← All playbooks

Incident Playbook

Data Breaches

SIIRF-PB-08DataTypical severity: High to criticalVersion 1.0 · October 2026

Summary

Personal or sensitive data has been exposed, shared, accessed or taken without authorisation.

Category
Data
Typical severity
High to critical
Response led by
Incident lead, with leadership and legal support

First 15 minutes

  1. Stop the leak: restrict access, remove sharing links and secure accounts.
  2. Work out what data was exposed, whose it was and how many people are affected.
  3. Assess the harm to people, putting their safety first.

1. Overview

A data breach is when personal or sensitive information is seen, shared or taken by people who shouldn't have it. It can come from an attack, a simple mistake or a lost device. For organisations working with vulnerable people, a breach can put lives at risk.

2. How it happens

  • Files shared with "anyone with the link" and forwarded beyond their intended audience.
  • Emails or attachments sent to the wrong person.
  • Hacked accounts and stolen passwords.
  • Insiders, including former staff, misusing access.
  • Lost or stolen devices without encryption.
  • Third-party services that store your data being breached themselves.

3. Indicators

Signs that this incident may be happening:

  • Someone outside the organisation mentions information they shouldn't have.
  • Files appear in places they shouldn't, or sharing settings are wider than intended.
  • Account activity shows downloads or access you can't explain.
  • A partner or service provider tells you they've had a breach.

4. Triage questions

Answer these first to understand scope and severity:

  1. What data was exposed, and how sensitive is it?
  2. Whose data is it, and how many people are affected?
  3. How was it exposed: a sharing link, misdirected email, hacked account, lost device, insider?
  4. Is the exposure ongoing, and who may have seen or taken the data?
  5. Could exposure lead to physical, legal, financial or emotional harm?

5. Severity guide

Use your plan's severity levels. As a guide for this incident:

LevelTypical situation
LowNon-sensitive data sent to a trusted recipient in error, and deleted.
MediumLimited personal data exposed briefly, with low risk of harm.
HighSensitive personal data accessed by unauthorised people.
CriticalData about vulnerable people exposed in a way that could lead to serious harm.

6. Response steps

Work through these in order. Record every action, with the time and who did it, in your incident log.

  1. Stop the leak: restrict access, remove sharing links and secure accounts.
  2. Work out what data was exposed, whose it was and how many people are affected.
  3. Assess the harm to people, putting their safety first.
  4. Check whether the law requires you to report it. Many data protection laws require reporting serious breaches, often within 72 hours.
  5. Tell affected people in a way that keeps them safe, and explain what they can do.
  6. Keep a careful record of every decision and action.

7. Communication

Who to inform, and when:

  • Incident lead, leadership and legal support, immediately.
  • Your data protection authority, if the law requires it, often within 72 hours of becoming aware.
  • Affected people, in a way that keeps them safe, explaining what happened and what they can do.
  • Partners and funders, if their data or agreements are involved.
  • Staff, about what happened and any changes to how data is handled.

8. Evidence to preserve

Keep these before making changes, wherever it's safe to do so:

  • What data was exposed, where, and for how long.
  • Access and sharing logs showing who opened or downloaded it.
  • Copies of misdirected messages and recipients' confirmation of deletion.
  • When the breach was discovered, by whom, and the timeline of actions.
  • Records of risk assessment and notification decisions.

9. Recovery and review

  • Fix the cause, whether a setting, a process or a gap in training.
  • Delete data you don't need.
  • Review who has access to sensitive data.
  • Train staff on what went wrong, without blame.
  • Record the breach and update your plan.

10. Prevention checklist

  • Know what personal data you hold, where it's stored and who can access it.
  • Collect and keep only what you need, and delete the rest on a schedule.
  • Share files with named people only, and review access regularly.
  • Encrypt devices, and protect accounts with 2-step verification.
  • Know your legal duties for reporting breaches before anything happens.
  • Check how partners and service providers protect your data.