
Notice of a personal data breach (affected individuals)
- Clear and easy to complete
- Practical help for your business
- Helps you comply with your UK GDPR obligations
This template Notice of a personal data breach (affected individuals) will allow you to produce a letter to send to any individuals who have been affected by a personal data breach in your business, where their personal data has been accidentally or illegally destroyed, lost or disclosed.
You have a legal requirement to inform affected individuals where the breach carries a high risk to their rights and freedoms. In the most serious cases, failure to notify the affected individuals of a personal data breach can result in a significant fine.
You can also purchase this document as part of the Data breach toolkit.
Q&A
When should I use this document?
Use this document when you become aware that there has been a personal data breach in your business, and there is a high risk to the rights and freedoms of the individuals who have been affected. You must notify the individuals involved without delay.
What does this document cover?
This notice, or letter, informs the individual concerned that there has been a data breach, and includes the following information:
-
a summary of the incident;
-
details of the personal data that has been affected;
-
steps the individual should take to minimise the risk of the current breach and any future breaches; and
-
steps your business is taking to contain the breach and minimise risks.
-
Why do I need this document?
You have a legal obligation to inform affected individuals without delay where there has been a personal data breach in your business, and it poses a high risk to their rights and freedoms.
This template letter will help you fulfil that obligation by guiding you through the information that is required.
Where can I find out more?
For detailed guidance on data breaches in general, see Data breaches.
For further information on your obligation to notify those individuals who have been affected by a data breach, see Obligations when a data breach occurs.
Related Toolkits
Data breach toolkit
Personal data breach policy
Template personal data breach register
Notice of a personal data breach (affected individuals)
- How-to guide: Data breach toolkit
Data protection policy toolkit
- How-to guide: Data protection policy toolkit
Privacy policy
Cookie policy
Data protection policy
Staff privacy notice
Staff recruitment privacy notice
Data subject request policy
Data protection impact assessment policy
Personal data breach policy
Data subject request toolkit
- How-to guide: Data subject request toolkit
Data subject request policy
Subject access request form
Data transfer request form
Request form to correct inaccurate or incomplete data
Request form to delete data
Request form to stop using data
Letter acknowledging receipt of data subject request (and requesting verification of ID)
Letter asking for further information about a data subject request
Letter confirming no data held in response to data subject request
Letter explaining reasons for extension of time to respond to data subject requests
Letter to third party seeking consent to disclosure of information
Subject access request response template
Letter confirming that data processing has ceased
Letter explaining why data processing will continue
Letter confirming that data has been corrected
Letter explaining why data will not be corrected
Letter to party who has been supplied with data to confirm its correction
Letter confirming that data has been deleted
Letter explaining why data will not be deleted
Letter to party who has been supplied data to confirm its deletion
Letter supplying data in response to a portability request
Letter supplying data to a third party in response to a portability request
Small claims toolkit
- How-to guide: Small claims toolkit
Letter before action
Witness statement
Letter of non-attendance for small claims hearing