(Extracted from the ICO – PIA Code of Practice)

All data breaches must be reported to the ICO within 72 hours. Breaches include accidental/unlawful destruction, loss, access, and alteration/disclosure of personal data. In the event of a data breach, the people affected must be notified and the organisation must document the impact and the remedies taken. ................
................