Regulatory Deadline Tracking
ICO 72-hour window, FCA reporting, and other regulatory notifications.
UK organisations face strict regulatory notification deadlines when a data breach or cyber incident occurs. CrownSync Playbooks tracks these deadlines automatically based on your incident detection time and regulatory flags, ensuring you never miss a critical notification window.
| Regulator | Deadline | Applies To |
|---|---|---|
| ICO | 72 hours from discovery | All organisations processing personal data |
| FCA | Immediately / within 1 business day | FCA-regulated firms |
| PRA | As soon as practicable | PRA-regulated firms |
| NIS | 72 hours | Operators of essential services |
| DSPT | Within 72 hours | NHS and social care organisations |
| SRA | As soon as reasonably practicable | SRA-regulated law firms |

Strict deadlines with serious consequences
Missing a regulatory notification deadline can result in significant fines, enforcement action, and reputational damage. The ICO has the power to fine organisations up to 4% of annual global turnover or 17.5 million pounds (whichever is greater) for serious breaches of UK GDPR, and failure to notify within 72 hours is treated as an aggravating factor.
ICO — 72-Hour Notification Window
Under Article 33 of UK GDPR, if a personal data breach is likely to result in a risk to individuals' rights and freedoms, you must notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. Key points:
- The 72-hour clock starts from the moment your organisation becomes aware of the breach, not from when the breach occurred or when the incident was declared in CrownSync.
- “Awareness” means when you have a reasonable degree of certainty that a breach has occurred, not when the investigation is complete.
- If you cannot provide full details within 72 hours, you may notify in phases — submit what you know and provide supplementary information later.
- Not all breaches require notification. If the breach is unlikely to result in a risk to individuals, you should still document it internally but are not obliged to notify the ICO.
CrownSync displays a countdown timer on the incident dashboard showing the remaining time in the 72-hour window. Warning notifications are sent at 48 hours, 24 hours, and 4 hours remaining.
FCA Notification Requirements
If your organisation is regulated by the Financial Conduct Authority, additional notification obligations apply. FCA-regulated firms must:
- Report material cyber incidents to the FCA as soon as possible and no later than within the timeframe specified in your regulatory obligations
- Submit reports through the FCA's notification process, separate from any ICO notification
- Provide details including the nature of the incident, systems affected, customer impact, and remediation steps
When the FCA regulatory flag is enabled on your organisation profile, CrownSync displays a separate deadline tracker for FCA notification alongside the ICO tracker.
Other Regulatory Bodies
Depending on your sector and regulatory flags, additional notification requirements may apply:
- PRA — Prudential Regulation Authority for dual-regulated financial firms
- DSPT — NHS Data Security and Protection Toolkit for health and social care organisations
- SRA — Solicitors Regulation Authority for law firms
- Ofcom — For telecommunications providers under NIS regulations
CrownSync tracks each applicable deadline independently, so you can see at a glance which notifications are pending, in progress, or completed.
Marking Notifications as Sent
Once you have submitted a notification to a regulator, record this in CrownSync by clicking Mark as Notified on the relevant deadline tracker. You will be prompted to provide:
- The date and time the notification was submitted
- The method of notification (online portal, email, telephone)
- A reference number if one was provided by the regulator
- Any notes about what was included in the notification
This information is recorded in the incident timeline and the audit log, providing a complete record that you met your notification obligations.
Reference Numbers
When a regulator acknowledges your notification, they typically provide a reference number. Store this in the incident record by editing the notification entry. The reference number is included in any subsequent incident reports and is useful for tracking ongoing correspondence with the regulator.
Deadline Warning Notifications
CrownSync sends automated notifications as regulatory deadlines approach:
- 48 hours remaining — Initial warning to the incident lead and organisation admins
- 24 hours remaining — Escalation warning to all team members with incident access
- 4 hours remaining — Critical alert with prominent in-app banner
- Deadline passed — Overdue alert (if notification has not been marked as sent)
These warnings cannot be disabled, as they serve a critical compliance function. Both in-app and email notifications are sent for all deadline warnings.
Was this page helpful?