
Checklist for responding to a data breach
- Clear and easy to understand
- Practical guidance
- Helps you comply with your UK GDPR obligations
This checklist for responding to a data breach takes you through the steps you should take once you become aware of a personal data breach in your business (where personal data has been accidentally or illegally destroyed, lost, stolen or disclosed).
This checklist includes the steps that you are legally required to take, depending on the circumstances of the breach.
Failure to take the necessary steps after a personal data breach can result in very serious consequences, including significant fines.
Q&A
When should I use this document?
Use this checklist as soon as possible after becoming aware that there has been a personal data breach in your business.
What does this document cover?
This checklist sets out the steps you should take, including those required by law, once you become aware that a personal data breach has occurred.
Why do I need this document?
It is important that you carry out the legal steps that are included on this checklist once you know that a personal data breach has occurred. Failure to do so can result in your business being fined up to £8.7 million or 2% of your global turnover, whichever is higher.
Where can I find out more?
See Data breaches for further guidance on personal data breaches and what to do if your business experiences a personal data breach.
Related Toolkits
Data breach toolkit
Personal data breach policy
Template personal data breach register
Notice of a personal data breach (affected individuals)
- How-to guide: Data breach toolkit
Data protection policy toolkit
- How-to guide: Data protection policy toolkit
Privacy policy
Cookie policy
Data protection policy
Staff privacy notice
Staff recruitment privacy notice
Data subject request policy
Data protection impact assessment policy
Personal data breach policy
Data subject request toolkit
- How-to guide: Data subject request toolkit
Data subject request policy
Subject access request form
Data transfer request form
Request form to correct inaccurate or incomplete data
Request form to delete data
Request form to stop using data
Letter acknowledging receipt of data subject request (and requesting verification of ID)
Letter asking for further information about a data subject request
Letter confirming no data held in response to data subject request
Letter explaining reasons for extension of time to respond to data subject requests
Letter to third party seeking consent to disclosure of information
Subject access request response template
Letter confirming that data processing has ceased
Letter explaining why data processing will continue
Letter confirming that data has been corrected
Letter explaining why data will not be corrected
Letter to party who has been supplied with data to confirm its correction
Letter confirming that data has been deleted
Letter explaining why data will not be deleted
Letter to party who has been supplied data to confirm its deletion
Letter supplying data in response to a portability request
Letter supplying data to a third party in response to a portability request
Small claims toolkit
- How-to guide: Small claims toolkit
Letter before action
Witness statement
Letter of non-attendance for small claims hearing