Policies

Personal data breach reporting and external notification procedure

To support the preparation of accurate and detailed personal data breach reports, timely submission of available information, later updates without undue delay, and consideration of relevant external notifications when a school experiences a personal data breach or related cyber incident.

SOP Template
CalmComplianceSOP Template

Personal data breach reporting and external notification procedure

Version
v1
Updated
7 October 2026
Reviewed
7 October 2026

This procedure applies when the school experiences a personal data breach or related cyber incident. Whether the school reports to the ICO, NCSC, Report Fraud, an insurer, a law-enforcement agency or another organisation depends on the facts of the incident and the requirements relevant to the case.

1. Prepare the incident account

Prepare an accurate account of what happened, when and how the school discovered the breach, who has been or may be affected, what action is being taken, who should be contacted for further information, and which other organisations have been told.

Include as much relevant detail as possible. Where the full facts are not yet known, record the information available at that stage and continue developing the account as the incident is understood.

2. Report to the ICO where applicable

Where ICO reporting is applicable, submit a factually accurate report with the relevant information available within the applicable reporting period. The ICO reporting requirement is 72 hours, and the school should provide whatever relevant information it has if a full and complete account is not yet available.

Provide additional information later without undue delay when the initial account is incomplete. Keep a copy of the submitted report and the information provided in later updates.

3. Consider other external notifications

Consider whether the circumstances make notification to the school’s insurer, a law-enforcement agency or the NCSC relevant. Where the breach was caused by a malicious actor, consider notifying the NCSC.

For each relevant external notification, record the decision to notify or not notify, the reason for that decision, any notification made, acknowledgements received and incident-specific contact details.

4. Respond to a cyber incident

If the event is a cyber incident, report it online where possible unless the school cannot access its system. Consider reporting the incident to the NCSC.

If the incident may involve criminal intent, consider reporting it to Report Fraud. This procedure applies to schools in England; the separate direction concerning Police Scotland does not apply.

5. Maintain the incident record

Maintain the completed reports, incident chronology, assessment of affected people, containment and mitigation records, relevant contact details, records of other notified organisations, report references and subsequent updates. Record any documented reason for not making a considered external notification.

Sources

  1. UK GDPR data breach reporting (DPA 2018) | ICOInformation Commissioner's Office (ICO)
CalmCompliance · v1Template for adaptation

Template details

Type
SOP Template
Version
v1
Updated
7 October 2026
Reviewed
7 October 2026
Sections
16 sections
  • UK GDPR data breach reporting (DPA 2018) | ICO

Get this template

Free, editable Word document. We’ll email you a download link. No Calm account needed.

Edit in Word or Google Docs.

We record your email and the template you request. Read our privacy policy.