Security · Incident Response
What a personal data breach is, why the first 72 hours matter, a timed checklist, roles and a breach log template.
Last updated: October 2026. Written by Athar Ahmad, Certified Bubble.io Developer and Tech Architect, Simple Automation Solutions.
Quick answer
In a personal data breach, contain the incident without destroying evidence, log everything, assemble an incident lead, technical adviser, legal or compliance adviser and communications lead, establish what happened and assess the risk to individuals. Under the GDPR and UK GDPR, notify the regulator without undue delay and where feasible within 72 hours of becoming aware unless risk is unlikely, tell affected individuals if risk is high, and notify clients as contracts require. Other laws vary. This is general information, not legal advice.
Key takeaways
- Contain, but do not wipe devices or destroy evidence.
- Record when you became aware; the 72-hour clock under GDPR starts then.
- Assess risk to individuals; notify the regulator and individuals as the law requires.
- Name an incident lead and rehearse a one-page plan before anything happens.
- General information; engage legal and technical specialists in a real incident.
In this guide
This guide is general information, not legal advice. Breach notification laws and deadlines differ by country, state and sector. Take advice from a qualified adviser, and prepare before an incident happens.
What is a personal data breach?
A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. Examples include a lost laptop with client files, an email sent to the wrong person with sensitive attachments, a compromised mailbox, ransomware that encrypts client records or a staff member viewing records they should not.
Why the first 72 hours matter
Under the GDPR and UK GDPR, a controller must generally notify the supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals. Where the risk to individuals is high, those affected must also be told without undue delay. Processors must tell the controller without undue delay. Other laws, such as US state laws and sector rules, have their own deadlines. Contracts with clients may also require prompt notice.
The first-72-hours checklist
| When | Action |
|---|---|
| Immediately | Stay calm and alert the incident lead. Record the time you became aware. |
| Immediately | Contain: disconnect affected devices from the network, disable compromised accounts, revoke access and stop further loss. Do not wipe or switch off systems without advice, since evidence may be lost. |
| First hours | Start a written log of facts, actions and times, as events happen. |
| First hours | Assemble the response team: incident lead, technical adviser, legal or compliance adviser, communications lead. Contact your insurer if you have cyber cover. |
| First 24 hours | Establish what happened: what data, whose, how many people, how it occurred, whether it is ongoing. |
| First 24 hours | Assess the risk to individuals: how sensitive is the data, how easily could it be misused, what harm could result? |
| Within 72 hours | Decide whether notification to the regulator is required, and notify within the deadline if so. You can provide information in phases if you do not yet have it all. |
| Within 72 hours | Decide whether affected individuals must be told, and prepare clear, honest communications. |
| Within 72 hours | Notify clients and others as your contracts and obligations require. |
| Afterwards | Fix the cause, restore safely, review what failed, update procedures and training, and record the breach and decisions. |
Who does what?
| Role | Responsibility |
|---|---|
| Incident lead | Coordinates the response, keeps the log and makes decisions |
| Technical adviser | Contains the incident, preserves evidence and restores systems |
| Legal or compliance adviser | Advises on notification duties and privilege |
| Communications lead | Prepares messages to clients, staff and regulators |
| Management | Authorises decisions and resources |
Breach log template
Breach record
Date and time of discovery: ________ Reported by: ________
What happened: ________
Data and people affected: ________
Containment steps and times: ________
Risk assessment: ________
Regulator notified? When and how: ________
Individuals notified? When and how: ________
Clients and insurer notified: ________
Cause and fixes: ________
Lessons and changes: ________
What to prepare before anything happens
- Name an incident lead and a deputy, with contact details kept outside the main systems.
- Write a one-page response plan.
- Keep contacts for your adviser, insurer and regulator.
- Know where client data lives and who the processors are.
- Keep an audit trail and logs, which help investigation. See our security guide.
- Take tested backups and keep one copy offline.
- Train staff to report incidents immediately, without blame.
- Rehearse the plan once a year.
What mistakes should you avoid?
- Delaying while trying to fix it quietly.
- Wiping devices and destroying evidence.
- Not recording the time of awareness.
- Notifying without understanding what happened, or never notifying when required.
- Blaming the person who reported it, which discourages reporting.
- No plan, so decisions are made in panic.
- Forgetting contractual notice duties.
How do we help?
Simple Automation Solutions builds systems with access control, logging and backups designed in, which makes incident investigation and recovery easier. We are not a legal or incident response firm, and we recommend engaging specialists in an incident. Builds start at $3,500, and a $345 Discovery Sprint, credited toward the build, includes logging and recovery requirements in the PRD. Support is from $35 per hour.
Frequently asked questions
What should I do in the first 72 hours after a data breach?
Contain it, log everything, assemble your response team, establish what happened, assess the risk to individuals, decide on notification to the regulator and individuals within the deadlines and notify clients as required.
Do I have to report a breach within 72 hours?
Under the GDPR and UK GDPR, generally yes for breaches likely to result in a risk to individuals, within 72 hours of becoming aware, with phased information allowed. Other laws have their own rules. Take advice.
Should I wipe an infected computer?
Not before taking advice. Evidence may be needed for investigation, insurance and regulators.
Who should be on the response team?
An incident lead, a technical adviser, a legal or compliance adviser, a communications lead and a decision maker.
How can I prepare for a breach?
Name an incident lead, write a one-page plan, know where data lives, keep logs and tested backups, train staff to report quickly and rehearse annually.
Want systems that make incidents easier to investigate and recover from?
Email us what your systems hold. We will plan logging, access control and recovery into the build.
Athar Ahmad, Certified Bubble.io Developer and Tech Architect, Simple Automation Solutions
About Simple Automation Solutions (SA Solutions)
Simple Automation Solutions is a Bubble.io development studio led by Athar Ahmad, a Certified Bubble.io Developer and Tech Architect. It builds web and mobile apps, client portals and SaaS products for founder-led businesses such as law firms, accounting firms, boutique agencies and consultants. Services include a free 30-minute Idea Audit, a $345 Discovery Sprint (a Product Requirements Document delivered within 24 hours, credited toward the build) and builds starting at $3,500. Website: sasolutionspk.com.