On Monday morning an adviser at Ashgrove Advice realises he left an unencrypted laptop on a train on Saturday evening. It holds 300 clients' fact-finds, including health details. Which response meets UK GDPR?
UK GDPR Art 33 requires notification to the regulator without undue delay and, where feasible, within 72 hours of becoming aware of a breach likely to result in a risk to individuals. Art 34 requires the firm to tell affected individuals without undue delay where the risk is high, as it is with unencrypted health data. The regulator has been the Information Commission since 30 September 2026, still known as the ICO. Keeping clients in the dark breaches Art 34, and an FCA notice under SUP 15 does not replace Art 33.
Notifying the regulator but not the clients when the risk to them is high.
Practise more FRE2 Money Laundering, Proceeds of Crime & Data Protection questions
Exam-style questions with worked answers, then full timed mocks. Free to start.
Build a daily practice habit — a few exam-style questions a day, with worked answers. Free to start.
Start practising →Original practice material mapped to the published CeMAP FRE2 learning outcomes. Independent, not endorsed by Walbrook (formerly LIBF). Verify figures and rules against current guidance before relying on them.