Source methodology

Implemented official source

ICO data security incident trends

One unique source report reference, published by Breach Gazette only as grouped counts

Q2 2019 through the latest reviewed quarterly workbook; Q1 2019 is excluded because the ICO says incidents were recorded differently before Q2 2019.

Regulator
Information Commissioner's Office
Jurisdiction
United Kingdom
Reporting scheme
UK GDPR personal data breach reports to the ICO
Publication level
Anonymized Notification
Coverage type
Complete Anonymized Dataset
Reporting threshold
The source covers personal data breaches reported to the ICO under UK GDPR reporting requirements; it is not a register of every data security incident in the United Kingdom.
Source population
Unique report references in the ICO's downloadable incident-trends workbook from its stated comparable period, excluding source references that cannot be assigned to one reporting quarter.
Licence state
Open Government Licence v3.0. Breach Gazette publishes attributed grouped counts and does not redistribute raw workbook rows or report-level characteristic combinations.
Rights boundary reviewed
24 July 2026
Redistribution decision
Approved With Conditions
Automated health
Healthy
Snapshot completeness
Partial
Update checkpoint
Complete
Reviewed record floor
100
Accepted records
73,848
Rejected records
0
Bounded retrieval limit
100,000
Source revision
ico-workbook:data-security-incidents-trends-q1-2019-to-q4-2025.xlsx:2026-03-11T17:37:09+00:00
Snapshot checksum
4179efdaa3ea4edbe41caef1ad3174f6d2a1454221138c588df5c2d8baaa7fa1
Latest update attempt
24 July 2026
Last successful update
24 July 2026

Limitations

  • The source contains only incidents discovered and reported to the ICO and is not a definitive census of UK breaches.
  • The ICO says some larger or more serious cases may be transferred to another system and absent from this dataset.
  • Categories, incident types, and sectors are source-assigned best-fit classifications, and input practices have changed over time.
  • Q1 2019 is excluded because the ICO identifies Q2 2019 as the start of the comparable series.
  • Reports can have multiple characteristics and appear on multiple workbook rows; Breach Gazette counts unique report references before calculating category memberships.
  • Category-membership totals can exceed unique-report totals because a report can hold multiple source characteristics.
  • Any source reference spanning conflicting reporting quarters is excluded rather than resolved by inference.
  • Raw workbook rows and report-level characteristic combinations are retained neither in durable state nor in the public site.

Correction process

Check the current ICO incident-trends page, workbook, published limitations, and report-reference consistency. Preserve unique-report and category-membership semantics and do not infer an organization or unique real-world incident.

Attribution

Information Commissioner's Office