A serious data breach can cost a business far more than the clean-up, the Information Commissioner's Office (ICO) can impose fines reaching £17.5 million or 4% of worldwide annual turnover, whichever is higher, for serious breaches of the UK GDPR. The good news is that most breaches are preventable, and regulators look closely at whether a business took reasonable steps. Here is how small and medium businesses in England and Wales can cut their risk in 2026.
Understand what counts as a breach
A "personal data breach" is any breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of, or access to, personal data. That includes the obvious (a hacker stealing a customer database) and the everyday (an email sent to the wrong person, a lost laptop, or files left unsecured).
Put appropriate security in place
The UK GDPR (Article 32) requires "appropriate technical and organisational measures" to keep personal data secure, judged against the risk. Practical steps include:
- Encrypt laptops, devices and sensitive files.
- Control access, staff should only reach the data they need, with strong, unique passwords and multi-factor authentication.
- Keep software patched and updated, and back data up securely.
- Use written data processing agreements with any supplier who handles personal data for you.
Train your people, the human factor
A large share of breaches come from human error, not hackers: a misdirected email, a weak password, a click on a phishing link. Regular, practical staff training is one of the cheapest and most effective protections, and the ICO expects to see it.
Collect less, keep it for less time
You cannot lose what you do not hold. Apply data minimisation: only collect personal data you genuinely need, and delete it when you no longer need it. Smaller datasets mean smaller risk and smaller breaches.
Have an incident response plan, and the 72-hour clock
If a breach happens, your response is judged as much as the breach itself. The UK GDPR (Article 33) generally requires you to notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of a breach that poses a risk to people's rights. Where there is a high risk to individuals, you must also tell the affected people without undue delay (Article 34). A written plan (who decides, who reports, what is recorded) makes hitting that deadline realistic.
Co-operate and document
When the ICO investigates, it can issue enforcement notices requiring you to put things right (Data Protection Act 2018, s 149), and it weighs how seriously you took your obligations. Keeping records of your security measures, training and breach response demonstrates accountability, and accountability is exactly what reduces the chance and the size of a fine.
Note: the data protection framework is being updated by the Data (Use and Access) Act 2025; check current ICO guidance for the latest detail.
Key takeaways
- Serious UK GDPR breaches can cost up to £17.5m or 4% of global turnover.
- Put appropriate security in place (encryption, access control, patching), Article 32.
- Train staff: human error causes most breaches.
- Practise data minimisation, hold less, for less time.
- Have a plan to notify the ICO within 72 hours, and document everything.
Sources
- UK GDPR, Articles 32 (security), 33 and 34 (breach notification) and 83 (fines)
- Data Protection Act 2018, section 149 (enforcement notices); Data (Use and Access) Act 2025
- Information Commissioner's Office (ICO) guidance
--- This article is general information about the law of England & Wales as at 2026, not legal advice. For advice on your circumstances, consult a qualified solicitor.