
Data breach toolkit
- Keep good records
- Reduce your risk of fines or other penalties
- Step-by-step guidance and relevant documents
This data breach toolkit guides you through the steps you need to take when you become aware of a personal data breach (such as a staff member sending customer information to the wrong person, or a device containing customer information being lost or stolen).
It includes a how-to guide, as well as a pack of the relevant documents you are likely to need. In this data breach toolkit you will find:
- a personal data breach policy;
- a template notice for notifying affected individuals; and
- a template personal data breach register for keeping records of breaches.
This data breach toolkit helps you to identify, assess and contain a personal data breach, inform the relevant people, and keep written records of the breach.
By using this toolkit, you reduce your risk of being penalised by the ICO. Keeping on top of your data protection processes also helps to maintain your reputation and build customer relationships.
Q&A
When should I use this toolkit?
You should use this data breach toolkit if you become aware of a personal data breach (such as customer information accidentally being sent to the wrong person).
As well as providing guidance on how to respond to a data breach, this toolkit includes a template Personal data breach policy, which you should have in place now.
What does this toolkit cover?
This data breach toolkit includes a how-to guide, which sets out the key steps to take when you become aware of a data breach. Such steps include identifying, assessing and containing the breach, informing the relevant people about the breach, and keeping written records of the breach.
The toolkit also includes all of the relevant documents you are likely to need:
- Personal data breach policy;
- Notice of a personal data breach; and
- Template personal data breach register.
Why do I need this toolkit?
It is very important to comply with your obligations under data protection law, to minimise the risk of being fined by the ICO and to maintain your business reputation and customer relationships.
By using this data breach toolkit, you ensure that you follow a proper process to deal with data breaches, which helps you to contain the breach and work out what steps you need to take (such as notifying the ICO). It also provides appropriate templates to keep good records.
Where can I find out more?
For full guidance on dealing with data breaches, see Data breaches.
Documents in Toolkit
How-to guide: Data breach toolkit
Notice of a personal data breach (affected individuals)
Personal data breach policy
Template personal data breach register
Related Toolkits
Data protection policy toolkit
- How-to guide: Data protection policy toolkit
Privacy policy
Cookie policy
Data protection policy
Staff privacy notice
Staff recruitment privacy notice
Data subject request policy
Data protection impact assessment policy
Personal data breach policy
Data subject request toolkit
- How-to guide: Data subject request toolkit
Data subject request policy
Subject access request form
Data transfer request form
Request form to correct inaccurate or incomplete data
Request form to delete data
Request form to stop using data
Letter acknowledging receipt of data subject request (and requesting verification of ID)
Letter asking for further information about a data subject request
Letter confirming no data held in response to data subject request
Letter explaining reasons for extension of time to respond to data subject requests
Letter to third party seeking consent to disclosure of information
Subject access request response template
Letter confirming that data processing has ceased
Letter explaining why data processing will continue
Letter confirming that data has been corrected
Letter explaining why data will not be corrected
Letter to party who has been supplied with data to confirm its correction
Letter confirming that data has been deleted
Letter explaining why data will not be deleted
Letter to party who has been supplied data to confirm its deletion
Letter supplying data in response to a portability request
Letter supplying data to a third party in response to a portability request
Small claims toolkit
- How-to guide: Small claims toolkit
Letter before action
Witness statement
Letter of non-attendance for small claims hearing
Redundancy toolkit
- How-to guide: Redundancy toolkit
Redundancy - Letter warning of proposed redundancies
Redundancy - Selection criteria form
Redundancy - Provisional selection for redundancy letter
Redundancy - First individual consultation meeting agenda
Redundancy - Outcome of individual consultation meeting
Redundancy - Invitation to final individual consultation meeting
Redundancy - Final individual consultation meeting agenda
Redundancy - Notice of termination of employment
Redundancy - Offer of alternative employment