1. Purpose and Scope
This procedure details how [Organisation Name] handles actual or suspected personal data breaches. It applies to all staff, systems, and formats containing personal data on customers, personnel, or third parties.
Working through related paperwork at the same time? See also our US Data Breach Response Procedure Template, Data Protection Policy Template and UK Data Retention & Disposal Policy Template.
2. Definition of a Personal Data Breach
A personal data breach is any security incident that causes accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. Examples include:
- Sending an email, letter, or attachment containing personal data to the wrong recipient.
- Losing or having stolen a laptop, phone, USB drive, or paper file.
- Phishing, ransomware, or unauthorized access to systems containing personal data.
- Staff viewing records without a legitimate work reason.
- Deleting or changing personal data by accident when no backup exists.
- Any suspected incident where facts are unconfirmed (report these immediately for formal assessment).
3. Roles and Responsibilities
- Breach Lead (and Deputy): Directs the incident response, maintains the breach log, and decides on regulatory reporting alongside [Senior Role].
- IT Support: Handles technical containment and secures digital evidence.
- All Staff: Reports actual or suspected breaches immediately via [Contact Channel]. We treat prompt reports of honest mistakes as operational issues, not disciplinary matters.
4. Immediate Actions: Reporting and Containment
- Report suspected breaches to the Breach Lead right away via [Contact Channel], regardless of the time or day.
- Note the exact time the organisation learned of the incident. This starts the statutory 72-hour reporting clock.
- Contain the damage immediately. Recall misdirected messages, wipe remote devices, disable compromised accounts, reset passwords, isolate network segments, or retrieve paper records.
- Preserve all evidence. Keep system logs, files, and emails linked to the incident.
- Ask unintended recipients to delete any shared data and confirm the deletion in writing.
Use our templates to fast-track your documentation
Customize this template and 100s of others for free in Whale, the fastest way to get your team aligned.
5. Risk Assessment
- Gather the facts: types of data involved, affected individuals, volume of records, root cause, and current exposure status.
- Assess the likelihood and severity of potential harm to individuals, including financial loss, fraud, distress, discrimination, or physical security risks.
- Assign higher risk levels if the breach involves special category data, financial details, or records belonging to children.
- Document the assessment methodology, details, and outcome in the breach log for every incident, regardless of severity.
6. Regulatory Notification
The Breach Lead and [Senior Role] will review the risk assessment to decide if the incident requires reporting to the Information Commissioner’s Office (ICO).
- If the breach poses a risk to individuals, report it to the ICO within 72 hours of discovery using the official reporting route.
- If the investigation is ongoing, submit initial findings within the 72-hour window. Send updates in phases to avoid reporting delays.
- If reporting is not required, log the exact reasoning and decision in the breach log.
7. Communication with Affected Individuals
If a breach poses a high risk to the rights and freedoms of individuals, notify them without delay.
- Send clear, direct notices detailing what happened, the data involved, containment measures taken, recommended self-protection steps, and internal contact details.
- Coordinate external communications with outside parties (such as insurers or service providers), but do not let coordination delay notifying affected individuals.
8. Records, Post-Incident Review, and Governance
- Breach Log: Log every breach, suspected breach, and near-miss at [System/Location]. Record dates, times, facts, risk assessments, decisions, regulatory notices, and corrective actions taken.
- Post-Incident Review: Within [Timeframe, e.g., two weeks] of closing an incident, the Breach Lead will conduct a lessons-learned review to update systems, operational controls, staff training, or this procedure.
- Review Cycle: [Role] owns this procedure. Review it [Review Frequency, e.g., annually] and after any reportable breach.
- Next Review Date: [Date].
FAQs on a data breach response procedure
What is a data breach response procedure?
A data breach response procedure details how your organisation handles actual or suspected personal data breaches. It applies to all staff, systems, and formats containing personal data on customers, personnel, or third parties.
Having it written down means the same rules apply to everyone, so managers are not making judgement calls case by case under pressure.
What does a data breach response procedure include?
This template covers definition of a personal data breach, immediate actions: reporting and containment, risk assessment and regulatory notification.
Every section is written to be filled in. The bracketed placeholders mark the decisions that are yours to make, such as timescales, approval owners and retention periods.
How to implement a data breach response procedure with Whale
Copy this template into Whale and work through the bracketed placeholders so it reflects how your organisation actually operates.
Assign it to the teams it applies to so it sits where people work rather than in a shared drive, and set a review date so it gets revisited on schedule instead of quietly going out of date.
Use our templates to fast-track your documentation
Customize this template and 100s of others for free in Whale, the fastest way to get your team aligned.