Data Breach Notification Policy

Open Legal LibraryUpdated 7 Feb 2026

This template sets out the organisation’s process for identifying, managing, recording, and reporting personal data breaches in compliance with the UK GDPR and the Data Protection Act 2018. It explains staff responsibilities, internal escalation, and when and how breaches must be notified to the ICO and affected individuals.

Data Breach Notification Policy

Purpose and Scope

This policy sets out [company name]’s approach to identifying, managing, recording, reporting and responding to personal data breaches in accordance with the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.

It applies to all employees, directors, contractors, agents, advisers, and other third parties acting on behalf of [company name] who process or have access to personal data held by the organisation.

Definitions

Personal Data: Any information relating to an identifiable individual.

Personal Data Breach: A breach of security which leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This includes, but is not limited to, loss of data or devices, system hacks, unauthorised access, disclosure to incorrect recipients, or the accidental publication of personal data.

Responsibilities

Data Protection Officer (DPO) or other designated data protection lead: Oversees breach management, reporting to the ICO and affected individuals as required. [company name]'s DPO can be contacted at [insert dpo or data protection contact details].

Employees and Contractors: Must report all actual or suspected data breaches to the DPO immediately.

If applicable:

Breach Management Team: Provides support to assess and contain breaches.

Reporting a Breach

Internal Reporting

All individuals must report any actual or potential data breach to the DPO without undue delay, and no later than 24 hours after becoming aware of it, regardless of perceived severity.

Third-Party Reporting

Processors acting on behalf of the organisation are required to notify the organisation without undue delay after becoming aware of a personal data breach. If a third party (such as a processor) notifies us of a breach affecting the organisation’s personal data, we will treat this as an internal report and follow the same procedure.

Assessment and Investigation

Upon notification, the DPO (or designated lead) will:

Confirm whether a personal data breach has occurred.

Assess the nature, scope and likely impact of the breach.

Contain and recover personal data, where possible.

Determine whether the breach is notifiable to the Information Commissioner’s Office (“ICO”) and/or affected individuals.

This assessment will include consideration of the likelihood of harm to individuals’ rights and freedoms. Serious or high-risk breaches may be escalated to senior management and, where appropriate, the board of directors.

Notification to the Information Commissioner’s Office

A breach that is likely to result in a risk to individuals’ rights and freedoms must be reported to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. If the organisation cannot provide all required information within 72 hours, it will submit what it can and provide the remainder as soon as possible.

Note: For the purposes of this policy, the organisation is considered “aware” of a personal data breach when it has a reasonable degree of certainty that a security incident has occurred that has led to personal data being compromised.

Notification to the ICO will include:

This is a preview. The full template is free on GitLaw.

5.0 out of 5 on Google

Read reviews

As seen in

Law360
Artificial Lawyer
Insider
Axios Pro
San Francisco Business Times
Built In
Startups Magazine
Business Reporter
Tech.eu

England & Wales note

This version is drafted for England & Wales. Scotland and Northern Ireland differ on some points — for example notice periods and tribunal procedure. Tell GitLaw where you hire and it adjusts the draft.

Jurisdiction
England & Wales
Document info
HTML document. Document created on Sat Feb 7th, 2026. Last updated on Sat Feb 7th, 2026.
This document is public
Licensed under CC BY 4.0 (Attribution).
Come to agreements faster
Write, review, negotiate, and manage legal contracts
Related documents
Denmark
Privacy Policy (Denmark) by Seedsummit
This internal data protection policy establishes how a company manages personal information in compliance with the EU General Data Protection Regulation. It defines processing principles such as data minimization and storage limitation, and outlines the responsibilities of a designated IT systems administrator in Denmark.
Updated 13 Aug 2026
European Union
Content Moderation Practices by Mozilla
This document outlines how an organization manages content moderation for user-generated text, images, and software applications. It specifies the human-led review process for reports of illegal or policy-violating content and the subsequent appeals procedure for both reporters and account holders.
Updated 13 Aug 2026
US
About Your Rights by Mozilla
This notice informs users of their rights under a free and open source software license, specifically allowing for the use, modification, and distribution of the source code. It includes placeholders for the software name, company name, and a direct link to the applicable privacy policy.
Updated 13 Aug 2026
England & Wales
Firefox Focus and Firefox Klar Privacy Notice by Mozilla
This privacy notice explains how a browser developer processes technical, interaction, and browsing data. It details user rights under data protection laws and provides options for managing data collection and search preferences.
Updated 13 Aug 2026
England & Wales
Data Protection Addendum (DPA)
This data protection addendum establishes the legal framework for processing personal data in connection with a cloud services agreement. It defines the roles of Controller and Processor while setting out specific obligations for subprocessor management, security incident response, and cross-border data transfers.
Updated 13 Aug 2026
US
VPN Privacy Notice by Mozilla
This privacy notice explains how a VPN service handles user data, encryption, and third-party sharing. It details the collection of account info, approximate location via IP address, and limited billing details from providers like Stripe or Apple.
Updated 13 Aug 2026

Frequently asked questions

A template isn't binding on its own - like any contract, it becomes binding once it's properly completed and signed. Templates in our curated library are professionally drafted for US or UK law; review any template before you sign it.

Yes. Chat with GitLaw to edit any section, or make changes directly in the editor.

Yes, read about team plans here.

Describe what you need in the chat and GitLaw will draft it for you.

Templates in our curated library are professionally drafted for US or UK law. The wider library comes from the GitLaw community and public sources - a solid starting point, but check any template fits your situation before you rely on it.

Mostly US and UK law. Some templates use general commercial terms that work across jurisdictions, and many note which law they're written for.

It depends on the situation. Templates work well for routine business agreements. For anything involving significant money, complex IP, employment, or areas you're unsure about, it's worth getting professional advice before you sign. GitLaw provides templates and tools, not legal advice.

Open any template in GitLaw and describe the change you want in the chat — 'make clause 4 mutual' or 'add a 30-day notice period', for example. GitLaw drafts the revised language and shows it as a suggested edit. You accept, reject, or keep editing from there.

Yes. Upload a Word, PDF, or Markdown file and GitLaw will open it in the editor. You can review, edit, or chat with GitLaw about it the same way you would with any template from the library.

Trusted by 5,000+ businesses

Nexus logoMlabs logoTechstars logo

From template to signed, in one place

Every template opens in an editor with an AI agent alongside it.

1

Open

Pick a template and open it. Nothing to download, and no credit card to start.

Free to open

2

Edit with AI

Describe your situation in chat and the agent adapts the wording, clause by clause.

Tracked changes you can review

3

Send and sign

Share it for negotiation, then collect signatures without leaving GitLaw.

eSign included

Built for your legal work,
with practicing lawyers

Trained on 5,500+ clauses and specialist areas of law. Built with a standards committee of independent lawyers.

As seen in

Law360
Artificial Lawyer
Insider
Axios Pro
San Francisco Business Times
Built In
Startups Magazine
Business Reporter
Tech.eu

Ready to get started?

No sales calls, no credit card. Just chat with GitLaw.

GitLaw provides templates and tools, not legal advice. Templates are a starting point, not a substitute for advice on your situation - for anything significant, speak to a qualified lawyer.