Just a moment
Compliance

The first 24 hours of a data breach

A lost phone, a misdirected email or a stolen laptop starts a 72 hour clock. Knowing the order of the first few steps is the difference between an incident and a crisis.

The Youzse team26 May 20264 min read

Most personal data breaches in small businesses are not hacks. They are a phone left in a taxi, a client list emailed to the wrong address, a laptop taken from a car or a member of staff who left with a copy of everything.

All of them start the same clock, and the businesses that handle it well are the ones that decided the order of the first few steps before anything happened.

This is a practical summary rather than legal advice. Where the stakes are high, get proper advice quickly.

What actually counts

A personal data breach is any security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data. Losing it counts. Deleting it by accident with no backup counts. Somebody inside the business looking at records they had no reason to see counts.

It does not require malice and it does not require a criminal. That is the part people get wrong, usually while deciding something was "not really a breach" and therefore not worth writing down.

The 72 hour clock

If a breach is likely to risk people's rights and freedoms, it has to be reported to the ICO within 72 hours of you becoming aware of it. Not 72 working hours. If it also poses a high risk to those individuals, they have to be told directly, without undue delay.

The clock starts at awareness, which means the moment somebody in the business knew, not the moment it reached the owner. That is a strong argument for staff knowing they must report immediately and never being punished for doing so.

The order to work in

  1. 1Contain it. Change the password, revoke the session, remotely wipe the device, recall the message, lock the account. Stop the bleeding before you analyse it.
  2. 2Find out what data and whose. Categories of data, roughly how many people and whether anything sensitive is involved. An approximate answer now is worth more than a precise one on Friday.
  3. 3Assess the risk to those people. Could this lead to fraud, distress, identity theft or physical harm? A list of first names is not the same as a list of home addresses with medical notes attached.
  4. 4Decide on reporting, and record the decision either way. If you decide not to report, write down why. That reasoning is what you will be asked for.
  5. 5Tell the people affected if the risk to them is high. Plainly, quickly, with what happened and what they should do.
  6. 6Fix the cause rather than the instance. A lost phone is a symptom. No screen lock and no remote wipe is the cause.

Write it down as you go

Every breach must be recorded internally, including the ones you decide not to report. Time it happened, time you found out, what data, how many people, what you did, what you decided and why.

That record is the single most useful thing you can produce if anybody asks later, and it takes ten minutes at the time and half a day to reconstruct afterwards.

The preparation that makes all of this easy

  • Know now who makes the call. In a small business it is the owner, and they should know that today rather than on the day.
  • Have the ICO reporting route to hand, along with anything you would need to log in to your own systems from somewhere else.
  • Make sure every device with client data on it has a screen lock, encryption and a remote wipe you have tested once.
  • Limit what each person can see. A breach of one account is only as bad as what that account could reach.
  • Tell staff that reporting a mistake immediately is the expected behaviour. A culture where people hide an error for a day is the only reliable way to miss the deadline.

The version to remember

Contain, assess, record, report if it warrants it, tell people if the risk to them is high, then fix the underlying cause. The mistake that turns an incident into a serious problem is nearly always hesitation rather than the breach itself.

Topics

GdprData breachIco

We value your privacy

Cookies keep Youzse running, improve the platform and help deliver relevant content. Read our privacy policy and cookie policy.