UK GDPR Articles 33-34 and PECR, Breach Notification in the United Kingdom
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 25 May 2018.
A breach notification rule binding public and private bodies.
As of 24 August 2026.
What it requires
- Notify the ICO without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in the United Kingdom, unless the breach is unlikely to risk their rights and freedoms.
- Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms, and if you are a telecoms or ISP-type provider, notify a PECR breach to the ICO within 72 hours.
If you get it wrong
Criminal exposureNo
Private right of actionYes
Penalty structure
UK GDPR Arts. 33-34 fall within "the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39 and 42 and 43" in Art. 83(4)(a), which sets the standard maximum amount: the higher of £8,700,000 or 2% of worldwide annual turnover (DPA 2018 s.157(6)). The Data (Use and Access) Act 2025 Sch. 13 (amending DPA 2018 s.157(2) as applied to the PEC Regulations) replaced PECR's former flat £500,000 maximum with this same higher/standard maximum framework, but only for the PECR provisions Sch. 13 para. 18 enumerates (regs. 5, 6, 7, 8, 14, 19, 20, 21, 21A, 21B, 22, 23 and 24, chiefly the marketing and cookie-consent rules; verified at https://www.legislation.gov.uk/ukpga/2025/18/schedule/13). PECR's own personal-data-breach notification duty (reg. 5A) is not in that enumerated list and keeps a separate, much smaller fixed monetary penalty of £1,000 per failure (£800 if paid within 21 days of the notice of intent) under reg. 5C, unaffected by the DUAA realignment (https://www.legislation.gov.uk/uksi/2003/2426/regulation/5C).
- Rule
- Higher of
- As of
- 2 September 2026
- Currency
- GBP
- Fixed cap
- 8,700,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
Information Commissioner's Office (ICO), the UK's single supervisory authority for data protection and PECR, exercising the Article 57 tasks and Article 58 powers conferred on the Commissioner by Data Protection Act 2018 s.115.
Enforcement record
Hand count from the ICO's own enforcement action register (Type facet Monetary penalties plus Enforcement notices), read across the register's first two pages (50 of 222 total listed actions of every type), which cover 7 August 2026 back to 24 April 2025, past the twelve-month cutoff. In the twelve months ending 7 August 2026 (the register's most recent entry), the ICO published 18 monetary penalty notices and 14 enforcement notices, for a combined actions_per_year of 32. Reprimands and prosecutions are excluded. Where the register lists a monetary penalty notice and an enforcement notice against the same underlying matter as two separate rows (for example Elderly Aids Limited, 6 August 2026), each row counts once as its own published enforcement instrument. fines_per_year is omitted: several monetary penalty rows in the register's list view state no penalty figure in the summary text shown there (only the full decision notice states it), so a sum from the visible list would understate the true total. This is the ICO's enforcement record for the data protection and PECR regime generally, not a record specific to this instrument's own provisions.
- As of
- 2 September 2026
- Source link
- https://ico.org.uk/action-weve-taken/enforcement/
- Actions per year
- 32
What it reaches
Obligation class
Breach notice
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
UK GDPR Articles 33 and 34 retain the same 72-hour and without-undue-delay structure as EU GDPR, with no threshold for how serious a breach must be before it is notifiable. The DUA Act shortened the separate PECR breach-notification window for telecoms and ISP-type breaches from 24 hours to 72 hours, in force 20 August 2025, aligning it with the UK GDPR timeline, and raised the maximum PECR fine to GBP 17.5 million or 4 percent global turnover, up from GBP 500,000.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
Read the law
legislation.gov.uk, official consolidated text
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.