WorldPrivacyAtlas
Laws by country

Data Security & Breach Notification

UK GDPR and Data Protection Act 2018 — personal data breach notification

UK GDPR Arts. 33-34

United Kingdom · May 25, 2018 (as EU law); continued as UK GDPR from January 1, 2021

The UK carried the GDPR breach regime over unchanged at Brexit: 72 hours to the ICO from awareness unless the breach is unlikely to result in a risk, and notification to affected individuals without undue delay where the risk to them is high. The Data (Use and Access) Act 2025 amended several parts of UK data protection law but did not shorten, lengthen, or remove this deadline. The practical divergence from the EU is jurisdictional rather than substantive: a breach touching both UK and EU residents is now two notifications to two regulators on the same clock, and the ICO runs its own reporting service and self-assessment tool.

UK GDPR (assimilated Regulation (EU) 2016/679), Arts. 32-34; Data Protection Act 2018 (c. 12)Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.