The Breach Response Playbook
Report, contain, assess, notify and record a personal data breach from the first hour through regulator decisions, DPO sign-off and audit-ready closure.
A practical implementation guide for running the live response and building the permanent record at the same time. Includes fillable forms, decision aids and checklists your team can use with a spreadsheet and shared drive.
A breach response and its evidence record must move together from the first hour.
A personal data breach starts a live operational response and a statutory clock. If reporting, containment, investigation and decision-making happen across inboxes and calls, the team may resolve the incident but still struggle to prove what happened, when it happened and who approved each decision.
This playbook connects the immediate response to the permanent breach register. It gives each role a clear sequence, captures the evidence behind notification decisions and closes the incident with DPO review, lessons learned and an audit-ready record.
What's inside the 26-page toolkit?
Response team and first hour
Standing RACI and contact sheet, reporting steps and a fillable internal incident form.
Containment and investigation
First 24 hours checklist plus practical evidence-preservation and chain-of-custody guidance.
Risk assessment
Fillable likelihood and severity matrix for recording the risk to affected individuals.
Notification decisions
Decision tree for regulator notification and guidance for communicating with affected individuals.
Closure and review
DPO sign-off, individual notification letter and fillable post-incident review.
Register and audit evidence
Breach register template, response-to-register workflow and audit readiness checklist.
Who is this toolkit for?
- Data protection officers
- Privacy and legal teams
- IT and security leads
- HR and communications teams
- Leadership and incident owners
Frequently asked questions
- What counts as a personal data breach?
- A personal data breach is a security incident that compromises the confidentiality, integrity or availability of personal data. The playbook helps teams distinguish these incidents from security events that do not involve personal data.
- What should happen in the first hour?
- Open the incident record immediately, assign an owner, capture what is known, begin containment and investigation in parallel, preserve evidence and identify any urgent escalation needs. Unknown details should be marked as open questions rather than delaying the log.
- Does every breach need to be reported to a regulator?
- No. Notification depends on the applicable law and the risk to affected individuals. The playbook provides a structured risk assessment and decision record, but organisations should obtain qualified advice where the threshold or jurisdiction is unclear.
- Should non-reportable breaches go in the register?
- Yes. The register should include every confirmed personal data breach, including incidents that did not meet the notification threshold, with the facts, assessment, decision, actions and closure evidence recorded.
- Can we use the playbook without Privacy360?
- Yes. The fillable forms, templates and checklists are designed to work with a spreadsheet and shared drive. Privacy360 can connect the same steps in a managed workflow when volume or organisational complexity increases.
Get the Toolkit
Complete the download form to receive the Breach Response Playbook.