Security · Incident Response

What a personal data breach is, why the first 72 hours matter, a timed checklist, roles and a breach log template.

Last updated: October 2026. Written by Athar Ahmad, Certified Bubble.io Developer and Tech Architect, Simple Automation Solutions.

Quick answer

In a personal data breach, contain the incident without destroying evidence, log everything, assemble an incident lead, technical adviser, legal or compliance adviser and communications lead, establish what happened and assess the risk to individuals. Under the GDPR and UK GDPR, notify the regulator without undue delay and where feasible within 72 hours of becoming aware unless risk is unlikely, tell affected individuals if risk is high, and notify clients as contracts require. Other laws vary. This is general information, not legal advice.

Key takeaways

  • Contain, but do not wipe devices or destroy evidence.
  • Record when you became aware; the 72-hour clock under GDPR starts then.
  • Assess risk to individuals; notify the regulator and individuals as the law requires.
  • Name an incident lead and rehearse a one-page plan before anything happens.
  • General information; engage legal and technical specialists in a real incident.

This guide is general information, not legal advice. Breach notification laws and deadlines differ by country, state and sector. Take advice from a qualified adviser, and prepare before an incident happens.

What is a personal data breach?

A personal data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. Examples include a lost laptop with client files, an email sent to the wrong person with sensitive attachments, a compromised mailbox, ransomware that encrypts client records or a staff member viewing records they should not.

Why the first 72 hours matter

Under the GDPR and UK GDPR, a controller must generally notify the supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals. Where the risk to individuals is high, those affected must also be told without undue delay. Processors must tell the controller without undue delay. Other laws, such as US state laws and sector rules, have their own deadlines. Contracts with clients may also require prompt notice.

The first-72-hours checklist

WhenAction
ImmediatelyStay calm and alert the incident lead. Record the time you became aware.
ImmediatelyContain: disconnect affected devices from the network, disable compromised accounts, revoke access and stop further loss. Do not wipe or switch off systems without advice, since evidence may be lost.
First hoursStart a written log of facts, actions and times, as events happen.
First hoursAssemble the response team: incident lead, technical adviser, legal or compliance adviser, communications lead. Contact your insurer if you have cyber cover.
First 24 hoursEstablish what happened: what data, whose, how many people, how it occurred, whether it is ongoing.
First 24 hoursAssess the risk to individuals: how sensitive is the data, how easily could it be misused, what harm could result?
Within 72 hoursDecide whether notification to the regulator is required, and notify within the deadline if so. You can provide information in phases if you do not yet have it all.
Within 72 hoursDecide whether affected individuals must be told, and prepare clear, honest communications.
Within 72 hoursNotify clients and others as your contracts and obligations require.
AfterwardsFix the cause, restore safely, review what failed, update procedures and training, and record the breach and decisions.

Who does what?

RoleResponsibility
Incident leadCoordinates the response, keeps the log and makes decisions
Technical adviserContains the incident, preserves evidence and restores systems
Legal or compliance adviserAdvises on notification duties and privilege
Communications leadPrepares messages to clients, staff and regulators
ManagementAuthorises decisions and resources

Breach log template

Breach record

Date and time of discovery: ________ Reported by: ________

What happened: ________

Data and people affected: ________

Containment steps and times: ________

Risk assessment: ________

Regulator notified? When and how: ________

Individuals notified? When and how: ________

Clients and insurer notified: ________

Cause and fixes: ________

Lessons and changes: ________

What to prepare before anything happens

  1. Name an incident lead and a deputy, with contact details kept outside the main systems.
  2. Write a one-page response plan.
  3. Keep contacts for your adviser, insurer and regulator.
  4. Know where client data lives and who the processors are.
  5. Keep an audit trail and logs, which help investigation. See our security guide.
  6. Take tested backups and keep one copy offline.
  7. Train staff to report incidents immediately, without blame.
  8. Rehearse the plan once a year.

What mistakes should you avoid?

  • Delaying while trying to fix it quietly.
  • Wiping devices and destroying evidence.
  • Not recording the time of awareness.
  • Notifying without understanding what happened, or never notifying when required.
  • Blaming the person who reported it, which discourages reporting.
  • No plan, so decisions are made in panic.
  • Forgetting contractual notice duties.

How do we help?

Simple Automation Solutions builds systems with access control, logging and backups designed in, which makes incident investigation and recovery easier. We are not a legal or incident response firm, and we recommend engaging specialists in an incident. Builds start at $3,500, and a $345 Discovery Sprint, credited toward the build, includes logging and recovery requirements in the PRD. Support is from $35 per hour.

Frequently asked questions

What should I do in the first 72 hours after a data breach?

Contain it, log everything, assemble your response team, establish what happened, assess the risk to individuals, decide on notification to the regulator and individuals within the deadlines and notify clients as required.

Do I have to report a breach within 72 hours?

Under the GDPR and UK GDPR, generally yes for breaches likely to result in a risk to individuals, within 72 hours of becoming aware, with phased information allowed. Other laws have their own rules. Take advice.

Should I wipe an infected computer?

Not before taking advice. Evidence may be needed for investigation, insurance and regulators.

Who should be on the response team?

An incident lead, a technical adviser, a legal or compliance adviser, a communications lead and a decision maker.

How can I prepare for a breach?

Name an incident lead, write a one-page plan, know where data lives, keep logs and tested backups, train staff to report quickly and rehearse annually.

Want systems that make incidents easier to investigate and recover from?

Email us what your systems hold. We will plan logging, access control and recovery into the build.

Email info@sasolutionspk.com

Athar Ahmad, Certified Bubble.io Developer and Tech Architect, Simple Automation Solutions

About Simple Automation Solutions (SA Solutions)

Simple Automation Solutions is a Bubble.io development studio led by Athar Ahmad, a Certified Bubble.io Developer and Tech Architect. It builds web and mobile apps, client portals and SaaS products for founder-led businesses such as law firms, accounting firms, boutique agencies and consultants. Services include a free 30-minute Idea Audit, a $345 Discovery Sprint (a Product Requirements Document delivered within 24 hours, credited toward the build) and builds starting at $3,500. Website: sasolutionspk.com.

Simple Automation Solutions

Business Process Automation, Technology Consulting for Businesses, IT Solutions for Digital Transformation and Enterprise System Modernization, Web Applications Development, Mobile Applications Development, MVP Development