UK GDPR Data Breaches: ICO Notification & Best Practice
Introduction
The UK GDPR requires controllers to notify the ICO of ‘personal data breaches’ in most cases and failure to do so increases the likelihood of enforcement action being taken against them.
A significant proportion of fines that have been levied under the UK GDPR to date relate to security breaches and several of these have exceeded £1million. In particular, controllers have been criticised for failing to implement multi-factor authentication and adequate back-up systems which has left them vulnerable to malware and ransomware attacks.
This webinar summarises the key provisions of the UK GDPR concerning data breaches and the relevant ICO guidance and summarises the key lessons to be learned from the ICO’s enforcement action.
What You Will Learn
This webinar will cover the following:
- Meaning of ‘personal data breach’ - wider than you might think
- Notification requirement - when and how to notify
- Communication requirement - when and how to communicate
- Risk assessment factors
- Reporting a breach to the ICO - key questions to be answered
- Enforcement action - lessons to be learned
- Summary of practical steps to take
This pre-recorded webinar will be available to view from Thursday 28th May 2026
Alternatively, you can gain access to this webinar and 2,101 others via the MBL Webinar Subscription. Please email webinarsubscription@mblseminars.com for more details.









