Learning 4 - Security, breaches and complaints

Site: MyStudentSite Moodle
Course: UK Data Protection Interactive SCORM
Book: Learning 4 - Security, breaches and complaints
Printed by: Guest user
Date: Tuesday, 4 August 2026, 11:48 PM

1. Section 4: Security, breaches and complaints

UK data protection learning

Section 4: Security, breaches and complaints

Protecting data, handling incidents and responding to people effectively.

Learning outcomes

By the end of this section, you should be able to:

  • explain the integrity and confidentiality principle;
  • identify a personal data breach;
  • apply a structured breach response and risk assessment;
  • explain the 72-hour ICO notification rule;
  • describe the complaint-handling duties in force from 19 June 2026; and
  • apply the full course to a realistic incident.

Security failures and poor complaint handling can turn manageable problems into serious harm. Staff should know how to recognise, contain, record and escalate concerns immediately.


Official reference points

Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.

1.1. 4.1 Security and personal data breaches

UK data protection learning

4.1 Security and personal data breaches

Recognising security measures and different forms of breach.

Appropriate security

The UK GDPR requires appropriate technical and organisational measures. “Appropriate” depends on risk, context, cost, current technology and the nature of the data.

Technical measuresOrganisational measures
Multi-factor authentication, encryption, patching, backups, logging, network controls, secure configuration, malware protection and tested recovery. Policies, training, access reviews, supplier management, incident plans, clear roles, secure disposal, physical security and auditing.

What is a personal data breach?

It is a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.

Confidentiality breach: data is disclosed to or accessed by an unauthorised person.
Integrity breach: personal data is changed incorrectly or without authorisation.
Availability breach: personal data is lost, destroyed or made unavailable.
A cyberattack is not required. Sending an email to the wrong person, losing an unencrypted device or accidentally deleting records can all be personal data breaches.

Knowledge checkpoint

Answer each question before opening the suggested answer.

1. A spreadsheet is sent to the wrong external recipient. Is this potentially a breach?

Suggested answer: Yes. It may be an unauthorised disclosure.

2. A system encrypts its own database after a ransomware attack. Which aspects may be affected?

Suggested answer: Availability and potentially confidentiality and integrity.

3. Does every personal data breach have to be reported to the ICO?

Suggested answer: No. The reporting threshold depends on risk, but every breach should be assessed and documented.


Official reference points

Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.

1.2. 4.2 Responding to a personal data breach

UK data protection learning

4.2 Responding to a personal data breach

Containment, risk assessment, notification, recovery and evidence.

Immediate response

  1. Escalate: notify the organisation's incident or data protection contact immediately.
  2. Contain: stop further disclosure, revoke links, retrieve information where possible and secure affected systems.
  3. Preserve evidence: retain logs, messages, timestamps and actions.
  4. Assess: identify the data, people, scale, protections and likely consequences.
  5. Decide notifications: consider the ICO, affected people, processors, insurers, law enforcement and contractual contacts.
  6. Recover and learn: restore services, reduce harm, address root causes and monitor corrective actions.

ICO notification

If the breach is likely to result in a risk to people's rights and freedoms, the controller must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it.

The 72 hours is not a waiting period. Work starts immediately. If all information is not yet available, an initial report may be supplemented in phases.

Telling affected people

If the breach is likely to result in a high risk, affected people normally need to be informed without undue delay in clear language, including the likely consequences and measures taken.

Internal records

Controllers must document breaches, facts, effects and remedial action so the ICO can verify compliance. This applies even where the ICO is not notified.

Activity: Risk-assess an email breach

A spreadsheet containing names, addresses, dates of birth and safeguarding notes for 35 learners is emailed to the wrong external organisation.

  1. What containment actions should be attempted immediately?
  2. What factors increase the risk?
  3. What evidence should be preserved?
  4. Is ICO notification likely to be required? Explain your provisional view.
  5. Could the learners face a high risk requiring direct communication?
  6. What corrective actions would reduce recurrence?
Open the answer guidance

Risk is elevated by the nature of safeguarding information, possible vulnerability of learners, identifiers, the external recipient and potential misuse. The organisation should urgently contact the recipient, request secure deletion and confirmation, preserve evidence and escalate.

A formal risk assessment is required. ICO notification is likely to need serious consideration and may be required. Communication to affected people depends on the assessed high-risk threshold and available protective measures.


