Notification of a personal data breach to the supervisory authority
Summary
Controller must notify ICO without undue delay and where feasible within 72 hours (UK mirrors EU GDPR Art.33).
breach notification72 hoursicoart33
Read the full official text: https://www.legislation.gov.uk/eur/2016/679/article/33
← Article 32
Security of processing
Article 34 →
Communication of a personal data breach to the data subject
Track UK GDPR article 33 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial