1. Purpose and Scope
- This Standard Operating Procedure (SOP) sets out the required process for responding to actual or suspected personal information breaches.
- This procedure applies to all personnel, systems, vendor integrations, and physical or electronic personal data held by [Organisation Name], including customer, staff, and third-party records.
Working through related paperwork at the same time? See also our UK Data Breach Response Procedure Template, Data Protection Policy Template and UK Data Retention & Disposal Policy Template.
2. Definition of Data Breach
A data breach occurs whenever personal information is lost, stolen, exposed, accessed without authorization, or improperly handled. Examples include:
- Sending emails, letters, or documents containing personal information to unintended recipients.
- Losing or suffering the theft of hardware, mobile devices, removable media, or physical files.
- Unauthorized system entry via phishing, malware, ransomware, or credential theft.
- Staff accessing records or personal data without a legitimate business need.
- Security incidents reported by third-party vendors or service providers holding company data.
3. Roles and Responsibilities
- Breach Lead (
[Role], Deputy[Role]): Directs incident response, maintains the breach log, coordinates internal and external resources, and decides on notification requirements alongside legal counsel and[Senior Management Role]. - IT and Security Support (
[Role/Provider]): Executes technical containment, secures systems, isolates network components, and preserves digital evidence. - Legal Counsel (
[Firm/Contact]): Advises on legal and regulatory duties across jurisdictions and approves all external communications before release. - All Personnel: Must report any actual, suspected, or potential data breach immediately upon discovery via
[Phone Number/Channel].
4. Incident Reporting and Containment Procedure
- Report the actual or suspected breach immediately to the Breach Lead via
[Phone Number/Channel]. Report incidents without delay, including outside standard business hours. - Record the exact date and time of discovery to track regulatory compliance deadlines.
- Contain the incident immediately using tactics suited to the breach type. Examples include recalling emails, wiping devices remotely, revoking access for compromised accounts, isolating network segments, or physically locking down paper files.
- Preserve all technical and physical evidence. Do not alter logs, delete files, or turn off devices unless instructed by technical or forensic leads.
- Contact the cyber insurance provider (
[Policy Number/Contact]) before hiring external forensic or technical vendors. - Request written confirmation of data deletion from any unintended recipient who received personal information.
Use our templates to fast-track your documentation
Customize this template and 100s of others for free in Whale, the fastest way to get your team aligned.
5. Scope and Risk Assessment Procedure
- Establish the facts: identify how the exposure happened, which systems are affected, the volume of impacted records, and whether the breach is still active.
- Identify the specific data types involved (such as names, government IDs, financial data, driver’s license details, health records, or login credentials).
- List all affected individuals and record their state or country of residence to determine applicable notification laws.
- Assess the likelihood and impact of potential harm, including identity theft, financial loss, account takeover, physical danger, or personal distress. Increase the risk severity rating if the breach involves credentials or information belonging to minors.
- Record every assessment step, piece of evidence, and conclusion in the central breach log.
6. Notification Assessment Procedure
- Check the affected jurisdictions against legal advice and current state or federal regulatory rules.
- Decide if the breach meets statutory notification triggers, considering the data types, operational impact, and whether the data was encrypted.
- Determine if you must notify state regulators, law enforcement, credit bureaus, or industry oversight bodies.
- Decide if reporting to law enforcement is necessary or helpful. Document any official law enforcement requests that delay notification schedules.
- Log the full legal and operational rationale in the breach log if you determine that formal notification is unnecessary.
7. Communication and Notification Procedure
- Draft plain-language notices for affected individuals. Include incident details, compromised data categories, actions taken to fix the issue, recommended self-protection steps, and direct contact details for [Organisation Name].
- Send all draft communications to legal counsel for review before release to ensure compliance with relevant laws.
- Coordinate notice distribution dates with cyber insurance reps, forensic leads, and law enforcement. Do not delay notices beyond statutory deadlines.
8. Records, Lessons Learned, and Review
- Maintain all incident records, risk assessments, legal advice, notifications, and remediation logs in the central breach log at
[System/Location]. - Within
[Period, e.g., 30 days]of resolving an incident, the Breach Lead will run a post-incident review. This review must pinpoint system failures, refine technical controls, update vendor terms, and refresh staff training. - Review this procedure annually. Update it immediately following any notifiable breach.
- Procedure Owner:
[Role] - Next Review Date:
[Date]
FAQs on a data breach response procedure
What is a data breach response procedure?
A data breach response procedure sets out the required process for responding to actual or suspected personal information breaches.
Having it written down means the same rules apply to everyone, so managers are not making judgement calls case by case under pressure.
What does a data breach response procedure include?
This template covers definition of data breach, incident reporting and containment procedure, notification assessment procedure and communication and notification procedure.
Every section is written to be filled in. The bracketed placeholders mark the decisions that are yours to make, such as timescales, approval owners and retention periods.
How to implement a data breach response procedure with Whale
Copy this template into Whale and work through the bracketed placeholders so it reflects how your organisation actually operates.
Assign it to the teams it applies to so it sits where people work rather than in a shared drive, and set a review date so it gets revisited on schedule instead of quietly going out of date.
Use our templates to fast-track your documentation
Customize this template and 100s of others for free in Whale, the fastest way to get your team aligned.