Forms

Personal data breach report and notification record

To record the assessment, management, external reporting or notification, contacts, acknowledgements and subsequent updates for a personal data breach or cyber incident affecting a school in England.

Form
CalmComplianceForm template

Personal data breach report and notification record

Version
v1
Updated
7 October 2026
Reviewed
7 October 2026
Audience
Primary and secondary schools in England, including maintained schools and academies; not intended for independent schools.
Jurisdiction
england

Blank fields · read-only preview

Scope and incident identification

Complete this record when the school experiences a personal data breach or cyber incident requiring assessment of external reporting or notification. Complete only the notification sections relevant to the circumstances; not every incident must be reported to every organisation.

School incident reference

Required

Use the school's internal reference for this incident.

For example, IR-2025-001

School name

Required

Enter the name of the school managing this record.

Written response

Record owner and role

Required

Name the person responsible for maintaining this record and their school role.

Written response

Incident type or types

Required

Select all categories that describe the event.

Choose all that apply

  • Personal data breach
  • Cyber incident
  • Loss or theft of device, paperwork or storage media
  • Unauthorised access or disclosure
  • Malware or ransomware
  • Phishing or social engineering
  • Other
  • Other

If other, please specify

Summary of what happened

Required

Give an accurate factual account. Record what is known and identify any material uncertainty.

Written response

Date the incident began or is believed to have begun

If the date is unknown, record the earliest known date in the incident summary and leave this field blank if permitted by local record-keeping practice.

Day
Month
Year

Date the school discovered or became aware of the incident

Required

Record the date the school found out about the incident.

Day
Month
Year

How the school discovered the incident

Required

Describe how the incident was identified, including the source of the alert or report.

Written response

Is the incident ongoing or still being investigated?

Required

Select this if the facts, scope or effects are not yet fully established.

  • Tick when complete

Incident chronology

Required

Record significant events, decisions and actions in date-and-time order. Add later entries as the investigation develops.

Include date, time, event, source of information and action taken for each entry.

Categories of personal data involved or potentially involved

Required

Select all that apply and use the other option for categories not listed.

Choose all that apply

  • Identity and contact details
  • Education, attendance or assessment information
  • Safeguarding information
  • Special category data
  • Criminal offence or alleged offence information
  • Financial or payment information
  • Account credentials or authentication information
  • Staff employment information
  • Other or not yet known
  • Other

If other, please specify

Categories of people affected or potentially affected

Required

Select all that apply.

Choose all that apply

  • Pupils
  • Parents or carers
  • School staff
  • Governors or trustees
  • Applicants or prospective pupils
  • Suppliers or contractors
  • Visitors
  • Other or not yet known
  • Other

If other, please specify

Number of people affected or potentially affected

Enter the current estimate. If unknown, record that in the affected-people narrative and update this field when possible.

Number

Minimum: 0

Details of affected or potentially affected people

Required

Explain how the categories and estimate were determined, including any vulnerable groups or particularly sensitive circumstances relevant to the assessment.

Written response

Systems, locations or recipients involved

Required

Identify the systems, records, devices, locations or unintended recipients involved, where known.

Written response

Containment, mitigation and assessment

Containment actions taken

Required

Record actions taken to contain the incident, with dates, times, owners and any remaining limitations.

Written response

Mitigation and remedial actions

Required

Record steps taken or planned to reduce harm and prevent recurrence.

Written response

Likely risks to affected people

Required

Describe the potential consequences and likelihood as assessed by the school, including any reasons for the assessment.

Written response

ICO reporting decision

Required

Record the school's decision and rationale. Complete this even if the decision is not to report.

Choose one

  • Report to the ICO
  • Do not report to the ICO
  • Decision under review
  • Not a personal data breach requiring an ICO decision

ICO reporting decision rationale

Required

Explain the assessment, including any uncertainty, the information available at the time and why the selected decision was reached.

Written response

Date reported to the ICO

Complete if the school has reported the incident to the ICO.

Day
Month
Year

ICO report or reference number

Complete if provided by the ICO.

Written response

Information provided to the ICO and outstanding information

Complete if reported. Record what was submitted, who submitted it, relevant contact details, and any information to be provided later without undue delay.

Written response

Other external organisations considered or notified

Required

Select only organisations relevant to the circumstances. Notification is not assumed for every incident. If the event involved a cyber incident, consider the NCSC; if criminal intent is suspected, consider Report Fraud; also consider the insurer and law enforcement where relevant.

Choose all that apply

  • National Cyber Security Centre (NCSC)
  • Report Fraud
  • Insurer
  • Law enforcement agency
  • None considered or notified
  • Under review
  • Other relevant organisation
  • Other

If other, please specify

Details of other external notifications or considerations

For each relevant organisation, record whether it was notified, the decision not to notify, the date, reference number, contact and rationale. Complete only where relevant.

Written response

Notification or communication to affected people

Record whether affected people were or will be contacted, the decision and rationale, the audience, date, method and message. Complete only where relevant.

Written response

Relevant school contacts

Required

Record the names, roles and contact details of people who can provide further information, such as the incident lead, data protection officer, designated safeguarding lead or IT lead where relevant.

Written response

Relevant external contacts

Record relevant contacts at notified organisations, suppliers, insurers, law enforcement or other parties.

Written response

Acknowledgements and updates

Acknowledgements received

Record acknowledgements, confirmations or reference numbers received from the ICO or other notified organisations. Complete only where applicable.

Written response

Next review or update date

Required

Set a date to review unresolved facts, containment, notifications and any additional information that needs to be supplied.

Day
Month
Year

Subsequent updates

Add dated updates without undue delay, including new facts, revised estimates, additional reports or notifications, further mitigation and changes to contacts.

Written response

Date the incident record was closed

Complete when the school has completed its internal review and no further update is expected, subject to the school's retention arrangements.

Day
Month
Year

Closure summary and lessons identified

Summarise the final known position, outstanding actions, lessons identified and owner or due date for any continuing actions.

Written response

CalmCompliance · v1Template for adaptation

Template details

Type
Form
Version
v1
Updated
7 October 2026
Reviewed
7 October 2026

Get this template

Free, editable Word document. We’ll email you a download link. No Calm account needed.

Edit in Word or Google Docs.

We record your email and the template you request. Read our privacy policy.