Personal data breaches
You must keep a record of every personal data breach, including the ones you decide not to report. The decision not to report is the one you will be asked to justify.
What the law requires
Article 33 of the UK GDPR requires a controller to notify the Information Commissioner of a personal data breach without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. Where notification is later than 72 hours it must be accompanied by reasons for the delay. Article 34 requires communication to the individuals concerned where the breach is likely to result in a high risk to them. Article 33(5) requires the controller to document every personal data breach — the facts, the effects and the remedial action — whether or not it was notifiable.
Legislation referred to on this page: UK GDPR Article 33 · UK GDPR Article 34 · Data Protection Act 2018. Named so you can read the source. Nothing on this page is legal advice, and whether a duty applies to your organisation is a question for you and your adviser.
Who it applies to
- Every controller. Processors must notify the controller without undue delay, which makes the contract terms part of the response.
- The clock runs from awareness, which is a defined moment and worth recording explicitly.
- A breach is not only a hack — a misdirected email, a lost laptop and a wrongly configured folder are the common ones.
What you have to be able to show
The list an inspector, insurer or auditor actually works through.
- The internal breach log, covering reported and unreported incidents alike.
- When you became aware, and how that was established.
- The risk assessment, and the reasoning behind reporting or not reporting.
- What was notified to the Information Commissioner, and when.
- Communication to affected individuals where the risk was high.
- Remedial action, and what changed so it does not happen again.
How DutyHub records it
DutyHub does not carry out any of the work below. It records who did, when, and what they found.
The clock starts at awareness
Awareness is recorded as its own timestamp, separate from when the incident happened and when somebody wrote it up.
Every breach logged, reportable or not
The register keeps the not-reported ones with their reasoning, because Article 33(5) asks for exactly those.
A tamper-evident trail
Decisions are written through the audit trail and sealed, so the record of what you knew and when is not a document somebody could tidy up later.
Start with what applies to you
Add your premises and answer a short set of questions about them. DutyHub works out which duties land on which building, and shows you the gaps before anybody else finds them.
Check your Martyn's Law tier — free See pricing