A personal data breach must be notified to the Isle of Man Information Commissioner without undue delay and, where feasible, within 72 hours of the controller becoming aware of it — unless the breach is unlikely to result in a risk to individuals' rights and freedoms. Where the risk is high, the affected individuals must also be told directly. Both duties sit in the Applied GDPR, the Island's own instrument, not the UK GDPR and not an EU regulation.
That 72-hour figure is the part everyone remembers and the part that causes the most trouble in practice, because the clock starts at awareness, not at confirmation, and because notifying the Commissioner and notifying individuals are two separate decisions with two separate thresholds. Firms that conflate them either over-report every minor incident to the Commissioner or under-report the ones that genuinely warrant telling customers. This post sets out what counts as a breach, how the two notification duties actually work, and where we see firms get the assessment wrong.
What actually counts as a personal data breach?
The Isle of Man Information Commissioner defines a personal data breach as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. That definition is wider than the mental image most people have of "a hack." The Commissioner's own examples cover unauthorised access to a system, sending data to the wrong recipient, a lost or stolen device, an unauthorised alteration of a record, and data made unavailable — for instance through ransomware encryption, where the data has not been stolen but a firm can no longer access or restore it.
The unifying thread is loss of confidentiality, integrity, or availability of personal data, not just theft of it. An email sent to the wrong client, a laptop left on a train, a database record altered without authority, and a ransomware lock-out are all, in principle, the same category of event under this definition. That breadth is deliberate: it forces firms to build one incident-response process that catches all four, rather than a narrow one tuned only to "cyber-attacks."

Does every IT incident have to be reported?
No — and this is the point most likely to trip up a busy IT or compliance team. The test is not "did something go wrong technically," it is documented risk to individuals' rights and freedoms. A lost laptop that was fully encrypted, with no working key exposed, may well not clear the bar for notifying the Commissioner at all. The same laptop unencrypted almost certainly does. Either way, the assessment itself has to be made and recorded: deciding "this is not reportable" without writing down why is, on its own, a gap the Commissioner can find later even if the underlying incident genuinely was harmless.
That distinction — assess versus assume — is where the risk sits for most firms, more than the incidents themselves. A ransomware event that encrypts a database is a breach under the Commissioner's definition the moment availability is lost, regardless of whether any data actually left the building. Firms that only think about breach notification in terms of exfiltrated records miss that an outage-only incident can trigger exactly the same 72-hour clock.
When must the Commissioner be notified, and by when?
Where a breach is not unlikely to result in a risk to individuals — in other words, where any real risk exists — the controller must notify the Isle of Man Information Commissioner without undue delay and, where feasible, within 72 hours of becoming aware of it. This obligation is set out in Article 33 of the Applied GDPR, with further explanation in Recitals 85-88. Notification is not required only where the breach is unlikely to result in a risk to the rights and freedoms of an individual — a genuinely low bar to clear, which is why the default assumption should be to assess formally rather than to reason your way out of reporting.
Two things follow from that wording. First, the clock runs from awareness, not from the point you finish investigating — 72 hours is not "72 hours after we understand what happened," it is 72 hours after you knew something had happened, with the option to supplement the notification as the investigation develops. Second, the decision not to notify is not a shrug; it is a risk assessment that has to be objective, reasoned, and kept on file. If the Commissioner later asks why a breach was not reported, "we didn't think it was serious" is not a defensible answer without the paperwork behind it. This is exactly the same discipline we describe in our post on the Data Protection Impact Assessment: a DPIA that correctly flagged high residual risk for a piece of processing is precisely the kind of processing where a later breach in that system is also likely to be high-risk, and to need individual notification, not just a note to the Commissioner.
We help firms build a breach-assessment process that produces a defensible record within the 72-hour window, whichever way the decision lands.
When must individuals be told, separately from the Commissioner?
This is the second, higher threshold, and it is where we see the most confusion. Under Article 34 of the Applied GDPR, where a breach is likely to result in a high risk to the rights and freedoms of affected individuals, the controller must also inform those individuals directly, without undue delay. High risk is a stronger test than the "not unlikely to result in a risk" threshold that triggers Commissioner notification — so a breach can clear the bar for telling the Commissioner while never reaching the bar for telling the people affected. Treating the two obligations as one and the same, and either notifying customers every time the Commissioner is told or never notifying customers at all, both misread the structure of the rule.
Getting this distinction right matters for firms handling special-category data, financial information, or records covered by an existing high-risk DPIA — where the same population is likely to sit closer to the individual-notification threshold if a breach ever occurs. It also matters for how a firm's data-subject rights processes interact with breach response: an individual whose data was affected in a high-risk breach may separately exercise rights under the framework covered in our Subject Access Requests post, and a firm's breach and SAR processes should be able to talk to each other rather than sitting in separate silos.

What is the actual cost of getting notification wrong?
Failing to meet these notification obligations can result in penalties of up to £1,000,000 under Isle of Man law. That figure applies to the failure to notify itself, independent of whatever penalty might separately follow from the underlying security failing that caused the breach. In other words, a firm can be fined for the breach and fined again, or fined instead, for how — or whether — it told the Commissioner and its data subjects about it. In our experience, the process failure is often the more avoidable one: firms that have never rehearsed a breach-notification decision under time pressure tend to spend the first 48 hours of the 72 arguing internally about whether the incident counts, rather than assessing it and recording the outcome.
Common mistakes we see

The most frequent error is starting the clock late — treating "72 hours" as beginning once IT has fully diagnosed the incident, rather than from the moment someone in the firm first became aware something had happened. A close second is assuming ransomware and similar availability incidents fall outside breach notification because no data was copied or stolen; under the Commissioner's definition, data made unavailable is squarely within scope. We also regularly see firms decide informally that an incident is "not reportable" with no written risk assessment behind that call, and firms that notify the Commissioner and then assume individual notification automatically follows, or automatically does not — when the two are governed by different thresholds and need separate, documented decisions.
We review breach logs and near-miss decisions against the Commissioner's expectations, including the ones a firm decided not to report.
If your incident-response plan has never been tested against a real deadline, the 72-hour window is the wrong moment to discover the gaps in it — and the broader framework it sits inside is covered in our pillar guide to GDPR compliance for Isle of Man firms.
Frequently asked questions
What counts as a personal data breach on the Isle of Man?
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data — as defined in the Isle of Man Information Commissioner's guidance. This covers unauthorised access, data sent to the wrong recipient, a lost or stolen device, an unauthorised alteration, and data made unavailable, for example through ransomware encryption, even where nothing has been copied or stolen.
How quickly must a breach be reported to the Commissioner?
Without undue delay and, where feasible, within 72 hours of the controller becoming aware of it, under Article 33 of the Applied GDPR. Notification is not required if the breach is unlikely to result in a risk to individuals' rights and freedoms — but that decision must be assessed objectively and documented, not assumed.
Is every IT incident a reportable breach?
No. The test is documented risk to individuals' rights and freedoms, not whether something technically went wrong. A fully encrypted device that is lost may not need to be reported; the same device unencrypted almost certainly does. Either way, the risk assessment itself must be carried out and recorded — an undocumented decision not to report is itself a gap.
When must individuals be told directly, rather than just the Commissioner?
Where the breach is likely to result in a high risk to the rights and freedoms of the affected individuals, under Article 34 of the Applied GDPR, the controller must inform them without undue delay. That is a higher threshold than the one for notifying the Commissioner, so a breach can require Commissioner notification without ever requiring individual notification — the two decisions have to be made and evidenced separately.
The 72 hours belongs to the clock; the judgement about risk, and the record proving you made it, belongs to you.
