What to do if you experience a breach of personal data

Data Breach

Unless your organisation has no personally identifiable information (impossible in today’s world), it is inevitable that you will suffer a breach.  An email may get sent to the wrong recipient, paperwork and files may be lost in a flood or fire or a device may get lost or stolen.

If a data breach occurs – don’t panic! Not all breaches are reportable to the Information Commissioner’s Office (ICO) and even those that are reportable do not always result in formal action on the part of the ICO. 

As soon as a data breach occurs start your timer

Start the timer as soon as you become aware that a breach has occurred.  However, only breaches that meet the threshold for reporting have to be sent to the ICO within 72 hours.

Investigate and contain the impact of your data breach

Keep a record of what happened, who is involved in the breach and what you are doing about it.  

At the same time as investigating, try to recover and/or protect the data.  

  • If an email goes astray, recall it or contact the recipient and ask them to delete it and confirm that they have not kept a copy.
  • If your laptop was stolen and it can be wiped remotely, do so.
  • For cyber incidents, make sure that passwords accessing your systems are changed.  

Assess the risk of your data breach

Understand whether there is any risk of harm to the person(s) affected by the incident.  Harm comes in various forms such as safeguarding issues, identity theft or significant psychological or emotional distress.  For simple mix-ups there’s unlikely to be much risk of harm and therefore no need to report them.  However, where you are dealing with serious breaches that could have a big impact or long-lasting effect on people, or less serious breaches impacting a large number of people, these will have to be reported to the ICO. 

Protect your data subjects

Unless you think there is a high risk of harm to the people impacted by the incident, you don’t have to tell them that the incident happened. 

If you do have to notify them, it’s helpful to tell your data subjects what can they can do to protect themselves.  Depending on the circumstances, this might include:

  • Change their passwords for stronger ones
  • Look out for phishing emails and explain what to do with them
  • Notify their bank and look out for fraudulent activity on their bank account

Also, tell them what you are willing to do to help, which might be to cover the cost of identity and credit risk checking for a period of time.  

Report the incident to the Information Commissioner’s Office

Even if you don’t have all the details, for reportable incidents make sure that the report is submitted within 72 hours of discovering the breach. Your report must include:

  • What happened and when
  • Details of your risk assessment
  • What steps have been taken to contain and protect

The ICO will take it from there.

Need a hand? Contact us for help in preparing your data breach strategy and process

Please contact us for a no-obligation chat.  We can help you understand your data protection obligations in more detail, so that you can comply with the law and put procedures in place to reduce the risk of breach or non-compliance, which will lead to building trust and boosting your reputation as a responsible business.