Data Protection Act 2018UK · 2018 c. 12
Digiphile

Sections

Section 67Notification of a personal data breach to the [F1Commission]

(1) If a controller becomes aware of a personal data breach in relation to personal data for which the controller is responsible, the controller must notify the breach to the [F2Commission]—
  • (a)
    without undue delay, and
  • (b)
    where feasible, not later than 72 hours after becoming aware of it.
(2) Subsection (1) does not apply if the personal data breach is unlikely to result in a risk to the rights and freedoms of individuals.
(3) Where the notification to the [F3Commission] is not made within 72 hours, the notification must be accompanied by reasons for the delay.
(4) Subject to subsection (5), the notification must include—
  • (a)
    a description of the nature of the personal data breach including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
  • (b)
    the name and contact details of the data protection officer or other contact point from whom more information can be obtained;
  • (c)
    a description of the likely consequences of the personal data breach;
  • (d)
    a description of the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
(5) Where and to the extent that it is not possible to provide all the information mentioned in subsection (4) at the same time, the information may be provided in phases without undue further delay.
(6) The controller must record the following information in relation to a personal data breach—
  • (a)
    the facts relating to the breach,
  • (b)
    its effects, and
  • (c)
    the remedial action taken.
(7) The information mentioned in subsection (6) must be recorded in such a way as to enable the [F4Commission] to verify compliance with this section.
(8) F5 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
(9) If a processor becomes aware of a personal data breach (in relation to personal data processed by the processor), the processor must notify the controller without undue delay.

Amended text

This Section is shown as amended by the Data (Use and Access) Act 2025 (c. 18), among other instruments (see the annotations below) (commenced provisions as at 30 September 2026, ELI), as incorporated in the text in force on 30 September 2026 as published on legislation.gov.uk.