Skip to content
DutyHub

Templates

Personal data breach log

The log has to cover the breaches you decided not to report. Those are the entries that get scrutinised.

Download the CSV

No email address required. It is a file.

What it records

Awareness time is its own column, separate from when the incident happened, because the 72 hours runs from the first and is routinely confused with the second. The reason-for-decision column exists because documenting every breach — including the non-notifiable ones — is the requirement people most often miss.

The columns

ColumnWhat goes in it
Reference Your reference.
Incident date/time When it happened, so far as known.
Became aware date/time When the organisation first knew. The clock starts here.
Discovered by Who reported it.
What happened A factual account.
Data involved Categories of data and roughly how many people.
Risk to individuals Your assessment of likely harm.
Reportable? Your decision.
Reason for decision Why. Required whether or not you reported.
Regulator notified Date and reference, if applicable.
Individuals told Whether, when and how.
Remedial action What changed.

This is a starting point, not a compliance document. What your organisation actually needs to record follows from your own risk assessment and from the arrangements you have in place; a template cannot know either. Nothing here is legal advice.

Or stop keeping it in a spreadsheet

A spreadsheet records what you type into it. It does not chase you when a week is missed, turn a duty amber when a check falls due, or raise an action from a failed reading — and it is not much use as evidence, because it can be edited afterwards without trace.

How DutyHub handles data breaches Recurring checks See pricing