
Personal data breach policy
- Ensures clear and efficient procedures are in place
- Quick and easy to complete
- Helps you comply with UK GDPR obligations
This template personal data breach policy allows you to produce an internal policy to help you comply with your data protection obligations if there has been a personal data breach in your business.
There are important legal obligations to fulfil when there has been a personal data breach, such as notifying the Information Commissioner’s Office and the individual concerned, within specified time frames.
This template policy sets out a response plan to any personal data breach, as well as steps your business can take to prevent personal data breaches and keep personal data secure.
You can also purchase this policy as part of the Data breach toolkit, the Remote working and cybersecurity toolkit, or the Data protection policy toolkit.
Q&A
When should I use this document?
Use this template personal data breach policy to put in place internal procedures to follow if a personal data breach happens in your business.
It is best to always have a personal data breach policy in place, regardless of whether a breach has occurred.
What does this document cover?
This template policy sets out clearly the procedures for your business to follow if there has been a personal data breach.
It includes reporting procedures, a response process, evaluation and record-keeping, as well as preventative measures to reduce the risk of a breach.
Why do I need this document?
Failure to fulfil your data protection obligations and notify the relevant people in the event of a personal data breach can lead to fines of up to £8.7 million or 2% of your global turnover (whichever is higher).
Having a personal data breach policy in place reduces the risk of fines or sanctions as a result of breaching data protection law.
Where can I find out more?
For more information on data breaches, including what to do when one occurs, see Data breaches.
Related Toolkits
Data breach toolkit
Personal data breach policy
Template personal data breach register
Notice of a personal data breach (affected individuals)
- How-to guide: Data breach toolkit
Data protection policy toolkit
- How-to guide: Data protection policy toolkit
Privacy policy
Cookie policy
Data protection policy
Staff privacy notice
Staff recruitment privacy notice
Data subject request policy
Data protection impact assessment policy
Personal data breach policy
Data subject request toolkit
- How-to guide: Data subject request toolkit
Data subject request policy
Subject access request form
Data transfer request form
Request form to correct inaccurate or incomplete data
Request form to delete data
Request form to stop using data
Letter acknowledging receipt of data subject request (and requesting verification of ID)
Letter asking for further information about a data subject request
Letter confirming no data held in response to data subject request
Letter explaining reasons for extension of time to respond to data subject requests
Letter to third party seeking consent to disclosure of information
Subject access request response template
Letter confirming that data processing has ceased
Letter explaining why data processing will continue
Letter confirming that data has been corrected
Letter explaining why data will not be corrected
Letter to party who has been supplied with data to confirm its correction
Letter confirming that data has been deleted
Letter explaining why data will not be deleted
Letter to party who has been supplied data to confirm its deletion
Letter supplying data in response to a portability request
Letter supplying data to a third party in response to a portability request
Small claims toolkit
- How-to guide: Small claims toolkit
Letter before action
Witness statement
Letter of non-attendance for small claims hearing