A data breach is any security incident that puts personal data at risk, such as data being lost, exposed or accessed by the wrong person. If one is likely to harm the people involved, it must be reported to the regulator within 72 hours.
What counts
- A device or login falling into the wrong hands
- Personal data sent to the wrong person
- Data being accessed or taken without permission
What to do straight away
- 1Contain it. Change passwords, end sessions and stop the data going any further.
- 2Assess it. What data was involved, how many people and how serious is the risk.
- 3If there is a real risk to people, report it to the ICO within 72 hours of becoming aware.
- 4If the risk is high, tell the affected people too.
How Youzse helps
You can raise an incident inside Youzse, and the platform helps you pull together what the regulator needs, with a report template populated from the details. Tools like two-factor sign-in, trusted devices and session controls help prevent incidents in the first place.
If you think something has happened
Act quickly and get in touch with the Youzse team. Moving fast is what counts.
Common questions
What counts as a breach?
Personal data lost, exposed or accessed by somebody who should not have it. A misdirected email can qualify.
How quickly must I report?
Within 72 hours of becoming aware, where the breach is likely to be a risk to people.
Who do I report to?
The ICO, and the people affected where the risk to them is high.