Learning 4 - Security, breaches and complaints
| Site: | MyStudentSite Moodle |
| Course: | UK Data Protection Interactive SCORM |
| Book: | Learning 4 - Security, breaches and complaints |
| Printed by: | Guest user |
| Date: | Tuesday, 4 August 2026, 11:48 PM |
1. Section 4: Security, breaches and complaints
Section 4: Security, breaches and complaints
Protecting data, handling incidents and responding to people effectively.
Learning outcomes
By the end of this section, you should be able to:
- explain the integrity and confidentiality principle;
- identify a personal data breach;
- apply a structured breach response and risk assessment;
- explain the 72-hour ICO notification rule;
- describe the complaint-handling duties in force from 19 June 2026; and
- apply the full course to a realistic incident.
Security failures and poor complaint handling can turn manageable problems into serious harm. Staff should know how to recognise, contain, record and escalate concerns immediately.
Official reference points
- ICO: Personal data breaches
- ICO: How to deal with data protection complaints
- ICO: New data protection complaints law now in force
- legislation.gov.uk: Data (Use and Access) Act 2025
Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.
1.1. 4.1 Security and personal data breaches
4.1 Security and personal data breaches
Recognising security measures and different forms of breach.
Appropriate security
The UK GDPR requires appropriate technical and organisational measures. “Appropriate” depends on risk, context, cost, current technology and the nature of the data.
| Technical measures | Organisational measures |
|---|---|
| Multi-factor authentication, encryption, patching, backups, logging, network controls, secure configuration, malware protection and tested recovery. | Policies, training, access reviews, supplier management, incident plans, clear roles, secure disposal, physical security and auditing. |
What is a personal data breach?
It is a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
Knowledge checkpoint
Answer each question before opening the suggested answer.
1. A spreadsheet is sent to the wrong external recipient. Is this potentially a breach?
Suggested answer: Yes. It may be an unauthorised disclosure.
2. A system encrypts its own database after a ransomware attack. Which aspects may be affected?
Suggested answer: Availability and potentially confidentiality and integrity.
3. Does every personal data breach have to be reported to the ICO?
Suggested answer: No. The reporting threshold depends on risk, but every breach should be assessed and documented.
Official reference points
Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.
1.2. 4.2 Responding to a personal data breach
4.2 Responding to a personal data breach
Containment, risk assessment, notification, recovery and evidence.
Immediate response
- Escalate: notify the organisation's incident or data protection contact immediately.
- Contain: stop further disclosure, revoke links, retrieve information where possible and secure affected systems.
- Preserve evidence: retain logs, messages, timestamps and actions.
- Assess: identify the data, people, scale, protections and likely consequences.
- Decide notifications: consider the ICO, affected people, processors, insurers, law enforcement and contractual contacts.
- Recover and learn: restore services, reduce harm, address root causes and monitor corrective actions.
ICO notification
If the breach is likely to result in a risk to people's rights and freedoms, the controller must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it.
Telling affected people
If the breach is likely to result in a high risk, affected people normally need to be informed without undue delay in clear language, including the likely consequences and measures taken.
Internal records
Controllers must document breaches, facts, effects and remedial action so the ICO can verify compliance. This applies even where the ICO is not notified.
Activity: Risk-assess an email breach
A spreadsheet containing names, addresses, dates of birth and safeguarding notes for 35 learners is emailed to the wrong external organisation.
- What containment actions should be attempted immediately?
- What factors increase the risk?
- What evidence should be preserved?
- Is ICO notification likely to be required? Explain your provisional view.
- Could the learners face a high risk requiring direct communication?
- What corrective actions would reduce recurrence?
Open the answer guidance
Risk is elevated by the nature of safeguarding information, possible vulnerability of learners, identifiers, the external recipient and potential misuse. The organisation should urgently contact the recipient, request secure deletion and confirmation, preserve evidence and escalate.
A formal risk assessment is required. ICO notification is likely to need serious consideration and may be required. Communication to affected people depends on the assessed high-risk threshold and available protective measures.
Official reference points
Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.
