Personal data breach lessons and control review record
- Version
- v1
- Updated
- 7 October 2026
- Reviewed
- 7 October 2026
- Audience
- Maintained and academy primary and secondary schools in England, including school leaders, data protection leads, information governance staff and others responsible for reviewing personal data breaches.
- Jurisdiction
- england
Blank fields · read-only preview
Scope and review context
Complete this record after a personal data breach affecting the school, whether or not the breach was reported to the ICO. Base the review on the actual incident, its causes, the controls in place and the evidence available after the event. The review should consider lessons learned, whether the risk-assessment process was comprehensive enough, and how effective the mitigations and controls were.
Incident reference
RequiredEnter the school's internal incident or case reference. Do not include unnecessary personal data.
For example, DPA-2025-001
Brief description of the breach
RequiredDescribe what happened, the affected systems or records, the categories of personal data involved and the relevant circumstances. Avoid including more personal data than necessary.
Written response
Date the breach occurred or was first identified
RequiredUse the earliest date known. If the occurrence date is unknown, enter the date it was first identified and explain the uncertainty in the incident summary.
- Day
- Month
- Year
Date of this review
RequiredEnter the date on which this lessons-learned and control review was completed.
- Day
- Month
- Year
Person leading the review
RequiredEnter the name and role of the person responsible for coordinating this review.
Written response
Incident status and response context
ICO notification status
RequiredSelect the status that applied to this incident. This field records the incident context and does not determine whether notification was legally required.
Choose one
- Not reported to the ICO
- Reported to the ICO
- Notification was under consideration
- Status is unclear or still being established
- Other
If other, please specify
Immediate containment and response actions
RequiredRecord the actions taken to contain the breach, protect affected people and preserve relevant evidence.
Written response
Categories of personal data involved
RequiredSelect all categories that were involved or potentially involved.
Choose all that apply
- Identity or contact details
- Pupil educational or safeguarding information
- Staff employment or personnel information
- Special-category data
- Criminal-offence data
- Financial information
- Credentials or authentication information
- Not yet established
- Other
If other, please specify
Lessons learned and risk-assessment review
Lessons learned from the incident
RequiredDescribe what the school learned about the incident, its causes, decision-making, communications, response arrangements and prevention of recurrence.
Written response
How comprehensive was the relevant risk-assessment process?
RequiredAssess whether the process identified the relevant threat, data, people, systems, dependencies, vulnerabilities and potential consequences before the incident.
Choose one
- Comprehensive for the circumstances
- Mostly comprehensive, with limited gaps
- Partially comprehensive, with material gaps
- Not comprehensive
- Could not be assessed from available evidence
Risk-assessment process gaps
RequiredExplain any gaps identified, including what was omitted, out of date, insufficiently specific or not reflected in operational practice.
Written response
How effective were the mitigations and controls?
RequiredAssess the controls that were intended to prevent, detect, contain or recover from this incident.
Choose one
- Effective in the circumstances
- Mostly effective, with limited weaknesses
- Partially effective, with material weaknesses
- Ineffective or absent
- Could not be assessed from available evidence
Review of relevant controls
RequiredFor each relevant control, record its intended purpose, how it operated during the incident, evidence reviewed, weaknesses identified and whether it should be retained, changed, replaced or added.
Written response
Evidence reviewed
RequiredList the records used to support the review, such as policies, risk assessments, access logs, training records, incident records, technical reports, meeting notes or communications. Do not attach unnecessary personal data.
Written response
Corrective actions and accountability
Corrective actions required
RequiredDescribe each action needed to address a cause, control weakness or risk-assessment gap. Include the expected outcome and any dependencies.
Written response
Highest priority assigned to the corrective actions
RequiredSelect the highest priority assigned to any action in this record.
Choose one
- Urgent
- High
- Medium
- Low
- No corrective action required
Responsible owner or owners
RequiredName the role or person accountable for completing the corrective actions. Use roles where appropriate and avoid unnecessary personal data.
Written response
Target completion date
RequiredEnter the target date for completing the corrective actions. If different actions have different dates, record them in the corrective actions field.
- Day
- Month
- Year
Corrective-action completion status
RequiredSelect the current status of the corrective actions at the time this record is completed.
Choose one
- Not started
- In progress
- Completed
- Partially completed
- Deferred with a recorded rationale
- No corrective action required
Completion evidence
RequiredDescribe or reference the evidence demonstrating that completed actions were implemented and, where relevant, tested or checked for effectiveness.
Written response
Resulting changes and sign-off
Changes required to risk assessments
RequiredRecord the risk assessments that need updating, the changes required and the date or review point for making those changes.
Written response
Changes required to controls or procedures
RequiredRecord any controls or procedures to introduce, strengthen, remove or monitor, including how implementation will be verified.
Written response
Follow-up review date
RequiredEnter the date for checking that corrective actions and resulting changes remain effective. If no follow-up is required, explain why in the final comments.
- Day
- Month
- Year
Final comments and unresolved issues
RequiredRecord any remaining uncertainty, dependencies, accepted residual issues or matters requiring escalation.
Written response
I confirm that this record reflects the evidence available for the incident and identifies the required follow-up actions.
RequiredSelect this only after reviewing the completed record for accuracy and completeness.
- Tick when complete
