What To Do in the Event of a Data Breach
27th February 2025
All organisations should know what to do if a personal data breach or any data incident occurs. Taking a proactive approach and having policies and procedures in place for such an event can help protect personal data, remain compliant with data protection laws, and limit the adverse effects of the data breach.
What is a Personal Data Breach?
First, we must understand what exactly constitutes a personal data breach, and from this point on, purely for ease of reading, I shall refer to this as a ‘data breach’. Article 4(12) of the UK GDPR defines a ‘personal data breach’ as:
“a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed”
A data breach could constitute anything from physical documents being left out where anyone present could view personal data or an email containing personal data being sent to the wrong person, to a fire or flood destroying personal data or a cybersecurity attack by a malicious party who wishes to access or expose personal data. The nature of the breach does not define it – it could be a simple accident or a deliberate act. The data also does not have to be stolen, it could be lost, destroyed, accessed or changed.
Steps to take following a data breach discovery
Consult your data breach policy
This is a document that will detail what you should do in the event of a data breach, this document should of course be created ahead of time – see our guide on creating a data breach policy.
Identify and inform the responsible person
Whilst not every potential data breach will need to be reported to a Regulator, all potential data incidents MUST be reported internally to the responsible individual or relevant team right away. Depending on an organisation’s structure, this could be someone’s immediate supervisor or manager, the IT team, the compliance team, or the designated Data Protection Officer (DPO) if one is appointed; some of the reporting may well occur concurrently, i.e. inform the DPO and IT team simultaneously. Your policy must be very clear on these reporting lines and responsibilities – a RACI (Responsible, Accountable, Consulted and Informed) matrix may be a good place to start.
One word of warning here, be careful that any policy is clear and that the individual discovering the breach does not notify unauthorised individuals, thereby compounding the breach and potentially causing greater distress or harm to the data subject(s) whose information was affected.
Investigation
Once a potential data incident has been reported, an internal investigation should be done by the appropriate individual or team as soon as possible to determine whether a data breach has occurred, the extent of the data breach, what data was involved, and what steps should be taken to prevent further issues.
Containment
A containment procedure should be created so that no additional data can be compromised. This could include resetting passwords, physically disconnecting affected devices from the network, revoking access privileges, and applying security patches and updates to software.
When should a data breach be reported to the ICO?
If the investigation reveals that personal data has been compromised resulting in a risk to an individual’s rights and freedoms, then the ICO (or appropriate Data Protection Authority) must be notified. This could be the case if sensitive data has been exposed (e.g. financial information, medical records), identity information (e.g. names, addresses, National Insurance numbers), large amounts of personal data, or if hackers or other malicious actors have accessed the data. If a small amount of personal data that is not sensitive was accidentally exposed to a trusted party, this might not warrant a report to the ICO. If the breach does not need to be reported to the ICO, be sure to document this and the reason for not notifying the Regulator. If in doubt, use the ICO’s self-assessment tool, call their helpline on 0303 123 1113, or complete their online enquiry form, to determine if a report should be made.
When should a data breach be reported to affected individuals?
If the data breach ‘could’, not ‘will’ result in a high risk to the rights and freedoms of individuals, the GDPR states that individuals should be informed as soon as possible, so they can take steps to protect themselves from the effects of the breach. What constitutes a high risk should be determined during the risk assessment phase, but could include the risk of identity theft, financial loss, damage to reputation, discrimination, emotional distress, or other significant effects.
How to report a data breach to the ICO
Data breaches can be reported on the ICO website using their online form. The form needs to be completed in one session – you can’t save it and return to it later, so make sure you have all the information and details about the breach to hand. You will need:
- Details of the breach, i.e. the date and time it occurred and when it was discovered.Details of staff members involved and what data protection training they have received.
- How much data was involved, the number of people affected, and the potential risks to the individuals involved.
- What preventative measures have you taken to minimise the effects of the data breach and prevent it from happening again, and other organisations involved that need to be informed about the breach?
If you identify opportunities for improvement, tell the ICO. The more information you can provide to the ICO on the actions you have, or intend to take, for example, changing policies, retraining staff, performing a full review of processes, etc. will improve the confidence of the ICO that you are taking the matter seriously and reduce their concerns. However, if you say you are going to take action, make sure you implement these actions or changes.
How long do I have to report a data breach?
UK data protection laws state that a data breach should be reported to the ICO within 72 hours of discovery. Record all the facts about the incident as they are uncovered, who is involved, and what actions have been taken to reduce the damage. Don’t worry if you don’t have all the information right away – you can make the initial report within 72 hours, and then follow up later by emailing additional information to the ICO.
If you need some assistance in creating your data breach policy, get in touch with us here at Griffin House Consultancy using our contact form or give us a call at 01673 885533 – we love to talk.
We also offer training and mentoring that can keep your team up to date on the best data protection practices and the latest UK data protection laws to ensure you remain compliant and reduce the risk of data breaches.
Author: Mike Martin LLM
Mike is an information governance specialist and one of the founder Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.