Learning 4 - Security, breaches and complaints
1. Section 4: Security, breaches and complaints
1.2. 4.2 Responding to a personal data breach
4.2 Responding to a personal data breach
Containment, risk assessment, notification, recovery and evidence.
Immediate response
- Escalate: notify the organisation's incident or data protection contact immediately.
- Contain: stop further disclosure, revoke links, retrieve information where possible and secure affected systems.
- Preserve evidence: retain logs, messages, timestamps and actions.
- Assess: identify the data, people, scale, protections and likely consequences.
- Decide notifications: consider the ICO, affected people, processors, insurers, law enforcement and contractual contacts.
- Recover and learn: restore services, reduce harm, address root causes and monitor corrective actions.
ICO notification
If the breach is likely to result in a risk to people's rights and freedoms, the controller must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it.
Telling affected people
If the breach is likely to result in a high risk, affected people normally need to be informed without undue delay in clear language, including the likely consequences and measures taken.
Internal records
Controllers must document breaches, facts, effects and remedial action so the ICO can verify compliance. This applies even where the ICO is not notified.
Activity: Risk-assess an email breach
A spreadsheet containing names, addresses, dates of birth and safeguarding notes for 35 learners is emailed to the wrong external organisation.
- What containment actions should be attempted immediately?
- What factors increase the risk?
- What evidence should be preserved?
- Is ICO notification likely to be required? Explain your provisional view.
- Could the learners face a high risk requiring direct communication?
- What corrective actions would reduce recurrence?
Open the answer guidance
Risk is elevated by the nature of safeguarding information, possible vulnerability of learners, identifiers, the external recipient and potential misuse. The organisation should urgently contact the recipient, request secure deletion and confirmation, preserve evidence and escalate.
A formal risk assessment is required. ICO notification is likely to need serious consideration and may be required. Communication to affected people depends on the assessed high-risk threshold and available protective measures.
Official reference points
Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.