Just a moment
Trust, privacy & GDPR

Reporting a data breach

What counts as a breach, the 72-hour rule and how to act quickly.

2 min readUpdated 6 August 2026

A data breach is any security incident that puts personal data at risk, such as data being lost, exposed or accessed by the wrong person. If one is likely to harm the people involved, it must be reported to the regulator within 72 hours.

What counts

  • A device or login falling into the wrong hands
  • Personal data sent to the wrong person
  • Data being accessed or taken without permission

What to do straight away

  1. 1Contain it. Change passwords, end sessions and stop the data going any further.
  2. 2Assess it. What data was involved, how many people and how serious is the risk.
  3. 3If there is a real risk to people, report it to the ICO within 72 hours of becoming aware.
  4. 4If the risk is high, tell the affected people too.

How Youzse helps

You can raise an incident inside Youzse, and the platform helps you pull together what the regulator needs, with a report template populated from the details. Tools like two-factor sign-in, trusted devices and session controls help prevent incidents in the first place.

If you think something has happened

Act quickly and get in touch with the Youzse team. Moving fast is what counts.

Common questions

What counts as a breach?

Personal data lost, exposed or accessed by somebody who should not have it. A misdirected email can qualify.

How quickly must I report?

Within 72 hours of becoming aware, where the breach is likely to be a risk to people.

Who do I report to?

The ICO, and the people affected where the risk to them is high.

Topics

GdprSecurityBreach

We value your privacy

Cookies keep Youzse running, improve the platform and help deliver relevant content. Read our privacy policy and cookie policy.