P-92 Data Breach Policy
File Reference : P-92 Data Breach Policy
Date File Updated 14-09-26
File Format MS Word
No. of files 1
Category Policies
Tags: ISO 27001, UK GDPR, data breach, personal data breach, ICO, data protection
  • £2.50

  or  

Login to Download


When a breach happens people need to know straight away that it has to be reported internally, and what the organisation will do next. This policy says that plainly, and tells anyone affected what to expect.

Effective Policy Templates

This policy template is supplied in fully editable MS Word format and can be easily customised and edited. The document uses pre-defined style formatting throughout, with all text in Calibri font for improved readability.
The following document labelling is included in the footer:

  • Policy number and title
  • Information-classification
  • Version
  • Page number / total pages
alphaZ documents - beautifully designed, tried and tested policy templates. No junk, jargon or unnecessary content. Simple and usable policy templates developed over 25 years through practical use in the real world.
Document Preparation
Logo Update Service *

Download this policy template with your company name and logo already added!
Document Preparation available with all document toolkits.

How to Download

To get access to this file please click on Add to Cart to purchase for immediate download. If you have an alphaZ Subscription just click on Download Files to view all the files available to download. This policy is also included in the GDPR / Data Protection Toolkit and the ISO 27001 toolkit and the integrated toolkits that include it, so the toolkit route gives you this file plus everything else you need in one download.

Implementation Support
Need Help Implementing?

If you'd like hands-on help setting up your data breach process and personal data records, our remote support services provide direct expert input from our team, by the day, by project, or on an ongoing basis.

File Formats

Data Breach Policy Template

A public data breach policy for stating how your organisation prevents, responds to and learns from a personal data breach. It explains what counts as a breach, the duty to report one internally, the steps taken to contain and assess it, when the regulator and the people affected are told, and how breaches are recorded.

What the Policy Covers

  • Our commitment - protecting personal data and acting quickly when something goes wrong
  • What counts as a data breach - loss, disclosure, unauthorised access or alteration, including through AI tools
  • Reporting a breach - reporting straight away, whoever finds it
  • What we do - contain, assess the risk, notify where required and put things right
  • If your personal data is affected - what people will be told and when
  • Records and learning - every breach recorded and reviewed, reportable or not

An Optional Standalone Policy

The PP-1-16 Data Protection Policy Procedure already contains the data breach content in its section Data Breach Procedure (Data Breach Policy), so a company using the procedure does not need this separate file. It is here for organisations that want a standalone, publicly shareable policy on this one subject - to give to a customer or answer a questionnaire, for example. Where both are used, make sure the policy says the same as the procedure.

Who Needs a Data Breach Policy?

Any organisation that holds personal data. It is often asked for in supplier due diligence alongside the data protection policy, and it gives staff a clear statement that breaches are to be reported rather than hidden.

Included in the GDPR / Data Protection Toolkit

This policy is part of the GDPR / Data Protection Toolkit - the registers, forms, policies, procedure and guidance for documenting how you collect and process personal data, in one download, and is also included in the ISO 27001 toolkit.

Works with the Personal Data Breach Form

Each breach is recorded and worked through to closure on the F-Q74 Personal Data Breach Form, which captures what happened, the people and records affected, the risk rating and any notification made.

Using the Policy

Add your company details and approval, and use the yellow prompt to refer to your incident or problems procedure if you have one. Share the policy with staff so everyone knows a breach must be reported straight away.

Breaches Involving AI Tools

Personal data entered into an AI tool that has not been approved, or an AI tool that exposes information it should not, can be a data breach. The policy includes these in what counts as a breach, so they are reported and assessed like any other.

Recording Every Breach

Not every breach has to be reported to the regulator, but every one should be recorded with the decision made and the reason, so patterns can be spotted and the decision can be explained later.

Related Documents

Other documents in the GDPR / Data Protection Toolkit that work alongside this one:

Would you rather we prepared it for you?

Our Personal Data Register and Privacy Notice Preparation service works through the personal data your organisation holds with you, including the AI tools in use, and prepares the register and privacy notice so they describe what actually happens to that data.

Personal Data Register and Privacy Notice Preparation

There are currently no comments for this document.

Add a Comment

Please Login or Subscribe to add Comments.