline behind sound financial management applies to protecting data: clear systems, regular review, and no shortcuts.
What Are the Stakes for Getting It Wrong?
The penalties are designed to focus minds. Serious UK data protection breaches can draw fines of up to £17.5 million or 4% of global annual turnover, whichever is higher. For a small firm, even a fraction of that is existential.
The financial hit is only part of it. A mishandled breach erodes the customer trust that a brand makeover works hard to build. Reputation, once dented, is slow to repair.
The flip side is reassuring. Businesses that respond well often retain customer confidence, because people judge the handling as much as the incident. Competence under pressure is its own kind of marketing.
What to Keep In Mind
- Reportable breaches must reach the regulator within 72 hours of discovery.
- A personal data breach exposes, loses, or steals personal data.
- Contain, assess, preserve evidence, convene the team, and note the time.
- High-risk breaches also require telling the affected individuals.
- Serious breaches can draw fines up to £17.5 million or 4% of turnover.
- Prevention through training and access control beats any cleanup.
Turning a Crisis Into a Controlled Process
A data breach is stressful, but it does not have to be chaotic. With a rehearsed plan, a clear grasp of the 72-hour rule, and honest communication, a business can contain the harm and keep its customers’ trust. Preparation is the difference between a controlled process and a crisis.
FAQ
Do I Have to Report Every Data Breach?
No. You must report a breach to the regulator only when it risks people’s rights and freedoms. You still have to record every breach and your reasoning, even the ones you do not report.
What Is the 72-Hour Rule?
Reportable personal data breaches must be reported to the ICO within 72 hours of the organisation becoming aware of them. The clock starts at discovery, not at the incident itself. Missing the deadline can itself draw scrutiny.
When Must I Tell Affected Customers?
You must inform individuals without undue delay when a breach is likely to cause them high risk. The message should explain what happened and how they can protect themselves. Clear, prompt honesty is best.
How Can Small Businesses Prevent Breaches?
Most breaches trace back to human error, so staff training is the top priority. Limit data access, encrypt devices, and rehearse a response plan. These low-cost steps prevent the majority of incidents.