1.3. 4.3 Data protection complaints
4.3 Data protection complaints
The current legal process for complaints about personal-data handling.
Requirements in force from 19 June 2026
Organisations must:
- give people a way to make a data protection complaint;
- acknowledge receipt within 30 days;
- take appropriate steps to respond without undue delay, including making appropriate enquiries;
- keep the complainant informed about progress; and
- tell the person the outcome without undue delay.
A good complaint process
- Provide a visible and accessible route, such as an electronic form or clear email address.
- Record the complaint, date and issues.
- Acknowledge within 30 days and explain next steps.
- Investigate objectively and gather relevant evidence.
- Address connected rights requests or breach issues.
- Communicate progress where the investigation continues.
- Give a clear outcome, reasons, remedial action and escalation information.
- Use complaint trends to improve systems and training.
Knowledge checkpoint
Answer each question before opening the suggested answer.
1. When did the statutory complaints requirements come into force?
Suggested answer: 19 June 2026.
2. What is the acknowledgement period?
Suggested answer: Within 30 days of receiving the complaint, calculated under the applicable rules.
3. Must a complaint be fully resolved within 30 days?
Suggested answer: Not necessarily. The organisation must acknowledge it within 30 days, act without undue delay, keep the person informed and provide the outcome without undue delay.
Official reference points
- ICO: How to deal with data protection complaints
- ICO: New data protection complaints law now in force
- legislation.gov.uk: Data (Use and Access) Act 2025
Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.
1.4. 4.4 Capstone case study and course summary
4.4 Capstone case study and course summary
Apply all four sections to one complex organisational scenario.
Case study: Northbridge Training
Northbridge Training introduces an online learner-support platform. It collects identity data, attendance, device identifiers, welfare notes and predicted risk scores. All tutors can see every record. Data is retained indefinitely. The supplier uses subcontractors outside the UK. A learner asks for copies of their data and complains that an inaccurate risk score affected a placement decision. During the investigation, a tutor sends welfare notes to the wrong employer.
Your task
- Identify the categories of personal data, including any special category data.
- Identify the controller, processor and possible sub-processors.
- Apply all seven principles and identify weaknesses.
- Identify the lawful-basis and Article 9 questions that must be answered.
- Explain why a DPIA is likely to be required.
- Plan the response to the learner's access request and rectification concern.
- Plan the response to the complaint under the current complaints requirements.
- Plan the response to the email breach, including risk assessment and notifications.
- Recommend at least eight corrective controls.
Open the model analysis
Data and roles: Identity, attendance and device data are personal data. Welfare notes and health-related information may be special category data. Northbridge is likely a controller; the platform supplier may be a processor, with overseas sub-processors.
Principles: Risks include excessive access, indefinite retention, possible inaccuracy, opaque profiling, weak transparency, insufficient security and poor accountability.
Lawfulness and risk: Northbridge must document an Article 6 basis for each purpose and an Article 9 condition for relevant welfare or health data. Profiling, vulnerable learners, special category data and significant decisions make a DPIA likely.
Rights and complaint: The learner's message may contain access, rectification, objection or automated-decision issues as well as a complaint. Each should be logged, investigated and handled under the relevant process.
Breach: The welfare-note disclosure requires immediate containment, evidence preservation and a documented risk assessment. ICO and individual notification thresholds must be considered promptly.
Controls: Role-based access, minimum fields, retention limits, privacy notices, human review, accuracy challenge routes, processor and sub-processor controls, transfer safeguards, staff training, incident playbooks, audit logs and periodic review.
Course summary
- Use personal data for clear and justified purposes.
- Apply all seven principles and select an appropriate lawful basis.
- Add Article 9 or criminal-offence safeguards where required.
- Make rights easy to exercise and maintain a reliable response process.
- Build privacy, security and retention into systems from the start.
- Escalate breaches immediately and document decisions.
- Acknowledge complaints within 30 days and respond without undue delay.
Official reference points
- ICO: UK GDPR guidance and resources
- ICO: Personal data breaches
- ICO: How to deal with data protection complaints
- ICO: Data protection impact assessments
Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.