Personal data breach procedure
How a personal data breach is recognised, assessed against the notification thresholds, notified to the authority within 72 hours and to the people affected, and recorded.
How the register reads it
| Also called | breach notification procedure, privacy breach procedure |
|---|---|
| Family | Privacy |
| Document type | Procedure. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Expected owner | The data protection officer or privacy lead. |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | GDPR or ISO 27701 is ticked and no line resolves to it. |
| Template | Data breach notification procedure. |
Which standards require it, and what each expects it to contain
3 requiring clauses, 2 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
ISO/IEC 27701:2025
ISO 27701 A.3.12 Response to information security incidentsFor a PII controller, an incident that involves PII shall trigger a review to determine whether a breach involving PII requiring a response has occurred, an event alone not necessarily triggering it; when a breach has occurred the response shall include the relevant notifications and records, jurisdictions defining when the supervisory authority and PII principals must be notified, and a record with sufficient information for regulatory or forensic reporting shall be kept covering the incident, the period, the consequences, the reporter, to whom it was reported, the resolution steps and data recovered, whether it caused unavailability, loss, disclosure or alteration of PII, the PII compromised, and the notifications made. For a PII processor, the contract with the customer shall cover breach notification, how the organization will provide the information the customer needs to notify authorities, the exclusion of breaches caused by the customer or PII principal or within components they are responsible for, and the expected and externally mandated limits on notification response times; some jurisdictions require the processor to notify the controller without undue delay and some require direct notification of a regulatory authority.
Common gap: Incidents closed as security events with no PII breach determination
Source: ISO/IEC 27701:2025
GDPR (Regulation (EU) 2016/679)
GDPR Art. 33 Notification of a personal data breach to the supervisory authorityOn becoming aware of a personal data breach, notify it to the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons; a notification made later than 72 hours must be accompanied by the reasons for the delay. A processor must notify its controller without undue delay after becoming aware of a breach. The notification must at least describe the nature of the breach including, where possible, the categories and approximate number of data subjects and of personal data records concerned, give the name and contact details of the data protection officer or other contact point, describe the likely consequences, and describe the measures taken or proposed including any measures to mitigate adverse effects. Information may be provided in phases where it cannot all be given at once. Document every personal data breach, including the facts, its effects and the remedial action taken, so the supervisory authority can verify compliance with this Article.
Common gap: The awareness clock started at the end of the investigation rather than at the point of reasonable certainty that a breach had occurred
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 34 Communication of a personal data breach to the data subjectWhere a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, communicate the breach to the affected data subjects without undue delay, describing in clear and plain language the nature of the breach and giving at least the contact point, the likely consequences and the measures taken or proposed including mitigation. Communication is not required where the controller had implemented appropriate technical and organisational protection measures and applied them to the affected data, in particular measures such as encryption rendering the data unintelligible to anyone unauthorised, where the controller has since taken measures making the high risk no longer likely to materialise, or where individual communication would involve disproportionate effort, in which case a public communication or similar equally effective measure must be made instead. The supervisory authority may require communication or decide that one of the exemptions applies.
Common gap: Communication deferred until the investigation completes, when the Article requires it without undue delay once high risk is identified
Source: GDPR (Regulation (EU) 2016/679)
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a register