Spot and contain
- Staff member spots a possible data incidentStaff
For UK and EU organisations: decide if a personal data breach must be reported to the regulator and to the people affected under UK GDPR or EU GDPR.
Examples: an email sent to the wrong person, a lost laptop, ransomware, or records deleted or changed without permission.
- Report it to the DPO or privacy lead straight awayStaff
Say what happened, when you found it, what data and systems are involved, and what you have already done.
Do not wait until you have every detail. The 72-hour clock can start once the organisation is aware.
- Does it involve personal data?DPO
Personal data is information that relates to an identifiable person, such as names, emails, health records or account details.
- Not a personal data breach. Handle as a security incidentDPO
- Was its confidentiality, integrity or availability affected?DPO
A personal data breach is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data (Article 4(12)).
Losing access counts too, for example when ransomware encrypts records and you cannot restore them.
- Not a breach. Log the near miss and closeDPO
- Treat it as a personal data breachDPO
- Are you the controller or a processor for this data?DPO
The controller decides why and how the data is used. A processor handles it on the controller's behalf, for example a payroll or cloud provider.
- Processor: go to step 9, Tell the controller without undue delay
- Controller: go to step 10, Note the time you became aware
- Tell the controller without undue delayDPO
Article 33(2). Your contract with the controller should say how and when to tell them. The controller makes the notification decisions.
- Note the time you became awareDPO
Record the date and time. The 72 hours run from when you became aware of the breach.
- Contain the breach and limit the harmDPO
For example: recall or ask the recipient to delete a misdirected email, disable compromised accounts, change passwords, restore from backup.
- Record the breach in your breach logDPO
Article 33(5): record every personal data breach, whether or not you report it. Include the facts, its effects and the remedial action taken.
Notify the regulator
- Is the breach likely to result in a risk to people's rights and freedoms?DPO
Consider the type and sensitivity of the data, how many people are affected, and the possible harm, such as fraud, discrimination, distress or loss of confidentiality.
The ICO has a self-assessment tool on its website if you are not sure.
- Unlikely: go to step 14, No report needed. Record your reasons in the log
- Likely: go to step 15, Notify the supervisory authority within 72 hours
- Not sure: go to step 15, Notify the supervisory authority within 72 hours
- No report needed. Record your reasons in the logDPO
You must be able to justify the decision not to report.
- Was the report made within 72 hours of becoming aware?DPO
- Add further details in phases if neededDPO
Article 33(4) allows information to be given in phases, without undue further delay.
Then go to step 19, Is the breach likely to result in a high risk to people?
- Give the reasons for the delay with the reportDPO
Article 33(1). A late report must be accompanied by reasons for the delay.
Tell the people affected
- Is the breach likely to result in a high risk to people?DPO
The bar is higher than for reporting to the regulator. Weigh both how severe the harm could be and how likely it is.
- No need to tell individuals. Record your reasoningDPO
- Does an Article 34(3) exception apply?DPO
The data was unintelligible to anyone without access, for example strongly encrypted with the key safe.
Or later measures mean the high risk is no longer likely to materialise.
- Disproportionate effort: go to step 22, Make a public communication instead
- Encrypted or risk removed: go to step 24, No need to tell individuals. Record why
- No exception: go to step 25, Tell affected people without undue delay
- Make a public communication insteadDPO
Article 34(3)(c). Use a public notice or similar measure that informs people in an equally effective way.
- Public notice made. Record it in the logDPO
- No need to tell individuals. Record whyDPO
The regulator can still require you to tell people (Article 34(4)).
- Tell affected people without undue delayDPO
Use clear and plain language. Describe the breach, give the DPO contact, likely consequences and what you have done.
Give practical advice, such as resetting passwords or watching for phishing and fraud.
Close out
- Update the breach log with notifications and outcomesDPO
- Unsure, or does another regime apply?DPO
Other rules can apply on top of GDPR, for example for telecoms providers (PECR), trust service providers (eIDAS), or NIS incident reporting.
- Take legal advice before the deadline passesDPO
- Breach handled and documentedDPO