0800 023 5232 hr@vethr.co.uk

Data Breach in a Veterinary Practice: The First 72 Hours

Last updated: 5 September 2026

TL;DR: A notifiable data breach must be reported to the ICO without undue delay and not later than 72 hours after you become aware of it. You report when the breach is likely to risk people’s rights and freedoms, you tell affected individuals directly where the risk is high, and you must keep an internal record of every breach whether or not it is reported.

What a veterinary practice must do in the first 72 hours after a data breach involving staff or client records.

Table of contents

It usually starts with something small. A rota emailed to the wrong address. A laptop left in a car. A reference request answered with the whole personnel file attached. None of those feel like an incident on the day, and the clock has already started on all three.

What counts as a data breach?

More than a hack. A personal data breach is a security incident affecting the confidentiality, integrity or availability of personal data, which covers accidental disclosure, loss and destruction as well as deliberate attacks.

That third word matters. Losing access to data counts too, so a ransomware incident that locks your practice management system, or a backup that turns out to be empty, is a breach even if nothing left the building.

It applies to staff data as much as client data. Practices tend to think first about client records, but a personnel file, a sickness record or a payroll report is special category or otherwise sensitive information about an identifiable person.

Human error causes most of them. The ICO’s guidance covers the full framework in personal data breaches: a guide, and the practical lesson is that your risk sits in daily habits rather than in your firewall.

What does a data breach look like in a veterinary practice?

Ordinary, and usually caused by someone doing their job in a hurry. Recognising the everyday versions is what turns a policy into something people actually use.

The leaver one is the most common in small practices, and the least noticed. A nurse who left in March and still has access to the rota system and the shared drive in September is a standing risk that nobody has looked at.

Consolidated systems help because permissions can be reviewed in one place, which is part of the argument in our guide to digital staff records.

Card showing the 72 hour reporting deadline running from the moment the practice becomes aware.

When must you report a data breach to the ICO?

When the breach is likely to result in a risk to people’s rights and freedoms. In that case the ICO requires you to report without undue delay and not later than 72 hours after becoming aware of it.

Risk of harm means any potential harm or detriment, including safeguarding issues, identity theft or significant distress. Applied to staff data, disclosing someone’s mental health absence to colleagues is capable of causing exactly that.

The 72 hours runs from awareness, not from the incident. If a rota went to the wrong address on a Friday and you learn on Monday, the clock starts Monday, and it does not pause for weekends.

Where you decide not to report, record the reasoning. The ICO requires a record of any personal data breach regardless of whether you were required to notify, including what happened, the effects and the remedial action taken.

What do you do in the first 72 hours?

Contain, assess, record, then decide on reporting, in that order. The instinct to work out who is to blame comes later, and doing it first costs you the hours you needed.

  1. Contain it. Recall the email, disable the account, lock the device, isolate the system.
  2. Record the time you became aware. Date, time, who reported it, to whom.
  3. Establish the facts. What data, how many people, whose, where it went.
  4. Assess the risk. Severity of the impact and likelihood of it happening.
  5. Decide on notification. ICO if a risk is likely, individuals if the risk is high.
  6. Log it. In the breach record, whether or not you reported.
  7. Fix the cause. Not the person, the process that allowed it.

Do not delay a report because the investigation is incomplete. The ICO expects notification within 72 hours where feasible, and you can provide further detail afterwards rather than waiting until you know everything.

Practise the sequence once. A ten minute tabletop exercise using a realistic scenario, such as a payroll report sent to an external address, tells you within minutes whether anyone knows who to call on a Saturday, which is exactly when these things surface.

Name the person who owns this before you need them. In a practice that is usually the practice manager, with a partner as deputy, and the whole team should know which name to say it to.

Card listing the seven immediate steps to take after discovering a personal data incident.

When do you tell the people affected?

Where the breach is likely to result in a high risk to their rights and freedoms, you must inform them directly and without undue delay. High risk is a higher bar than the one for reporting to the ICO.

Assess both severity and likelihood. A payroll file sent to an external address is severe and probable; an internal email seen by one colleague who deleted it immediately is neither, though it still goes in the record.

Tell people plainly and quickly when you do tell them. What happened, what data, what you have done, what they should watch for, and who to contact. Staff forgive the incident far more readily than the discovery that you knew for a fortnight.

Expect a follow-up request for their file. A data breach frequently produces a subject access request from the person concerned, and being ready for that is part of handling the first event well.

No breach log and no named owner? A free 30-minute HR health check will get both in place. Book your HR health check.

How do you reduce the risk of a data breach?

By fixing the six habits that cause most of them. Practices reach for technology first, and the cheaper wins are almost entirely about process and access.

  1. Review access quarterly. Who can see HR records, and does that still make sense?
  2. Remove leaver access on the last day. Systems, email, shared drives, group chats.
  3. Keep personnel matters off group chats. Shift cover in the group, people matters elsewhere.
  4. Apply a retention schedule. Data you no longer hold cannot be breached.
  5. Encrypt devices and use practice accounts. Not personal email for staff data.
  6. Train on recognition and reporting. Most people do not know an email to the wrong address counts.

Point six changes the numbers most. A practice where staff report near misses catches errors in the hour rather than in the month, and near miss reporting is a habit our See It Report It system is designed to build.

Watch personal devices in particular. Staff photograph rotas, forward records to personal email to work at home and keep client details in their own phones, all with good intentions, and each of those habits puts practice data somewhere you cannot reach it after they leave.

Build the offboarding step into your leaver checklist so access removal is not a memory task. Our guide to GDPR and staff records covers the wider retention and security picture.

Frequently asked questions about a data breach

How long do we have to report a data breach?

Where the breach is notifiable, the ICO requires a report without undue delay and not later than 72 hours after you become aware of it. The clock starts from awareness rather than from the incident, and it does not stop for weekends or bank holidays.

Does every breach have to be reported?

No. You report where the breach is likely to result in a risk to people’s rights and freedoms. You must, however, keep a record of every personal data breach regardless of whether it was reportable, including what happened, the effects and the remedial action taken.

Is an email sent to the wrong person a breach?

Yes, if it contained personal data. Whether it is reportable depends on the risk: a rota with home addresses sent externally is very different from an internal message seen by one colleague. Assess it, record it, and report if a risk to people is likely.

What if we are not certain of the facts yet?

Report anyway if a risk is likely. The ICO expects notification within 72 hours where feasible and accepts that information can follow in phases. Waiting until the investigation is complete is the most common way practices miss the deadline.

Do staff data breaches count as much as client ones?

Yes. The obligations attach to personal data about identifiable people, and employee records often contain health information, bank details and home addresses. In practice, staff data incidents are frequently more sensitive than the client records people worry about.

The practice view

The practices that handle a data breach well are not the ones with the best software. They are the ones where somebody knew immediately who to tell, the time of awareness got written down, and the containment happened before the blame conversation.

Name an owner, keep a breach log, review access quarterly and remove leaver access on the last day. Our policy library and HR consultancy cover the people side of all of it, and the free HR health check is where to start.

The Vet HR Team provides HR consultancy and white-labelled staff systems exclusively to UK veterinary practices. Check current ICO guidance, and take specialist advice on a serious incident.