Incident Playbook
Data Breaches
Summary
Personal or sensitive data has been exposed, shared, accessed or taken without authorisation.
- Category
- Data
- Typical severity
- High to critical
- Response led by
- Incident lead, with leadership and legal support
First 15 minutes
- Stop the leak: restrict access, remove sharing links and secure accounts.
- Work out what data was exposed, whose it was and how many people are affected.
- Assess the harm to people, putting their safety first.
1. Overview
A data breach is when personal or sensitive information is seen, shared or taken by people who shouldn't have it. It can come from an attack, a simple mistake or a lost device. For organisations working with vulnerable people, a breach can put lives at risk.
2. How it happens
- Files shared with "anyone with the link" and forwarded beyond their intended audience.
- Emails or attachments sent to the wrong person.
- Hacked accounts and stolen passwords.
- Insiders, including former staff, misusing access.
- Lost or stolen devices without encryption.
- Third-party services that store your data being breached themselves.
3. Indicators
Signs that this incident may be happening:
- Someone outside the organisation mentions information they shouldn't have.
- Files appear in places they shouldn't, or sharing settings are wider than intended.
- Account activity shows downloads or access you can't explain.
- A partner or service provider tells you they've had a breach.
4. Triage questions
Answer these first to understand scope and severity:
- What data was exposed, and how sensitive is it?
- Whose data is it, and how many people are affected?
- How was it exposed: a sharing link, misdirected email, hacked account, lost device, insider?
- Is the exposure ongoing, and who may have seen or taken the data?
- Could exposure lead to physical, legal, financial or emotional harm?
5. Severity guide
Use your plan's severity levels. As a guide for this incident:
| Level | Typical situation |
|---|---|
| Low | Non-sensitive data sent to a trusted recipient in error, and deleted. |
| Medium | Limited personal data exposed briefly, with low risk of harm. |
| High | Sensitive personal data accessed by unauthorised people. |
| Critical | Data about vulnerable people exposed in a way that could lead to serious harm. |
6. Response steps
Work through these in order. Record every action, with the time and who did it, in your incident log.
- Stop the leak: restrict access, remove sharing links and secure accounts.
- Work out what data was exposed, whose it was and how many people are affected.
- Assess the harm to people, putting their safety first.
- Check whether the law requires you to report it. Many data protection laws require reporting serious breaches, often within 72 hours.
- Tell affected people in a way that keeps them safe, and explain what they can do.
- Keep a careful record of every decision and action.
7. Communication
Who to inform, and when:
- Incident lead, leadership and legal support, immediately.
- Your data protection authority, if the law requires it, often within 72 hours of becoming aware.
- Affected people, in a way that keeps them safe, explaining what happened and what they can do.
- Partners and funders, if their data or agreements are involved.
- Staff, about what happened and any changes to how data is handled.
8. Evidence to preserve
Keep these before making changes, wherever it's safe to do so:
- What data was exposed, where, and for how long.
- Access and sharing logs showing who opened or downloaded it.
- Copies of misdirected messages and recipients' confirmation of deletion.
- When the breach was discovered, by whom, and the timeline of actions.
- Records of risk assessment and notification decisions.
9. Recovery and review
- Fix the cause, whether a setting, a process or a gap in training.
- Delete data you don't need.
- Review who has access to sensitive data.
- Train staff on what went wrong, without blame.
- Record the breach and update your plan.
10. Prevention checklist
- Know what personal data you hold, where it's stored and who can access it.
- Collect and keep only what you need, and delete the rest on a schedule.
- Share files with named people only, and review access regularly.
- Encrypt devices, and protect accounts with 2-step verification.
- Know your legal duties for reporting breaches before anything happens.
- Check how partners and service providers protect your data.