Personal data breach log
The log has to cover the breaches you decided not to report. Those are the entries that get scrutinised.
No email address required. It is a file.
What it records
Awareness time is its own column, separate from when the incident happened, because the 72 hours runs from the first and is routinely confused with the second. The reason-for-decision column exists because documenting every breach — including the non-notifiable ones — is the requirement people most often miss.
The columns
| Column | What goes in it |
|---|---|
| Reference | Your reference. |
| Incident date/time | When it happened, so far as known. |
| Became aware date/time | When the organisation first knew. The clock starts here. |
| Discovered by | Who reported it. |
| What happened | A factual account. |
| Data involved | Categories of data and roughly how many people. |
| Risk to individuals | Your assessment of likely harm. |
| Reportable? | Your decision. |
| Reason for decision | Why. Required whether or not you reported. |
| Regulator notified | Date and reference, if applicable. |
| Individuals told | Whether, when and how. |
| Remedial action | What changed. |
This is a starting point, not a compliance document. What your organisation actually needs to record follows from your own risk assessment and from the arrangements you have in place; a template cannot know either. Nothing here is legal advice.
Or stop keeping it in a spreadsheet
A spreadsheet records what you type into it. It does not chase you when a week is missed, turn a duty amber when a check falls due, or raise an action from a failed reading — and it is not much use as evidence, because it can be edited afterwards without trace.
How DutyHub handles data breaches Recurring checks See pricing