Official reference points

Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.

1.3. 4.3 Data protection complaints

UK data protection learning

4.3 Data protection complaints

The current legal process for complaints about personal-data handling.

Requirements in force from 19 June 2026

Organisations must:

  • give people a way to make a data protection complaint;
  • acknowledge receipt within 30 days;
  • take appropriate steps to respond without undue delay, including making appropriate enquiries;
  • keep the complainant informed about progress; and
  • tell the person the outcome without undue delay.
Thirty days is the acknowledgement deadline. It is not automatically the deadline for resolving every complaint, but the organisation must act without undue delay and keep the person informed.

A good complaint process

  1. Provide a visible and accessible route, such as an electronic form or clear email address.
  2. Record the complaint, date and issues.
  3. Acknowledge within 30 days and explain next steps.
  4. Investigate objectively and gather relevant evidence.
  5. Address connected rights requests or breach issues.
  6. Communicate progress where the investigation continues.
  7. Give a clear outcome, reasons, remedial action and escalation information.
  8. Use complaint trends to improve systems and training.

Knowledge checkpoint

Answer each question before opening the suggested answer.

1. When did the statutory complaints requirements come into force?

Suggested answer: 19 June 2026.

2. What is the acknowledgement period?

Suggested answer: Within 30 days of receiving the complaint, calculated under the applicable rules.

3. Must a complaint be fully resolved within 30 days?

Suggested answer: Not necessarily. The organisation must acknowledge it within 30 days, act without undue delay, keep the person informed and provide the outcome without undue delay.


Official reference points

Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.

1.4. 4.4 Capstone case study and course summary

UK data protection learning

4.4 Capstone case study and course summary

Apply all four sections to one complex organisational scenario.

Case study: Northbridge Training

Northbridge Training introduces an online learner-support platform. It collects identity data, attendance, device identifiers, welfare notes and predicted risk scores. All tutors can see every record. Data is retained indefinitely. The supplier uses subcontractors outside the UK. A learner asks for copies of their data and complains that an inaccurate risk score affected a placement decision. During the investigation, a tutor sends welfare notes to the wrong employer.

Your task

  1. Identify the categories of personal data, including any special category data.
  2. Identify the controller, processor and possible sub-processors.
  3. Apply all seven principles and identify weaknesses.
  4. Identify the lawful-basis and Article 9 questions that must be answered.
  5. Explain why a DPIA is likely to be required.
  6. Plan the response to the learner's access request and rectification concern.
  7. Plan the response to the complaint under the current complaints requirements.
  8. Plan the response to the email breach, including risk assessment and notifications.
  9. Recommend at least eight corrective controls.
Open the model analysis

Data and roles: Identity, attendance and device data are personal data. Welfare notes and health-related information may be special category data. Northbridge is likely a controller; the platform supplier may be a processor, with overseas sub-processors.

Principles: Risks include excessive access, indefinite retention, possible inaccuracy, opaque profiling, weak transparency, insufficient security and poor accountability.

Lawfulness and risk: Northbridge must document an Article 6 basis for each purpose and an Article 9 condition for relevant welfare or health data. Profiling, vulnerable learners, special category data and significant decisions make a DPIA likely.

Rights and complaint: The learner's message may contain access, rectification, objection or automated-decision issues as well as a complaint. Each should be logged, investigated and handled under the relevant process.

Breach: The welfare-note disclosure requires immediate containment, evidence preservation and a documented risk assessment. ICO and individual notification thresholds must be considered promptly.

Controls: Role-based access, minimum fields, retention limits, privacy notices, human review, accuracy challenge routes, processor and sub-processor controls, transfer safeguards, staff training, incident playbooks, audit logs and periodic review.

Course summary

  • Use personal data for clear and justified purposes.
  • Apply all seven principles and select an appropriate lawful basis.
  • Add Article 9 or criminal-offence safeguards where required.
  • Make rights easy to exercise and maintain a reliable response process.
  • Build privacy, security and retention into systems from the start.
  • Escalate breaches immediately and document decisions.
  • Acknowledge complaints within 30 days and respond without undue delay.
Next activity: Complete the separate Moodle mini test. A score of 70% or more is recommended as the pass threshold.

Official reference points

Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.