When personal data is lost, sent to the wrong person or accessed without authority, the facts needed to decide whether to report it have to be gathered quickly. This form asks for them in the order you need them, from what happened through to closure.
This form template is supplied in fully editable MS Word format and can be easily customised and edited. The document uses pre-defined style formatting throughout, with all text in Calibri font for improved readability.
The following document labelling is included in the footer:
- Form number and title
- Information-classification
- Version
- Page number / total pages
alphaZ documents - beautifully designed, tried and tested form templates. No junk, jargon or unnecessary content. Simple and usable form templates
developed over 25 years through practical use in the real world.
Further guidance on personal data breaches:
Download this form template with your company name and logo already added!
Document Preparation available with all document toolkits.
To get access to this file please click on Add to Cart to purchase for immediate download. If you have an alphaZ Subscription just click on Download Files to view all the files available to download. This form is also included in the GDPR / Data Protection Toolkit and the ISO 22458 toolkit and the integrated toolkits that include it, so the toolkit route gives you this file plus everything else you need in one download.
If you'd like hands-on help setting up your data breach reporting process, our remote support services provide direct expert input from our team, by the day, by project, or on an ongoing basis.
Personal Data Breach Form Template
A personal data breach form for recording a breach from the moment it is discovered through to closure - what happened and when, the containment action, the review of the risk and cause, the decision on reporting, and the final check that the action taken worked.
What's Included in this Form
- A. Breach Details and Containment Action - logged by and date, when the breach occurred and when it was discovered, details of the breach and the containment action taken
- B. Review and Reporting - responsibility, a low, medium or high risk rating, the review of cause and action, the categories of personal data involved, the people affected and approximate numbers, the records involved, whether and when the ICO and the people affected were told, and the reporting requirements and communications
- C. Final Review - reviewed by and date, verification that corrective action has been effective, any further action and the date closed
The form is marked Confidential.
Who Needs a Personal Data Breach Form?
Any organisation that holds personal data. Every breach should be recorded, whether or not it has to be reported, and a consistent form makes that record complete.
Included in the GDPR / Data Protection Toolkit
This form is part of the GDPR / Data Protection Toolkit - the registers, forms, policies, procedure and guidance for documenting how you collect and process personal data, in one download, and is also included in the ISO 22458 toolkit.
Works with the Data Breach Policy
The P-92 Data Breach Policy states the organisation's approach to breaches, and the PP-1-16 Data Protection Policy Procedure sets out the full process. This form is the record of each breach.
Using the Form
Start the form as soon as a breach is discovered and complete section A straight away. Complete section B once the facts are known, including the decision on reporting and the reason for it, and close the breach in section C once the corrective action has been checked.
Deciding Whether to Report
The categories of personal data, the people affected and the number of records are the facts needed to judge the risk. The form asks for them together, so the reporting decision is made on the right information and recorded with the date any notification was made.
Learning from Breaches
The final review checks the corrective action worked. Reviewing completed forms together can show recurring causes, such as emails sent to the wrong person or information entered into AI tools that have not been approved.
Related Documents
Other documents in the GDPR / Data Protection Toolkit that work alongside this one:
Keeping the Record
Keep the completed form even when the breach was not reportable. The record shows the breach was taken seriously and explains the decision if it is questioned later.
Would you rather we prepared it for you?
Our Personal Data Register and Privacy Notice Preparation service works through the personal data your organisation holds with you, including the AI tools in use, and prepares the register and privacy notice so they describe what actually happens to that data.
Personal Data Register and Privacy Notice Preparation