When personal data is lost, disclosed or accessed without authority, the UK GDPR gives you a short window to act. This form logs the breach, the containment action, the review of cause and whether it has to be reported, so nothing is missed under pressure.
This form template is supplied in fully editable MS Word format and can be easily customised and edited. The document uses pre-defined style formatting throughout, with all text in Calibri font for improved readability.
The following document labelling is included in the footer:
- Form number and title
- Information-classification
- Version
- Page number / total pages
alphaZ documents - beautifully designed, tried and tested form templates. No junk, jargon or unnecessary fields. Simple and usable form templates
developed over 25 years through practical use in the real world. No AI generated nonsense here!
Further guidance on personal data breaches and data protection:
Download this form template with your company name and logo already added!
Document Preparation available with all document toolkits.
To get access to this file please click on Add to Cart to purchase for immediate download. If you have an alphaZ Subscription just click on Download Files to view all the files available to download. This form is also included in the GDPR & Data Protection Toolkit and every alphaZ ISO toolkit that covers information security and data protection, so the toolkit route gives you this file plus everything else you need in one download.
If you'd like hands-on help setting up your data breach reporting process, or your wider information security management system, our remote support services provide direct expert input from our team, by the day, by project, or on an ongoing basis.
Personal Data Breach Form Template
A personal data breach form for recording a breach from the moment it is discovered - what happened, the immediate containment action, a review of the risk and cause, whether it has to be reported, and the final check that the matter is resolved and closed.
The UK GDPR and the Data Protection Act 2018 require personal data breaches to be recorded, and reportable breaches to be notified to the ICO without undue delay and, where feasible, within 72 hours. This form gives you a consistent way to capture and work a breach through to closure and to evidence that you handled it properly.
Built for the UK GDPR Breach Duties
The form takes a breach through the stages the regulation expects:
- Breach details and immediate containment action to limit the damage
- A review of the breach, its cause, a risk rating and any corrective action
- An assessment of reporting requirements and a record of any notification to the ICO or data subjects
- A final review confirming the action taken was effective and the issue is closed
What's Included in this Personal Data Breach Form
The form is set out in three sections so a breach can be logged, reviewed and closed in one place:
- A. Breach Details and Containment Action - logged by and date, details of the breach and the containment action taken
- B. Review and Reporting - responsibility, a breach risk rating, a review of the breach, cause and action, reporting requirements and any reporting action and communications
- C. Final Review - reviewed by and date, verification that corrective action has been effective, any further action required and the date the issue was closed
Who Needs a Personal Data Breach Form?
Any organisation that holds personal data can suffer a breach - a lost laptop, a misdirected email, a ransomware attack - and has to record it and decide whether to report it. A simple, repeatable form matters most for smaller businesses without a dedicated data protection team, and for anyone maintaining data protection compliance or an information security management system aligned with ISO 27001.
Included in the GDPR & Data Protection Toolkit
This form is part of the GDPR & Data Protection Toolkit - the registers, forms, policies and guidance for documenting how you collect and process personal data in one download - and is included in the alphaZ ISO 27001 Toolkit for information security.
Pairs with the Data Protection Compliance Checklist
To check your wider data protection arrangements are in order rather than just react to a breach, the F-Q106 Personal Data Protection Compliance Checklist reviews your processing records, policies, training, security and breach procedures against the UK GDPR.