For some time, the Information Commissioner’s Office has advised organisations of all shapes and sizes to indulge in the masochistic activity of ‘breach notification’. Though taken to absurd levels of hair-shirtery in the NHS and some councils, the belief that any attention-grabbing data-related cock-up must automatically be reported to the ICO is widely held. I offer a modest prize for anyone can find me the interview in which Christopher Graham – earlier in his tenure – mistakenly claimed that breach notification was mandatory. I sometimes cause a frisson in training sessions when I quietly suggest that there is no such obligation, and on one memorable occasion, I was even shouted at by an angry Data Protection Officer who had just told his employer that they were obliged to report. My advice, gentle reader, is that if you think that reporting an incident to the ICO will improve your compliance with…

