Your Data Breach Response Plan in 5 Steps
Under UK GDPR you must report a personal-data breach to the ICO within 72 hours of becoming aware of it — but only if you've identified it in the first place. Most businesses lose those 72 hours fumbling because they never planned ahead. Here's the response plan every business should have written down before it needs it.
Step 1 — Contain
Stop the bleeding first. Disconnect the affected system, revoke compromised credentials, and take the affected service offline if needed. Your priority is limiting further exposure, not investigating — that comes after.
Step 2 — Assess
Work out exactly what happened, what data was affected, how many people, and what the likely impact is. This determines both whether you must notify the ICO and whether you must tell the individuals affected (you must tell individuals when there's a high risk to their rights and freedoms).
Step 3 — Notify
Report to the ICO within 72 hours if the breach poses a risk. Document everything: what, when, who, what you've done. If you miss the 72-hour window, explain why.
Step 4 — Remediate
Fix the root cause so it can't recur — patch the vulnerability, rotate credentials, tighten access. Remediation is what separates a one-off incident from a pattern.
Step 5 — Learn
Hold a short post-incident review, update your risk register and your response plan, and train staff on what they should have done differently.
Data Breach Response Kit
A ready-to-go response kit: notification templates, an ICO reporting checklist and a step-by-step runbook so you're never scrambling in hour one.
Get it nowThis guide is general information, not legal advice. Reporting obligations vary by case — seek professional guidance for a live incident.