Personal data breach report and notification record
- Version
- v1
- Updated
- 7 October 2026
- Reviewed
- 7 October 2026
- Audience
- Primary and secondary schools in England, including maintained schools and academies; not intended for independent schools.
- Jurisdiction
- england
Blank fields · read-only preview
Scope and incident identification
Complete this record when the school experiences a personal data breach or cyber incident requiring assessment of external reporting or notification. Complete only the notification sections relevant to the circumstances; not every incident must be reported to every organisation.
School incident reference
RequiredUse the school's internal reference for this incident.
For example, IR-2025-001
School name
RequiredEnter the name of the school managing this record.
Written response
Record owner and role
RequiredName the person responsible for maintaining this record and their school role.
Written response
Incident type or types
RequiredSelect all categories that describe the event.
Choose all that apply
- Personal data breach
- Cyber incident
- Loss or theft of device, paperwork or storage media
- Unauthorised access or disclosure
- Malware or ransomware
- Phishing or social engineering
- Other
- Other
If other, please specify
Summary of what happened
RequiredGive an accurate factual account. Record what is known and identify any material uncertainty.
Written response
Date the incident began or is believed to have begun
If the date is unknown, record the earliest known date in the incident summary and leave this field blank if permitted by local record-keeping practice.
- Day
- Month
- Year
Date the school discovered or became aware of the incident
RequiredRecord the date the school found out about the incident.
- Day
- Month
- Year
How the school discovered the incident
RequiredDescribe how the incident was identified, including the source of the alert or report.
Written response
Is the incident ongoing or still being investigated?
RequiredSelect this if the facts, scope or effects are not yet fully established.
- Tick when complete
Incident chronology
RequiredRecord significant events, decisions and actions in date-and-time order. Add later entries as the investigation develops.
Include date, time, event, source of information and action taken for each entry.
Categories of personal data involved or potentially involved
RequiredSelect all that apply and use the other option for categories not listed.
Choose all that apply
- Identity and contact details
- Education, attendance or assessment information
- Safeguarding information
- Special category data
- Criminal offence or alleged offence information
- Financial or payment information
- Account credentials or authentication information
- Staff employment information
- Other or not yet known
- Other
If other, please specify
Categories of people affected or potentially affected
RequiredSelect all that apply.
Choose all that apply
- Pupils
- Parents or carers
- School staff
- Governors or trustees
- Applicants or prospective pupils
- Suppliers or contractors
- Visitors
- Other or not yet known
- Other
If other, please specify
Number of people affected or potentially affected
Enter the current estimate. If unknown, record that in the affected-people narrative and update this field when possible.
Number
Minimum: 0
Details of affected or potentially affected people
RequiredExplain how the categories and estimate were determined, including any vulnerable groups or particularly sensitive circumstances relevant to the assessment.
Written response
Systems, locations or recipients involved
RequiredIdentify the systems, records, devices, locations or unintended recipients involved, where known.
Written response
Containment, mitigation and assessment
Containment actions taken
RequiredRecord actions taken to contain the incident, with dates, times, owners and any remaining limitations.
Written response
Mitigation and remedial actions
RequiredRecord steps taken or planned to reduce harm and prevent recurrence.
Written response
Likely risks to affected people
RequiredDescribe the potential consequences and likelihood as assessed by the school, including any reasons for the assessment.
Written response
ICO reporting decision
RequiredRecord the school's decision and rationale. Complete this even if the decision is not to report.
Choose one
- Report to the ICO
- Do not report to the ICO
- Decision under review
- Not a personal data breach requiring an ICO decision
ICO reporting decision rationale
RequiredExplain the assessment, including any uncertainty, the information available at the time and why the selected decision was reached.
Written response
Date reported to the ICO
Complete if the school has reported the incident to the ICO.
- Day
- Month
- Year
ICO report or reference number
Complete if provided by the ICO.
Written response
Information provided to the ICO and outstanding information
Complete if reported. Record what was submitted, who submitted it, relevant contact details, and any information to be provided later without undue delay.
Written response
Other external organisations considered or notified
RequiredSelect only organisations relevant to the circumstances. Notification is not assumed for every incident. If the event involved a cyber incident, consider the NCSC; if criminal intent is suspected, consider Report Fraud; also consider the insurer and law enforcement where relevant.
Choose all that apply
- National Cyber Security Centre (NCSC)
- Report Fraud
- Insurer
- Law enforcement agency
- None considered or notified
- Under review
- Other relevant organisation
- Other
If other, please specify
Details of other external notifications or considerations
For each relevant organisation, record whether it was notified, the decision not to notify, the date, reference number, contact and rationale. Complete only where relevant.
Written response
Notification or communication to affected people
Record whether affected people were or will be contacted, the decision and rationale, the audience, date, method and message. Complete only where relevant.
Written response
Relevant school contacts
RequiredRecord the names, roles and contact details of people who can provide further information, such as the incident lead, data protection officer, designated safeguarding lead or IT lead where relevant.
Written response
Relevant external contacts
Record relevant contacts at notified organisations, suppliers, insurers, law enforcement or other parties.
Written response
Acknowledgements and updates
Acknowledgements received
Record acknowledgements, confirmations or reference numbers received from the ICO or other notified organisations. Complete only where applicable.
Written response
Next review or update date
RequiredSet a date to review unresolved facts, containment, notifications and any additional information that needs to be supplied.
- Day
- Month
- Year
Subsequent updates
Add dated updates without undue delay, including new facts, revised estimates, additional reports or notifications, further mitigation and changes to contacts.
Written response
Date the incident record was closed
Complete when the school has completed its internal review and no further update is expected, subject to the school's retention arrangements.
- Day
- Month
- Year
Closure summary and lessons identified
Summarise the final known position, outstanding actions, lessons identified and owner or due date for any continuing actions.
Written response
