// personal data breach log

Personal Data Breach Log

/personal-data-breach-log

You must document any personal data breach — what happened, the effect, and what you did — and report qualifying breaches to the ICO, usually within 72 hours of becoming aware. A ready breach log helps you act fast under pressure. PrivacyReady assembles a structured breach record from a few details for you to complete and keep on file.

not legal advice. For use in the United Kingdom only. A standard template; a knowledgeable person must tailor it to how you actually use data.

// inputs00/05 set

Secure one-off payment via Stripe. No account needed.

preview · personal-data-breach-log
watermarked

// personal-data-breach-log

Personal Data Breach Log

Personal Data Breach Record

Controller: [Business name] ([contact]).

Discovered: [date/time].

What happened

[description of the breach].

Who and what was affected

[people and data affected].

Record the approximate number of individuals affected and the approximate number of personal data records concerned, the categories of individuals (for example customers or employees), and the categories of personal data involved (for example names, contact details, financial or special category data). Note the likely consequences for those individuals, such as distress, financial loss, or identity theft.

Assessment and actions

Assess the likely risk to affected people. If it is likely to risk their rights and freedoms, report to the ICO without undue delay (usually within 72 hours), and tell affected people if the risk is high.

Record the containment steps taken and lessons learned.

Record the date and time you became aware of the breach and, if the ICO was notified more than 72 hours after that, the reasons for the delay. If the breach was not reported to the ICO, record the reasons for deciding it was unlikely to result in a risk to individuals.

Record what you did to contain and remedy the breach (for example recalling or deleting data, resetting passwords, or notifying affected individuals), whether affected individuals were informed and how, and any steps taken to prevent a recurrence. Keep this record even where the breach was not reportable, as you must document all personal data breaches.

draft generated by privacyready — Sample content — review with a qualified person. Not legal advice.

// frequently asked

Questions, answered.

01
When must I report a breach to the ICO?
You must report a breach to the ICO without undue delay, and usually within 72 hours, where it is likely to risk people's rights and freedoms. Confirm the current threshold and process in ICO guidance.
02
Is this legal advice or a guarantee of compliance?
No. PrivacyReady helps you draft and organise your data-protection paperwork. The wording is a standard template that must be tailored to how your business actually uses personal data. It is not legal advice and does not guarantee UK GDPR compliance. Follow ICO guidance.