Skip to content
Law Society of Scotland
Search
Find a Solicitor
Contact us
About us
Sign in
Search
Find a Solicitor
Contact us
About us
Sign in
  • For members

    • For members

    • CPD & Training

    • Membership and fees

    • Rules and guidance

    • Regulation and compliance

    • Journal

    • Business support

    • Career growth

    • Member benefits

    • Professional support

    • Lawscot Wellbeing

    • Lawscot Sustainability

  • News and events

    • News and events

    • Law Society news

    • Blogs & opinions

    • CPD & Training

    • Events

  • Qualifying and education

    • Qualifying and education

    • Qualifying as a Scottish solicitor

    • Career support and advice

    • Our work with schools

    • Lawscot Foundation

    • Funding your education

    • Social mobility

  • Research and policy

    • Research and policy

    • Research

    • Influencing the law and policy

    • Equality and diversity

    • Our international work

    • Legal Services Review

    • Meet the Policy team

  • For the public

    • For the public

    • What solicitors can do for you

    • Making a complaint

    • Client protection

    • Find a Solicitor

    • Frequently asked questions

    • Your Scottish solicitor

  • About us

    • About us

    • Contact us

    • Who we are

    • Our strategy, reports and plans

    • Help and advice

    • Our standards

    • Work with us

    • Our logo and branding

    • Equality and diversity

  1. Home
  2. For members
  3. Business support
  4. Technology
  5. Cybersecurity guide
  6. Notification requirements and incident response

Notification requirements and incident response

Notification requirements

GDPR introduces a duty on all organisations to notify the relevant supervisory authority about certain types of personal data breach. Where a cybersecurity breach is likely to result in a risk of adversely affecting individuals’ rights and freedoms, GDPR requires that the data controller notifies the Information Commissioner’s Office without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach. Where there is high risk to individuals, you must also inform the affected individuals without undue delay. This is not required if appropriate technical and organisational protection measures have been applied to the personal data, such as encryption and, possibly, pseudonymisation. You will also have to notify the police when it is suspected that the breach has arisen from a criminal act. An organisation is considered to be aware when it has a reasonable degree of certainty that a security incident has occurred and that this has led to personal data being compromised. For more information, see the Law Society’s Guide to GDPR: www.lawscot.org.uk/gdpr

 

The General Data Protection Regulation (GDPR) and the Data Protection Act 2018

Under GDPR and the Data Protection Act 2018, businesses and their staff are responsible for the security, compliance and governance of their data. GDPR is based around six privacy principles together with the accountability principle. In addition to these principles, individuals have specific rights in relation to their personal information placing certain obligations on organisations that are responsible for processing it. An overview of these principles is available on the Information Commissioner’s Office website:
www.ico.org.uk

Add To Favorites

Additional

  • Cybersecurity guide

In this section

  • Notification requirements and incident response
  • The General Data Protection Regulation (GDPR) and the Data Protection Act 2018

Mitigo

Our cyber security partner

Find out more about Mitigo
Law Society of Scotland
Atria One, 144 Morrison Street
Edinburgh
EH3 8EX
If you’re looking for a solicitor, visit FindaSolicitor.scot
T: +44(0) 131 226 7411
E: lawscot@lawscot.org.uk
About us
  • Contact us
  • Who we are
  • Strategy reports plans
  • Help and advice
  • Our standards
  • Work with us
Useful links
  • Find a Solicitor
  • Sign in
  • CPD & Training
  • Rules and guidance
  • Website terms and conditions
Law Society of Scotland | © 2025
Made by Gecko Agency Limited