Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

ICO reveals fivefold increase in personal data breach reports

by The Gurus
July 31, 2018
in Editor's News
cybersecurity
Share on FacebookShare on Twitter

The Information Commissioner’s Office (ICO) has revealed a big rise in the number of self-reported personal data breach notifications in the first full month following the introduction of the new General Data Protection Regulation (GDPR).

During a webinar for data controllers posted on the ICO website, Laura Middleton, head of the ICO’s personal data breach reporting team revealed there were 1,792 personal data breaches notified to the ICO in June, following the introduction of the GDPR on 25 May 2018. This was a 173 per cent rise on the 657 reports received in May 2018, and an almost fivefold increase versus April when there were just 367 notifications.

The sectors which accounted for the highest number of self-reported data breaches were the health, education, general business, solicitors and barristers, and local government sectors, according to the ICO.

Last year, the number of self-reported data breaches increased by 29 per cent from 2,447 in 2016-17 year to 3,156 in 2017-18 according to the ICO’s annual report.

The GDPR places new obligations on employers to self-report qualifying personal data breaches to the ICO within 72 hours of a breach becoming known.

Breaches can typically be of electronic records but they can also cover paper records and other media. In addition to confidentiality breaches to personal data, qualifying breaches can also include incidents of unauthorised or accidental alteration to data, or accidental or unauthorised loss off, access to, or destruction of, personal data.

David Morris, a technology risk assurance director at RSM said: ‘By the ICO’s own admission, they were expecting a significant rise in the self-reporting of personal data breaches following GDPR and the early indications are they haven’t been disappointed. 

‘This increase doesn’t necessarily mean that more data breach incidents are occurring. It’s more likely that the reporting of issues will now be more accurate as a result of the new rules. The increase may also reflect that organisations have understood the importance of the compliance work that they have been doing to prepare for GDPR and the need for the new procedures that they have spent many hours implementing.

‘Organisations that suffer a qualifying personal data breach have just 72 hours to notify the ICO and provide an assessment of the risks involved to the individuals whose data has been compromised. They are also obliged to set out what actions they propose to take to mitigate the loss and prevent it happening again.

‘The message from the ICO seems to be that organisations need to get better at recognising what type of breaches are reportable, and to carry out a full risk assessment in order to be able to make a full disclosure within the 72-hour deadline. This is a big culture change for organisations aiming to meet their GDPR compliance obligations.’

Tags: CybersecurityTechnology
ShareTweet
Previous Post

Cosco Systems Fully Recovered from Cyber Attack

Next Post

UK Card Fraud Falls 8 Percent in 2017 as Criminals Seek New Battlegrounds

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol