Data breach procedures: a one-page plan
What counts as a personal data breach, the notification deadlines, and a one-page procedure a small business can actually follow under pressure.
The short answer
A personal data breach is a security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. That is broader than a hacker stealing a database: a lost device, an email sent to the wrong recipient, a misconfigured storage bucket, a ransomware attack that makes data unavailable, and a former employee with access they should not have are all capable of qualifying. When you become aware of one, you must assess the risk to the people affected. You notify your supervisory authority within seventy-two hours of becoming aware, in phases if necessary, unless you can demonstrate the breach is unlikely to result in a risk to their rights and freedoms. If you notify later than seventy-two hours, the notification must state the reasons for the delay. If it is likely to result in a high risk, you must also tell the people affected without undue delay, in clear plain language, unless an exception applies such as the data being unintelligible through encryption. Whether or not you notify, every breach must be documented internally, and that register is the first thing a regulator asks to see.
The one-page procedure
| Step | What happens | Who | Timing |
|---|---|---|---|
| 1. Report | Anyone who suspects a breach tells the named contact, without fear of blame | All staff | Immediately |
| 2. Contain | Stop the exposure: revoke access, take a system offline, recall or block, change credentials | Technical lead and partner | Immediately |
| 3. Assess | What data, whose, how many, what could happen to them, is it recoverable | Named responsible person with advice | Within hours |
| 4. Decide | Can you demonstrate the breach is unlikely to result in a risk? If not, it is notifiable. Separately: is a high risk to individuals likely? | Named responsible person, documented | Before the deadline |
| 5. Notify the authority | Nature, categories and numbers, likely consequences, measures taken | Named responsible person | Within 72 hours of awareness; in phases if needed |
| 6. Inform individuals | Plain language, what happened, likely consequences, what you are doing, what they should do, a contact | Named responsible person | Without undue delay where high risk |
| 7. Record | Facts, effects, decisions, reasoning, actions | Named responsible person | Always, notified or not |
| 8. Review | Root cause, what changes, who owns it | Management | Within two weeks |
Preparing before you need it
- Name the responsible person and a deputy, with contact details known to everyone.
- Write the one-page procedure and put it somewhere reachable without the company systems.
- Know your supervisory authority and how to reach their notification form.
- Collect processor notification timelines from your agreements, so you know who tells you and how fast.
- Prepare templates: an internal report form, an authority notification skeleton, a plain-language message to affected people.
- Create the breach register now, empty.
- Tell staff what to report and to whom, and that reporting is expected rather than punished.
- Rehearse once: a tabletop walkthrough of a plausible scenario takes an hour.
Telling the people affected
When it is required, the message should be direct: what happened, when, what data was involved, what the likely consequences are, what you have done, what they should do now, and a named contact. Avoid minimising language and avoid technical detail that obscures. People are more forgiving of a breach explained honestly and quickly than of one they learn about later or in a vaguer form than the facts warranted, and regulators take the same view.
What this means for you
Know what counts as a breach, assess risk when one occurs, notify your supervisory authority within seventy-two hours of awareness where notifiable, tell affected people where the risk is high, and document every breach regardless. Prepare the one-page procedure, name the responsible person, keep processor notification timelines to hand, and rehearse once. This is general information rather than legal advice; a serious breach warrants qualified help immediately.
Frequently asked questions
Does a lost laptop count?
If it held personal data and the data was not adequately protected, yes: loss of availability or potential unauthorised access is a breach. An encrypted device with no evidence of compromise may be a breach that is unlikely to result in risk, which changes whether notification is required but not the obligation to assess and document it. The assessment and the record are required in both cases.
Does the seventy-two hours start when we discover it?
It runs from becoming aware, meaning having a reasonable degree of certainty that a security incident has occurred leading to personal data being compromised. Investigating to confirm is part of becoming aware, but a business cannot delay awareness by declining to look. If the full picture is not ready in time, notification can be made in phases, which is expressly permitted and better than missing the deadline.
Who has to notify if our supplier is breached?
The processor must notify you without undue delay; you as controller notify the supervisory authority and, where required, the people affected. That is why processing agreements specify notification timelines, and why a supplier that discovers an incident and takes a week to tell you creates a problem for you as well as themselves. Check the timeline in every agreement you sign.
Sources
- EUR-Lex: Regulation (EU) 2016/679, Articles 33 and 34 (accessed 2026-09-14)
- Autoriteit Persoonsgegevens: Data breaches (accessed 2026-09-12)