---
title: "72-Hour Breach Notification Guide: meet GDPR | Firevault"
description: "UK GDPR requires breach notification to the ICO within 72 hours. When your email, document systems, and contact databases are encrypted, meeting this deadline…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/guides/72-hour-breach-notification#webpage",
      "url": "https://fire-vault.com/learn/guides/72-hour-breach-notification",
      "name": "72-Hour Breach Notification Guide: meet GDPR",
      "description": "UK GDPR requires breach notification to the ICO within 72 hours. When your email, document systems, and contact databases are encrypted, meeting this deadline…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2F72-hour-breach-notification.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/guides/72-hour-breach-notification#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/guides/72-hour-breach-notification#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Guides",
          "item": "https://fire-vault.com/learn/knowledge?filter=guides"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "The 72-Hour Breach Notification Window",
          "item": "https://fire-vault.com/learn/guides/72-hour-breach-notification"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "The 72-Hour Breach Notification Window",
      "description": "UK GDPR requires breach notification to the ICO within 72 hours. When your email, document systems, and contact databases are encrypted, meeting this deadline becomes a governance challenge that only prior preparation can solve.",
      "url": "https://fire-vault.com/learn/guides/72-hour-breach-notification",
      "image": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2F72-hour-breach-notification.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "datePublished": "2026-02-19T09:13:51.962911+00:00",
      "dateModified": "2026-08-28T07:05:10.849702+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/guides/72-hour-breach-notification"
      },
      "inLanguage": "en-GB",
      "articleSection": "Compliance",
      "wordCount": 582,
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

The Clock Starts TickingWhat You Need Within 72 HoursThe Notification Content Require…How OSS Solves the 72-Hour ProblemBeyond Compliance: The Reputatio…Practical ImplementationConclusionMore

[Guides](/learn/knowledge?filter=guides)/ Compliance 

Compliance · 19 February 2026 

# The 72-Hour Breach Notification Window

UK GDPR requires breach notification to the ICO within 72 hours. When your email, document systems, and contact databases are encrypted, meeting this deadline becomes a governance challenge that only prior preparation can solve.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

3 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2F72-hour-breach-notification)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2F72-hour-breach-notification&text=The%2072-Hour%20Breach%20Notification%20Window%0A%0AUK%20GDPR%20requires%20breach%20notification%20to%20the%20ICO%20within%2072%20hours.%20When%20your%20email%2C%20document%20systems%2C%20and%20contact%20databases%20are%20encrypted%2C%20meeting%20this%20deadline%20becomes%20a%20governance%20challenge%20that%20only%20prior%20preparation%20can%20solve.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2F72-hour-breach-notification)[](mailto:?subject=The%2072-Hour%20Breach%20Notification%20Window&body=UK%20GDPR%20requires%20breach%20notification%20to%20the%20ICO%20within%2072%20hours.%20When%20your%20email%2C%20document%20systems%2C%20and%20contact%20databases%20are%20encrypted%2C%20meeting%20this%20deadline%20becomes%20a%20governance%20challenge%20that%20only%20prior%20preparation%20can%20solve.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2F72-hour-breach-notification)

![The 72-Hour Breach Notification Window](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2F72-hour-breach-notification.jpg)

Compliance 

Why it matters

## What this means for organisations holding critical data

UK GDPR requires breach notification to the ICO within 72 hours. When your email, document systems, and contact databases are encrypted, meeting this deadline becomes a governance challenge that only prior preparation can solve.

**On this page**[The Clock Starts Ticking](#section-0)[What You Need Within 72 Hours](#section-1)[The Notification Content Require…](#section-2)[How OSS Solves the 72-Hour Problem](#section-3)[Beyond Compliance: The Reputatio…](#section-4)[Practical Implementation](#section-5)[Conclusion](#section-6)

On this page

1.  [The Clock Starts Ticking](#section-0)
2.  [What You Need Within 72 Hours](#section-1)
3.  [The Notification Content Requirements](#section-2)
4.  [How OSS Solves the 72-Hour Problem](#section-3)
5.  [Beyond Compliance: The Reputational Dimension](#section-4)
6.  [Practical Implementation](#section-5)
7.  [Conclusion](#section-6)

## The Clock Starts Ticking

Under UK GDPR Article 33, organisations must notify the ICO within 72 hours of becoming aware of a personal [data breach](/learn/breaches). The forthcoming Cyber Security and Resilience Bill is expected to introduce even shorter notification windows for operators of essential services.

Seventy-two hours sounds like adequate time. Until you consider that in a major cyber incident, your email is down, your document management system is encrypted, your contact databases are inaccessible, and your legal team cannot access the notification templates they prepared for exactly this situation.

