You detect an intrusion. Files containing personal data have been accessed. You don't yet know how the attacker got in, how much data they touched, or whether anything was copied out.
That uncertainty doesn't pause the clock. Under UK GDPR, the 72-hour notification deadline starts the moment you become aware of the breach - not once you've confirmed it, not once you understand its scope, and not once you've fixed it.
If your crisis response plan assumes an investigation phase before the clock starts, it's built on a misreading of the rule, and that gap tends to surface at the worst possible moment.
The ICO's own guidance is more forgiving than most organisations assume — but only if you know how to use that flexibility.
Article 33(4) of the UK GDPR explicitly recognises that you won't always be able to fully investigate a breach within 72 hours. It allows you to notify in phases, as long as any further information is provided without undue delay. What it does not allow is silence. You still have to notify within 72 hours of becoming aware, even with an incomplete picture, and follow up as the investigation develops.
The ICO's own example makes the shape of this clear: you detect an intrusion, you know personal data was accessed, but you don't yet know the entry point, the extent of access, or whether data was exfiltrated. You notify within 72 hours, explain what you don't yet know, and tell the ICO when you expect to have more. Once the investigation produces answers, you send them on — without further delay.
That's a materially different task than "write and submit a complete breach report." It's "assemble and send a partial, honest, well-evidenced first submission, fast, while an investigation continues in parallel." Most crisis plans are built for the former. Almost none are built for the latter.
Even a phased or partial notification needs to address four things:
Notice what's on that list: contact details for a specific person, and a description of measures either taken or proposed. Both of those are things you can prepare before you're ever in this situation. Neither should depend on whoever happens to be reachable at 2am on the day it happens.
In practice, organisations rarely blow the 72-hour window because the legal drafting is hard. They blow it - or scrape in late and under-prepared - because of coordination failures that have nothing to do with the law:
None of these are legal problems. They're communication and coordination problems that happen to have a legal deadline attached.
A compressed but realistic timeline:
Every deadline in that timeline is hit before the investigation is finished. That's the point.
"Undue delay" is judged against what you could reasonably have done - not against what your systems allowed you to do on the day. A crisis plan that only works when your normal tools are working isn't a crisis plan.
If the 72-hour clock is going to survive contact with an actual incident, it needs a communication path that survives it too.
A scope note: this article covers UK GDPR and ICO notification requirements specifically. Organisations that also process EU personal data should note that EU GDPR carries the same 72-hour standard, but notification goes to the relevant EU supervisory authority rather than the ICO.