Forms

Personal data breach lessons and control review record

Record a structured post-incident review of a personal data breach, including the comprehensiveness of the risk-assessment process, the effectiveness of mitigations and controls, corrective actions, ownership, completion evidence, and resulting changes to risk assessments or controls.

Form
CalmComplianceForm template

Personal data breach lessons and control review record

Version
v1
Updated
7 October 2026
Reviewed
7 October 2026
Audience
Maintained and academy primary and secondary schools in England, including school leaders, data protection leads, information governance staff and others responsible for reviewing personal data breaches.
Jurisdiction
england

Blank fields · read-only preview

Scope and review context

Complete this record after a personal data breach affecting the school, whether or not the breach was reported to the ICO. Base the review on the actual incident, its causes, the controls in place and the evidence available after the event. The review should consider lessons learned, whether the risk-assessment process was comprehensive enough, and how effective the mitigations and controls were.

Incident reference

Required

Enter the school's internal incident or case reference. Do not include unnecessary personal data.

For example, DPA-2025-001

Brief description of the breach

Required

Describe what happened, the affected systems or records, the categories of personal data involved and the relevant circumstances. Avoid including more personal data than necessary.

Written response

Date the breach occurred or was first identified

Required

Use the earliest date known. If the occurrence date is unknown, enter the date it was first identified and explain the uncertainty in the incident summary.

Day
Month
Year

Date of this review

Required

Enter the date on which this lessons-learned and control review was completed.

Day
Month
Year

Person leading the review

Required

Enter the name and role of the person responsible for coordinating this review.

Written response

Incident status and response context

ICO notification status

Required

Select the status that applied to this incident. This field records the incident context and does not determine whether notification was legally required.

Choose one

  • Not reported to the ICO
  • Reported to the ICO
  • Notification was under consideration
  • Status is unclear or still being established
  • Other

If other, please specify

Immediate containment and response actions

Required

Record the actions taken to contain the breach, protect affected people and preserve relevant evidence.

Written response

Categories of personal data involved

Required

Select all categories that were involved or potentially involved.

Choose all that apply

  • Identity or contact details
  • Pupil educational or safeguarding information
  • Staff employment or personnel information
  • Special-category data
  • Criminal-offence data
  • Financial information
  • Credentials or authentication information
  • Not yet established
  • Other

If other, please specify

Lessons learned and risk-assessment review

Lessons learned from the incident

Required

Describe what the school learned about the incident, its causes, decision-making, communications, response arrangements and prevention of recurrence.

Written response

How comprehensive was the relevant risk-assessment process?

Required

Assess whether the process identified the relevant threat, data, people, systems, dependencies, vulnerabilities and potential consequences before the incident.

Choose one

  • Comprehensive for the circumstances
  • Mostly comprehensive, with limited gaps
  • Partially comprehensive, with material gaps
  • Not comprehensive
  • Could not be assessed from available evidence

Risk-assessment process gaps

Required

Explain any gaps identified, including what was omitted, out of date, insufficiently specific or not reflected in operational practice.

Written response

How effective were the mitigations and controls?

Required

Assess the controls that were intended to prevent, detect, contain or recover from this incident.

Choose one

  • Effective in the circumstances
  • Mostly effective, with limited weaknesses
  • Partially effective, with material weaknesses
  • Ineffective or absent
  • Could not be assessed from available evidence

Review of relevant controls

Required

For each relevant control, record its intended purpose, how it operated during the incident, evidence reviewed, weaknesses identified and whether it should be retained, changed, replaced or added.

Written response

Evidence reviewed

Required

List the records used to support the review, such as policies, risk assessments, access logs, training records, incident records, technical reports, meeting notes or communications. Do not attach unnecessary personal data.

Written response

Corrective actions and accountability

Corrective actions required

Required

Describe each action needed to address a cause, control weakness or risk-assessment gap. Include the expected outcome and any dependencies.

Written response

Highest priority assigned to the corrective actions

Required

Select the highest priority assigned to any action in this record.

Choose one

  • Urgent
  • High
  • Medium
  • Low
  • No corrective action required

Responsible owner or owners

Required

Name the role or person accountable for completing the corrective actions. Use roles where appropriate and avoid unnecessary personal data.

Written response

Target completion date

Required

Enter the target date for completing the corrective actions. If different actions have different dates, record them in the corrective actions field.

Day
Month
Year

Corrective-action completion status

Required

Select the current status of the corrective actions at the time this record is completed.

Choose one

  • Not started
  • In progress
  • Completed
  • Partially completed
  • Deferred with a recorded rationale
  • No corrective action required

Completion evidence

Required

Describe or reference the evidence demonstrating that completed actions were implemented and, where relevant, tested or checked for effectiveness.

Written response

Resulting changes and sign-off

Changes required to risk assessments

Required

Record the risk assessments that need updating, the changes required and the date or review point for making those changes.

Written response

Changes required to controls or procedures

Required

Record any controls or procedures to introduce, strengthen, remove or monitor, including how implementation will be verified.

Written response

Follow-up review date

Required

Enter the date for checking that corrective actions and resulting changes remain effective. If no follow-up is required, explain why in the final comments.

Day
Month
Year

Final comments and unresolved issues

Required

Record any remaining uncertainty, dependencies, accepted residual issues or matters requiring escalation.

Written response

I confirm that this record reflects the evidence available for the incident and identifies the required follow-up actions.

Required

Select this only after reviewing the completed record for accuracy and completeness.

  • Tick when complete
CalmCompliance · v1Template for adaptation

Template details

Type
Form
Version
v1
Updated
7 October 2026
Reviewed
7 October 2026

Get this template

Free, editable Word document. We’ll email you a download link. No Calm account needed.

Edit in Word or Google Docs.

We record your email and the template you request. Read our privacy policy.