Skip to main content

Regulatory Deadline Tracking

ICO 72-hour window, FCA reporting, and other regulatory notifications.

UK organisations face strict regulatory notification deadlines when a data breach or cyber incident occurs. CrownSync Playbooks tracks these deadlines automatically based on your incident detection time and regulatory flags, ensuring you never miss a critical notification window.

RegulatorDeadlineApplies To
ICO72 hours from discoveryAll organisations processing personal data
FCAImmediately / within 1 business dayFCA-regulated firms
PRAAs soon as practicablePRA-regulated firms
NIS72 hoursOperators of essential services
DSPTWithin 72 hoursNHS and social care organisations
SRAAs soon as reasonably practicableSRA-regulated law firms
Regulatory deadline tracking panel showing ICO 72-hour countdown
The platform automatically tracks regulatory notification deadlines.

Strict deadlines with serious consequences

Missing a regulatory notification deadline can result in significant fines, enforcement action, and reputational damage. The ICO has the power to fine organisations up to 4% of annual global turnover or 17.5 million pounds (whichever is greater) for serious breaches of UK GDPR, and failure to notify within 72 hours is treated as an aggravating factor.

ICO — 72-Hour Notification Window

Under Article 33 of UK GDPR, if a personal data breach is likely to result in a risk to individuals' rights and freedoms, you must notify the Information Commissioner's Office within 72 hours of becoming aware of the breach. Key points:

  • The 72-hour clock starts from the moment your organisation becomes aware of the breach, not from when the breach occurred or when the incident was declared in CrownSync.
  • “Awareness” means when you have a reasonable degree of certainty that a breach has occurred, not when the investigation is complete.
  • If you cannot provide full details within 72 hours, you may notify in phases — submit what you know and provide supplementary information later.
  • Not all breaches require notification. If the breach is unlikely to result in a risk to individuals, you should still document it internally but are not obliged to notify the ICO.

CrownSync displays a countdown timer on the incident dashboard showing the remaining time in the 72-hour window. Warning notifications are sent at 48 hours, 24 hours, and 4 hours remaining.

FCA Notification Requirements

If your organisation is regulated by the Financial Conduct Authority, additional notification obligations apply. FCA-regulated firms must:

  • Report material cyber incidents to the FCA as soon as possible and no later than within the timeframe specified in your regulatory obligations
  • Submit reports through the FCA's notification process, separate from any ICO notification
  • Provide details including the nature of the incident, systems affected, customer impact, and remediation steps

When the FCA regulatory flag is enabled on your organisation profile, CrownSync displays a separate deadline tracker for FCA notification alongside the ICO tracker.

Other Regulatory Bodies

Depending on your sector and regulatory flags, additional notification requirements may apply:

  • PRA — Prudential Regulation Authority for dual-regulated financial firms
  • DSPT — NHS Data Security and Protection Toolkit for health and social care organisations
  • SRA — Solicitors Regulation Authority for law firms
  • Ofcom — For telecommunications providers under NIS regulations

CrownSync tracks each applicable deadline independently, so you can see at a glance which notifications are pending, in progress, or completed.

Marking Notifications as Sent

Once you have submitted a notification to a regulator, record this in CrownSync by clicking Mark as Notified on the relevant deadline tracker. You will be prompted to provide:

  • The date and time the notification was submitted
  • The method of notification (online portal, email, telephone)
  • A reference number if one was provided by the regulator
  • Any notes about what was included in the notification

This information is recorded in the incident timeline and the audit log, providing a complete record that you met your notification obligations.

Reference Numbers

When a regulator acknowledges your notification, they typically provide a reference number. Store this in the incident record by editing the notification entry. The reference number is included in any subsequent incident reports and is useful for tracking ongoing correspondence with the regulator.

Deadline Warning Notifications

CrownSync sends automated notifications as regulatory deadlines approach:

  • 48 hours remaining — Initial warning to the incident lead and organisation admins
  • 24 hours remaining — Escalation warning to all team members with incident access
  • 4 hours remaining — Critical alert with prominent in-app banner
  • Deadline passed — Overdue alert (if notification has not been marked as sent)

These warnings cannot be disabled, as they serve a critical compliance function. Both in-app and email notifications are sent for all deadline warnings.

Was this page helpful?