Personal data breach
A personal data breach is a security failure causing accidental or unlawful loss, change, destruction, disclosure of or access to personal data.
A breach is wider than stolen data
A personal data breach is a failure of confidentiality, integrity or availability. It can be deliberate or accidental. Examples include sending payroll information to the wrong person, giving unauthorised access to sickness records, changing information without authority, losing an unencrypted device or being unable to restore employee records when they are needed.
Contain the incident without destroying evidence. Record when the organisation became aware, what happened, which systems and people are affected, the types and sensitivity of data, likely consequences, immediate action and the person leading the response.
Assess the risk to people
The controller must assess the likelihood and severity of harm to people's rights and freedoms. Consider the nature and volume of the information, who could receive it, how easily people can be identified and consequences such as discrimination, financial loss, identity fraud, distress or loss of confidentiality.
If a risk is likely, notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware. The ICO's breach guide allows details to be supplied in phases, so do not wait for every fact. Explain any delay. If risk is unlikely, an ICO report is not required, but the decision and evidence still belong in the internal breach record.
Meet each notification duty
When the likely risk is high, tell affected people directly and without undue delay, using plain language and practical protective advice. A processor has a different duty: it must notify its controller without undue delay rather than waiting to decide the regulator threshold.
Record every breach, including those not reported externally. Name an incident owner, escalation route, processor contacts and notification authority, then rehearse the process before a real event tests it.
Start free with your first 10 people.
Bring your team over from a spreadsheet. There is no card, no sales call and no lock-in. For up to 10 people, everyday HR is free.