Settings

The clock

What happened

Who and what is affected

Does anyone have to be told

This is a prompt, not a decision. Whether a particular incident is reportable, and to whom, depends on where you are and what you do. What the page can do is put in front of you the things that make it more likely, and make sure the answer is written down before it is needed.

What has been done, and when

The write-up, and getting it out

What this is, and what it is not

Awareness is a moment, and it is earlier than people want it to be. The clock starts when the organisation has a reasonable degree of certainty that something has happened, not when the investigation finishes and not when it reaches the person who deals with these. A member of staff who saw it on Friday and mentioned it on Monday makes Friday the day, and the timeline here exists so that the honest version is written down while everyone still remembers it.

An incomplete report on time beats a complete one late. Where a deadline applies, it is usually possible to report what you know and follow up with the rest. Holding the report back until every fact is settled is the most common way of missing the deadline, and the follow-up was expected anyway. The page says what is not yet known rather than leaving a gap in the form.

Describe the consequence, not the category. "A risk to rights and freedoms" is a phrase from a statute, not an assessment. What matters is what somebody could actually do with what got out: open an account, reuse a password somewhere else, turn up at an address, tell an employer something private. Writing that sentence is usually what settles whether the people affected need to be told.

Encryption is the difference, when it is real. Data that got out in a form nobody can read is a different incident from data that got out readable, and that is the one place where a technical measure changes the answer. The qualification matters: the key must not have gone with it, and the protection must be current. "There was a password on the spreadsheet" is not encryption.

It stays on this machine. An incident record is the most sensitive document an organisation produces about its own worst day, and it is the one most likely to be read by somebody else later. It should not be drafted in a form that posts to a service. Export it and keep it with the incident.

Questions people ask

Where does seventy-two hours come from?

It is the reporting deadline under the UK and EU regimes, running from awareness, for breaches of personal data that are likely to result in a risk to people. Other regimes differ, and some sectors have their own shorter ones. The page counts seventy-two by default and lets you set another period.

What if I am not sure it is reportable?

Write it up anyway. An incident that turns out not to be reportable and was recorded properly costs an hour. One that was reportable and was not recorded costs considerably more, and the thing regulators ask for first is the internal record of how the decision was made.

Do I have to tell the people affected?

Usually only where there is a high risk to them, which is a higher bar than the one for reporting. The exceptions are worth knowing: it is generally not required where the data was unintelligible to whoever got it, where you have taken steps that make the risk unlikely to materialise, or where telling everyone individually would be disproportionate and a public announcement would do.

The clock has already run out. Now what?

Report it now and say why it is late. A late report is a problem; an unreported breach found by somebody else is a different order of problem. The page keeps counting past the deadline for exactly this reason rather than hiding the number.

Our supplier had the breach, not us.

If they are processing on your behalf, they tell you without undue delay and the duty to report is generally yours. Your clock starts when they tell you, which is why the day they told you and the day it happened are separate fields here.

Related tools