TL;DR:
- A stolen laptop containing personal data is a notifiable data breach under UK GDPR — you have 72 hours from discovering the theft to report it to the ICO if the breach is likely to cause risk to individuals
- If the laptop’s drive is fully encrypted and the encryption key wasn’t stolen with it, you are very likely exempt from the reporting obligation — full-disk encryption is the single most important protection
- Many small businesses don’t realise their obligation until after the window has passed; the key is having a simple decision-making procedure that anyone can follow when a device goes missing
Device theft is one of the most common data breaches reported to the ICO. It’s also one of the most easily preventable from a GDPR consequence perspective. The difference between a breach that triggers mandatory reporting and notification obligations and one that doesn’t comes down almost entirely to whether the device was encrypted — a question you need to have answered before any device goes missing, not after.
Is This a Reportable Breach?
Not every stolen device triggers a mandatory ICO report. UK GDPR (Article 33) requires you to notify the ICO when a personal data breach is “likely to result in a risk to the rights and freedoms of natural persons.” The assessment you need to make:
What personal data was on the device?
Personal data includes anything that identifies or could identify a living person: names, email addresses, phone numbers, customer records, employee records, health information, financial data, contract details. If the device was used for work and wasn’t fully wiped between uses, there’s almost certainly some personal data on it.
Could an unauthorised person access it?
This is the encryption question. If the device has full-disk encryption enabled (BitLocker on Windows, FileVault on Mac) and the attacker doesn’t have the decryption key or the device’s login credentials, the data is effectively inaccessible. The ICO’s guidance explicitly recognises that encryption can render a breach non-reportable.
What’s the risk to individuals?
Customer financial data or health records stolen from an unencrypted device: high risk. A staff contact list from an encrypted device where the thief can’t access the data: no risk.
The most common scenario in small business device theft — an unencrypted laptop with customer records or employee data — is a reportable breach.
The 72-Hour Clock
The clock starts when you become aware of the breach, not when it happened. “Aware” means you have reasonable certainty that a breach has occurred — not when you’ve fully investigated it.
A stolen laptop is immediately a known incident. You don’t have 72 hours from when you finish your investigation; you have 72 hours from when you discover the device is missing.
To report to the ICO, use the self-service reporting tool at ico.org.uk/report. You’ll need to provide:
- Nature of the breach (theft/loss)
- Categories and approximate number of data subjects affected
- Categories and approximate number of personal data records affected
- Name and contact details of your Data Protection Officer or contact point
- Description of the likely consequences
- Measures taken or proposed to address the breach
You do not need to have all the answers before reporting. The ICO explicitly allows for phased reporting — you can submit an initial notification within 72 hours with the information you have, then provide additional detail as your investigation continues.
Missing the 72-hour window is not automatically an enforcement matter, but it becomes a factor in how the ICO assesses your response. Reporting late with an explanation is significantly better than not reporting at all.
Do You Also Need to Tell Individuals?
Separate from the ICO report, UK GDPR (Article 34) requires you to notify the affected individuals “without undue delay” when the breach is likely to result in a high risk to them.
This threshold is higher than the ICO reporting threshold. You notify the ICO when there’s a risk; you notify individuals when there’s a high risk. For a stolen laptop with customer financial data or health records, this threshold is probably met. For a stolen laptop with basic contact information (names, email addresses), it depends on context.
When you do need to notify individuals, the communication should:
- Explain clearly what happened in plain language
- Describe the nature of the data involved
- Give the name and contact details of someone they can ask questions
- Describe the likely consequences
- Explain what steps you’re taking
Don’t use legalistic language. A short, direct email from the business owner explaining what was stolen and what you’re doing is better than a lengthy legal notice.
How Encryption Changes Everything
Full-disk encryption means the data on the device is unreadable without the decryption credentials. If a thief steals an encrypted laptop and cannot access the account — because they don’t have the login credentials, or because the device requires a BitLocker PIN they don’t know — the personal data on the device is not compromised.
In this scenario:
- The breach occurred (the device was stolen)
- But no personal data was actually exposed to an unauthorised person
- The breach is very unlikely to cause risk to individuals
- ICO reporting is not required
This is why enabling full-disk encryption on all devices that handle personal data is the single most important GDPR control for device theft. It turns a potentially serious notifiable breach into a non-event from a compliance perspective.
Enabling encryption on common platforms:
- Windows: BitLocker is built into Windows Pro and Enterprise. Search “Manage BitLocker” in the Start menu. Enable it for the system drive and save the recovery key to your Microsoft account or print it and store it securely.
- Mac: FileVault is built into macOS. System Settings → Privacy & Security → FileVault → Turn On. Save the recovery key.
- Mobile (Android/iOS): Both encrypt by default when a PIN or password is set. Ensure all work phones and tablets require a PIN.
Check whether encryption is actually enabled on your current devices. Many business laptops have BitLocker available but not turned on because it wasn’t configured during setup.
What to Do When a Device Is Reported Missing
Have a procedure before you need it. When a staff member reports a missing device, the immediate steps:
- Confirm the device is missing — is it definitely stolen/lost, or just temporarily misplaced?
- Check encryption status — was this device encrypted? You should know this from your device inventory; if you don’t know, assume it wasn’t.
- Identify what was on it — what accounts were logged in? What files were synced locally? What personal data could have been accessible?
- Remote wipe if possible — Microsoft Intune, Apple Business Manager, and Google Workspace all support remote device wipe. Do this immediately and document when you did it.
- Change passwords — for any accounts that were logged in on the device, change the password and revoke active sessions.
- Make the ICO decision — based on encryption status and data content, decide whether this is reportable. If in doubt, report.
- Report to the ICO within 72 hours if required.
- Assess individual notification — is the risk high enough to require telling affected customers or staff?
- Document everything — the ICO expects you to maintain records of all data breaches, including ones you decided didn’t require reporting.
Your Record-Keeping Obligation
Even if the breach doesn’t require reporting to the ICO, UK GDPR requires you to maintain a record of it internally. Keep a breach log — a spreadsheet is fine — with: date discovered, nature of incident, what data was involved, decision made (report or not report and why), and any steps taken.
This record has no format requirement. Its purpose is to demonstrate to the ICO, if they ever ask, that you have a functional data breach response process. Businesses that have a log — even one that shows minor incidents handled correctly — are in a far better position than those with no records at all.
Getting Ahead of It
The businesses that handle device theft well share one characteristic: they set this up before it happened.
- Device inventory with encryption status recorded for each device
- Remote wipe capability configured and tested (not assumed to work)
- A written one-page procedure for what to do when a device goes missing, accessible to all staff
- At least two people who know how to make the ICO decision and submit the report
Device theft is predictable. Unlike a sophisticated cyberattack, the response to a stolen laptop is something you can script entirely in advance. An hour spent setting up encryption across your device fleet and writing a simple procedure is insurance against a 72-hour compliance scramble at the worst possible time.