What to do if your charity has a data breach

If personal data has been lost, stolen or exposed, act at once. First contain the breach and stop it spreading, then work out whose data and what kind was affected. If people’s rights are likely to be at risk, you must report to the ICO within 72 hours of becoming aware. This playbook walks you through the first 24 hours, the first week, and your exact reporting duties.

A data breach is not only a hacker: a mis-sent email, a lost USB stick, a stolen laptop or a compromised email account all count. The steps below apply to charities across the UK. Data protection is UK-wide, so the ICO duties are the same in England, Wales, Scotland and Northern Ireland; the Charity Commission steps apply in England and Wales, with OSCR and CCNI equivalents noted.

You must report a notifiable personal data breach to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it (Source: ICO, “Personal data breaches: a guide”, accessed 10 July 2026).

Before you do anything: contain it and preserve evidence

Your first job is to stop the breach getting worse, then preserve the evidence of what happened. Do not delete emails, wipe devices or “tidy up” — you will need the trail to assess the breach and to report it. Move quickly but keep a calm, dated record of what you find and what you do, because you may have to explain your decisions to the ICO.

If the breach is a live cyber attack, get technical help immediately and disconnect affected devices from the network rather than switching them off, where you can, to preserve evidence — but follow specialist advice.

The first 24 hours

In the first day, contain the breach, understand roughly what happened, and start the 72-hour clock. Work out what data was involved and whose, whether it is still exposed, and how serious the risk to those people is. Bring in IT or cyber support if the cause is technical, and tell the people in your charity who need to respond.

  • Contain it. Stop the breach spreading — recall or delete a mis-sent email and ask the recipient to delete it, disable a compromised account, reset passwords, or isolate an affected device with specialist help.
  • Find out what was affected. Identify what personal data was involved, how much, and whose — beneficiaries, donors, staff or volunteers — and whether any of it is sensitive (health, financial, safeguarding).
  • Assess the risk to people. Judge how likely the breach is to harm those individuals — identity theft, distress, financial loss, safety. This decides whether you must report and whether you must tell them.
  • Note when you became aware. Record the date and time — the 72-hour ICO clock runs from here.
  • Preserve evidence and log decisions. Keep a written record of what happened, what you have done, and why.
  • Get help if it is a cyber attack. Contact IT or cyber support and report the incident to the NCSC at report.ncsc.gov.uk.

The first week

In the first week, make the reports the law requires, tell affected people if the risk is high, and begin to put things right. This is when you notify the ICO if the breach is notifiable, inform individuals where the risk to them is high, report any cyber-crime, consider a serious incident report to the Charity Commission, and review how it happened.

  • Report to the ICO if notifiable. If the breach is likely to risk people’s rights, report it within 72 hours of becoming aware, using the ICO’s online form. If you cannot yet provide every detail, report what you have and follow up in phases.
  • Tell affected individuals if the risk is high. Where the breach is likely to be high risk, tell those people without undue delay, in plain language, and explain what they can do to protect themselves.
  • Report cyber-crime. If it was an attack, report to Report Fraud (0300 123 2040) in England, Wales and Northern Ireland, or Police Scotland on 101, and to the NCSC.
  • Consider a serious incident report. If the breach is significant for your charity, report it to the Charity Commission as a serious incident (OSCR in Scotland, CCNI in Northern Ireland).
  • Notify your insurer. If you hold cyber or data cover, tell your insurer promptly.
  • Fix and review. Close the vulnerability, and review what went wrong so it cannot happen the same way again.

Your reporting duties, precisely

A data breach can trigger several duties at once, to different bodies. The core one is to the ICO; on top of that you may have to tell affected individuals, report a cyber-crime, and make a Charity Commission serious incident report. Check each against your situation.

The ICO (within 72 hours, if notifiable)

Report a personal data breach to the ICO without undue delay and within 72 hours of becoming aware, where it is likely to risk people’s rights and freedoms. Use the ICO’s online reporting form; if you are unsure whether to report, the ICO’s confidential helpline is 0303 123 1113. You must record every breach internally, even the ones you decide not to report. This duty is the same across the whole UK.

Affected individuals (if high risk)

If the breach is likely to result in a high risk to people’s rights and freedoms, you must tell those individuals without undue delay. Explain, in clear plain language, what happened and what they can do to protect themselves. The point is to let people act — change a password, watch for fraud, be alert to scams.

The Charity Commission (if significant)

A significant data breach can be a reportable serious incident in its own right, separate from the ICO duty — for instance where it affects many people, involves sensitive data, or seriously harms the charity. Report promptly; the duty rests with the trustees. In Scotland report to OSCR; in Northern Ireland to CCNI.

NCSC and the police (if a cyber attack)

Report a cyber incident to the NCSC at report.ncsc.gov.uk, and report the crime through Report Fraud (0300 123 2040) in England, Wales and Northern Ireland, or Police Scotland on 101. For ransomware, do not pay without advice — payment does not guarantee recovery and can carry legal and sanctions risks.

Who to call

Keep this to hand. In the first hours the priority is containing the breach and assessing risk; then come the ICO, affected people, and any cyber-crime report. The full set of contacts is below.

  • IT or cyber support — first, to contain a technical breach and preserve evidence.
  • The ICO — online breach report; helpline 0303 123 1113 if unsure whether to report.
  • The NCSC — report.ncsc.gov.uk, for cyber incidents.
  • Report Fraud (police) — 0300 123 2040 (England, Wales, Northern Ireland); Police Scotland 101; 999 if there is an immediate threat.
  • The Charity Commission — serious incident report if the breach is significant (OSCR / CCNI equivalents).
  • Your insurer — promptly, if you hold cyber or data cover.
  • Your funders — if their data or grant-related information was affected.

Stopping it happening again

Once the breach is contained and reported, fix the cause and reduce the chance of a repeat. Most charity data breaches come from simple, preventable causes — a weak or reused password, no two-factor authentication, sending to the wrong recipient, or an unencrypted device. A few basic controls prevent the majority of them. Record the lessons and the changes, and report the review to your trustees.

Practical steps that help: turn on two-factor authentication on email and key systems; use strong, unique passwords or a password manager; encrypt laptops and phones; limit who can access personal and sensitive data; train staff and volunteers to spot phishing; and keep software updated. Follow the NCSC’s free guidance for charities and review your data risks in your risk register at least annually.

CharityIQ is built to keep personal data grounded and access logged, and never trains public models on your data — but strong basics like two-factor authentication and staff awareness remain your first line of defence.