Data Breach Response Procedure
A clear procedure for identifying, containing, and reporting personal data breaches in a GP practice setting, including ICO notification criteria.
## Data Breach Response Procedure
### Definition
A personal data breach is any security incident resulting in accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
### Common Breach Examples in GP Practices
- Misdirected fax or email containing patient information
- Lost or unencrypted USB drive
- Ransomware or cyberattack on clinical systems
- Verbal disclosure to an unauthorised third party
- Paper records found in non-secure waste
### Immediate Response (within 24 hours)
1. Contain the breach — retrieve misdirected data if possible, isolate affected systems
2. Assess scope — how many records affected, what data types, what is the likely impact?
3. Report internally — notify the DPO and Practice Manager immediately
### ICO Notification Assessment
You must notify the ICO within **72 hours** if the breach is likely to result in a risk to individuals' rights and freedoms. Factors to consider:
- Sensitivity of the data involved
- Volume of records affected
- Whether the data has been accessed by an unauthorised person
- Whether harm to individuals is likely (financial loss, discrimination, physical harm)
### ICO Reporting
Report at: ico.org.uk/report-a-breach. Keep a record of the breach and your assessment regardless of whether you notify.
### Individual Notification
If the breach is likely to result in high risk to individuals, you must notify affected individuals without undue delay.
### Documentation
All breaches, including those not reported to the ICO, must be logged in your Data Breach Register.
Sign in to save this resource.
Added 9 July 2026 · 0 views