// personal-data-breach-log
Personal Data Breach Log
Personal Data Breach Record
Controller: [Business name] ([contact]).
Discovered: [date/time].
What happened
[description of the breach].
Who and what was affected
[people and data affected].
Record the approximate number of individuals affected and the approximate number of personal data records concerned, the categories of individuals (for example customers or employees), and the categories of personal data involved (for example names, contact details, financial or special category data). Note the likely consequences for those individuals, such as distress, financial loss, or identity theft.
Assessment and actions
Assess the likely risk to affected people. If it is likely to risk their rights and freedoms, report to the ICO without undue delay (usually within 72 hours), and tell affected people if the risk is high.
Record the containment steps taken and lessons learned.
Record the date and time you became aware of the breach and, if the ICO was notified more than 72 hours after that, the reasons for the delay. If the breach was not reported to the ICO, record the reasons for deciding it was unlikely to result in a risk to individuals.
Record what you did to contain and remedy the breach (for example recalling or deleting data, resetting passwords, or notifying affected individuals), whether affected individuals were informed and how, and any steps taken to prevent a recurrence. Keep this record even where the breach was not reportable, as you must document all personal data breaches.
draft generated by privacyready — Sample content — review with a qualified person. Not legal advice.