How To Write a Personal Data Breach Policy

13th January 2025

Organisations should take a proactive approach to data protection and create a personal data breach policy. This policy can help the organisation respond appropriately to a data breach by providing the necessary steps that should be taken. An effective data breach policy can minimise risks and protect the organisation and the individuals concerned from the negative consequences of a data breach. 

Before creating a data breach policy, the following steps should be taken and considerations made:

Risk assessment

Performing a risk assessment before processing personal data can help to determine the type, nature, classification and volume of data you handle, whether that data is considered sensitive or special category data, and the potential impact of a data breach on the data subject and the organisation as a whole, for example, in terms of damage to reputation.

Existing security policies

Do not reinvent the wheel, and try to keep your policies and guidance on distinct subjects. Remember, you can refer to and build upon existing security policies and procedures when creating a personal data breach policy. Take a look at the organisation’s existing privacy and security policies and use them as a base for the data breach policy.

Response team

Consider who should be informed in the event of a data breach, e.g. the DPO, senior staff members and/or management, and the IT team. Include specific people and their contact information. The channel(s) for reporting incidents must also be well thought out, robust, and crystal clear.

Procedure

This should detail what exactly needs to be done if a data breach occurs, e.g., who needs to be informed within the organisation, and what immediate actions should be taken depending on the nature of the data breach. 

Mitigation

Having identified any potential risks, Controllers can then specify what action needs to be taken in the event of a breach to minimise any harm to the data subject(s), which will naturally reduce the risk to the organisation. 

How to Create a Data Breach Policy

Note: A policy is not an SOP (standard operating procedure) or guidance! As part of my day job, I write and review policy documents all the time. Organisations often confuse a policy, which should outline an organisation’s overarching aims, with a standard operating procedure or guidance. A policy should be a 2 or 3-sided document. You should be happy to share a policy externally as there should be nothing confidential in it.

So that all employees and stakeholders know what to do if they are suspicious of, or encounter evidence of a data breach or incident, businesses and organisations should create a personalised data breach policy and associated guidance if necessary. However, creating an incredible 200-page forensic document that is too complicated, technical or detailed for employees to follow is no use.

KISS – Follow the universal first rule in business – Keep It Simple!

A good policy should have a number of elements, including:

  1. Policy Aims
    The objective of the policy should be clearly defined. This could be to ensure the organisation responds swiftly and effectively to any data breach, minimising damage, ensuring compliance with legal obligations, and protecting individuals’ rights.
  2.  Purpose and Scope of this Policy
    This section should outline how the organisation will achieve the policy’s aim. It should clearly state who is covered by the policy (e.g., employees, contractors, third-party suppliers) and under what circumstances it applies (e.g., any unauthorised access, disclosure, loss, or alteration of personal data). This is also where you clarify whether the policy applies to specific data types or all data within the organisation.
  3. Responsibilities
    Define the roles and responsibilities of individuals within the organisation. Who is accountable for overseeing compliance? Who should be notified in the event of a data breach? This section might include the Data Protection Officer (DPO), IT teams, department heads, and all employees who handle personal data. It’s important to also outline the process for escalating a breach to senior management or regulatory bodies.
  4. Why we need to comply
    Explain the legal framework and regulations underpinning the policy, such as the GDPR and Data Protection Act 2018. This section should stress the importance of compliance not only for legal reasons but also to maintain customer trust and organisational reputation.
  5. How we comply
    Provide overarching guidance on the actions employees and stakeholders must take to remain compliant. This could include guidance on securing data, recognising potential breaches, and the immediate actions required if a breach is suspected or confirmed (e.g., reporting to the DPO, containing the breach, gathering evidence). Note: this should not contain confidential information.
  6. Resources and other information
    Provide links to related guidance, SOPs, and other policies such as data protection policies, IT security policies, or employee confidentiality agreements. This section can also include external resources, such as links to data protection authorities, relevant legal texts, or industry-specific guidance.
  7. Version History
    A version control table is essential to ensure the policy remains current and to demonstrate compliance with the Accountability Principle under GDPR. Each update should include the date, author, and summary of changes, ensuring there is a clear record of the policy’s development over time.

Training and policy reviews

Data breach policies should be periodically reviewed to ensure they are still effective and up to date, consider reviewing yours once per year, or when a new data protection law or regulation comes into effect.

Company-wide data protection training should include a section on what to do in the event of a data breach. Employees should be aware of the data breach policy and the plans in place if a data breach occurs.

Note: Don’t just store your data breach policy on your devices, main computer network, or in the cloud. If computers or networks are affected by the breach, you may not be able to access them. Instead, print off hard copies and make sure every employee has access to one.

If you need help creating your personal data breach policy, we can help. With over 25 years of experience in data protection and information governance, the Griffin House Consultancy can assist with policy creation, auditing, training and more – get in touch with us here.

Author: Mike Martin LLM

Mike is an information governance specialist and one of the founder Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details