## What You Need Within 72 Hours

To meet notification requirements, your team needs access to:

-   **ICO contact details and notification portal information**
-   **Pre-drafted notification templates** that comply with Article 33(3) content requirements
-   **Data processing records** that identify what personal data was held and how it was processed
-   **Breach counsel contact details** and insurance policy notification procedures
-   **Sector-specific regulator contacts** (FCA, Ofcom, CQC, etc.) if additional notification obligations apply
-   **Communication templates** for notifying affected individuals under Article 34

Every one of these items is typically stored on connected systems. Every one becomes inaccessible at exactly the moment it is needed most.

## The Notification Content Requirements

Article 33(3) specifies that notification must include:

1.  The nature of the personal data breach, including categories and approximate numbers of data subjects and records
2.  The name and contact details of the Data Protection Officer
3.  A description of likely consequences
4.  A description of measures taken or proposed to address the breach

Providing this information requires access to data processing records, risk assessments, and organisational documentation that may be encrypted or inaccessible during the incident.

## How OSS Solves the 72-Hour Problem

[Offline Secure Storage](/offline-secure-storage)® ensures that everything needed for breach notification is accessible regardless of connected system status:

### Pre-Staged Notification Packs

Maintain offline copies of pre-drafted notification templates for the ICO, sector regulators, and affected individuals. These templates should be pre-populated with standing information (organisation details, DPO contacts, processing descriptions) so that incident-specific details can be added quickly.

### Regulatory Contact Directory

A complete offline directory of regulatory contacts, including ICO regional offices, sector regulators, breach counsel, insurance notification lines, and law enforcement contacts.

### Data Processing Summaries

Offline copies of your Record of Processing Activities (ROPA) and data flow maps, enabling your team to identify what personal data may have been affected without access to connected systems.

### Communication Protocols

Pre-defined communication channels and procedures for coordinating the notification process when standard communication tools are unavailable.

## Beyond Compliance: The Reputational Dimension

Organisations that notify promptly and comprehensively are treated more favourably by regulators. The ICO has explicitly stated that the quality and timeliness of notification is a factor in enforcement decisions. Being able to demonstrate that you had governance procedures in place to meet notification requirements, even during a major incident, signals the kind of organisational maturity that regulators reward.

## Practical Implementation

1.  **Create a Notification Pack.** Assemble all templates, contacts, and procedures into a single governed package.
2.  **Store it offline.** Place the pack in [physically disconnected storage](/storage) with identity-verified access.
3.  **Update quarterly.** Regulatory contacts, DPO details, and processing records change. Establish a quarterly review cycle.
4.  **Test annually.** Include notification procedures in your incident response exercises. Time the process to verify you can complete it within 72 hours.

## Conclusion

The 72-hour notification window is not a generous deadline when your systems are down. It is a governance challenge that requires preparation. Offline secure storage ensures that the documentation, contacts, and templates needed for regulatory notification are accessible precisely when connected systems are not.

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

[Get started](/get-started)[Talk to the team](/demo)

**Custody**Named, access-controlled hardware in a Firevault Bunker 

**Evidence**Access windows and retrieval events are recorded 

**Separation**Physical isolation that satisfies offline copy requirements 

**Jurisdiction**Stored where your regulatory position requires 

Related Reading

## You may also find these useful

[

![ICO Fines Data Breach: A Security Wake-Up Call](/__l5e/assets-v1/140d47c1-4862-44b4-bd59-dfa7f604bb32/ico-imposes-fine-for-data-breach-a-wake-up-call-for-security-1771660854229-2x.jpg)

Compliance 

### ICO Fines Data Breach: A Security Wake-Up Call

The Information Commissioner's Office (ICO) has issued a significant fine following a serious data breach. This enforcement action underscores the critical importance of robust cybersecurity measures for all organisations handling personal data.

21 Feb 2026 4 min 







](/news/ico-imposes-fine-for-data-breach-a-wake-up-call-for-security)[

![NIS2 Directive: Bolstering UK Cyber Resilience](/__l5e/assets-v1/c63aada9-5048-4eb0-86b9-ed6b57370c4c/nis2-directive-bolstering-uk-cyber-resilience-1771401643177-2x.jpg)

Compliance 

### NIS2 Directive: Bolstering UK Cyber Resilience

The NIS2 Directive has come into force, significantly expanding the scope of cybersecurity regulations across the European Union. While not directly applicable to the UK, its influence on supply chain security and best practices is undeniable, urging UK businesses to review their cyber defences.

18 Feb 2026 4 min 







](/news/nis2-directive-bolstering-uk-cyber-resilience)[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. Most of it came from free terminal WiFi sign-ups and from car parking, lounge and fast-track bookings.

27 Aug 2026 5 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

![David Bailey](/assets/david-bailey-Dgqj8eaE.jpg)

![Kenny Phipps](/assets/kenny-phipps-CVyooRsR.jpg)

Online Now 

Concierge 

## Put this guide into practice

Ready to apply what you have learned? Explore how Firevault delivers the offline protection covered in this guide.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up