Local Government is facing a growing HR and wellbeing challenge as new analysis highlights the scale of GDPR breaches across the sector.
According to data from the Information Commissioner’s Office (ICO), analysed by Reward Gateway | Edenred, councils reported 1,956 data breaches between 2023 and the first quarter of 2025, making local government one of the most affected sectors.
Across all industries, nearly 22,000 self-reported breaches were recorded in this period, with health, education, retail and finance also among the most impacted sectors.
Breaches range from lost laptops and emails sent to the wrong recipient, to cyberattacks exposing sensitive records.
Under UK GDPR rules, organisations must notify the ICO within 72 hours of a breach that risks individuals’ rights and freedoms, and in some cases inform those affected.