This module explains what constitutes a data breach, the steps to take if a breach occurs, and the reporting obligations under GDPR.
Determine what happened, what data was affected, and who might be impacted
Take immediate steps to limit the damage and prevent further data loss
Evaluate the severity of the breach and potential impact on affected individuals
Notify the ICO and affected individuals as required by GDPR
A data breach occurs when personal data is accidentally or unlawfully destroyed, lost, altered, disclosed, or accessed without authorization. Examples include:
Under GDPR, organizations have specific reporting obligations in the event of a data breach:
Inform your Data Protection Officer or supervisor immediately after discovering a breach
If the breach poses a risk to individuals' rights, report to the ICO within 72 hours
If the breach poses a high risk to individuals, notify them without undue delay