Law / United Kingdom

UK GDPR Articles 33-34 and PECR, Breach Notification in the United Kingdom

UK GDPR, Arts. 33-34; Privacy and Electronic Communications Regulations (PECR), as amended by the Data (Use and Access) Act 2025

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 25 May 2018.

A breach notification rule binding public and private bodies.

As of 24 August 2026.

What it requires

  • Notify the ICO without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in the United Kingdom, unless the breach is unlikely to risk their rights and freedoms.
  • Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms, and if you are a telecoms or ISP-type provider, notify a PECR breach to the ICO within 72 hours.

If you get it wrong

Criminal exposureNo

Private right of actionYes

Penalty structure

UK GDPR Arts. 33-34 fall within "the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39 and 42 and 43" in Art. 83(4)(a), which sets the standard maximum amount: the higher of £8,700,000 or 2% of worldwide annual turnover (DPA 2018 s.157(6)). The Data (Use and Access) Act 2025 Sch. 13 (amending DPA 2018 s.157(2) as applied to the PEC Regulations) replaced PECR's former flat £500,000 maximum with this same higher/standard maximum framework, but only for the PECR provisions Sch. 13 para. 18 enumerates (regs. 5, 6, 7, 8, 14, 19, 20, 21, 21A, 21B, 22, 23 and 24, chiefly the marketing and cookie-consent rules; verified at https://www.legislation.gov.uk/ukpga/2025/18/schedule/13). PECR's own personal-data-breach notification duty (reg. 5A) is not in that enumerated list and keeps a separate, much smaller fixed monetary penalty of £1,000 per failure (£800 if paid within 21 days of the notice of intent) under reg. 5C, unaffected by the DUAA realignment (https://www.legislation.gov.uk/uksi/2003/2426/regulation/5C).

Rule
Higher of
As of
2 September 2026
Currency
GBP
Fixed cap
8,700,000
Turnover percentage cap
2

Who enforces it

Enforcement body

Information Commissioner's Office (ICO), the UK's single supervisory authority for data protection and PECR, exercising the Article 57 tasks and Article 58 powers conferred on the Commissioner by Data Protection Act 2018 s.115.

Enforcement record

Hand count from the ICO's own enforcement action register (Type facet Monetary penalties plus Enforcement notices), read across the register's first two pages (50 of 222 total listed actions of every type), which cover 7 August 2026 back to 24 April 2025, past the twelve-month cutoff. In the twelve months ending 7 August 2026 (the register's most recent entry), the ICO published 18 monetary penalty notices and 14 enforcement notices, for a combined actions_per_year of 32. Reprimands and prosecutions are excluded. Where the register lists a monetary penalty notice and an enforcement notice against the same underlying matter as two separate rows (for example Elderly Aids Limited, 6 August 2026), each row counts once as its own published enforcement instrument. fines_per_year is omitted: several monetary penalty rows in the register's list view state no penalty figure in the summary text shown there (only the full decision notice states it), so a sum from the visible list would understate the true total. This is the ICO's enforcement record for the data protection and PECR regime generally, not a record specific to this instrument's own provisions.

As of
2 September 2026
Source link
https://ico.org.uk/action-weve-taken/enforcement/
Actions per year
32

What it reaches

Obligation class

Breach notice

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

UK GDPR Articles 33 and 34 retain the same 72-hour and without-undue-delay structure as EU GDPR, with no threshold for how serious a breach must be before it is notifiable. The DUA Act shortened the separate PECR breach-notification window for telecoms and ISP-type breaches from 24 hours to 72 hours, in force 20 August 2025, aligning it with the UK GDPR timeline, and raised the maximum PECR fine to GBP 17.5 million or 4 percent global turnover, up from GBP 500,000.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

Read the law

legislation.gov.uk, official consolidated text

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app