For DPOs, privacy, legal, security, IT and leadership teams
The Breach Response Playbook
Handle a personal data breach from the first report to containment, notification and closure with a clear, deadline-aware and audit-ready workflow.
- First-hour incident report and 24-hour response checklist
- Response-team RACI and contact sheet
- Risk scoring matrix and notification decision tree
- Regulator and affected-individual notification guidance
- Breach register, closure review and audit checklist
A personal data breach starts a statutory clock
Breaches rarely arrive with a complete picture. Privacy, security, IT, legal, communications and leadership must act quickly while facts, affected people and regulatory duties are still being established.
This playbook connects the live incident file to the permanent breach register, helping teams contain harm, preserve evidence, make defensible notification decisions and prove what happened later.
Inside the Playbook
Seven stages for a defensible breach response
Report quickly, contain the incident, assess risk, decide who must be notified and retain a complete record. Fillable templates support each decision from the first hour to closure.
Prepare the team
Set roles before an incident with a fillable RACI and contact sheet for privacy, security, legal, communications and leadership.
Report and log
Capture the first report immediately, assign an incident owner and start a contemporaneous working record.
Contain and investigate
Limit further exposure, preserve evidence and establish what happened, when, to whom and through which systems.
Assess the risk
Use the fillable scoring matrix and decision tree to evaluate likelihood, severity and notification thresholds.
Notify appropriately
Prepare regulator and affected-individual communications, including guidance for the GDPR 72-hour window.
Review and close
Document DPO review, remedial actions, lessons learned and formal closure with accountable owners.
Maintain the register
Create a linked permanent register entry for every confirmed breach, including non-reportable incidents.
Who this is for
Written for the teams that detect, coordinate, investigate, communicate and approve personal data breach decisions.
- Data Protection Officers and privacy teams accountable for risk assessment and notification decisions
- Security and IT teams responsible for containment, investigation and evidence preservation
- Legal and communications teams managing regulator and affected-individual notifications
- Leadership and operational owners who need clear decisions, escalation and closure records
Frequently asked questions
About this toolkit
What types of personal data breach does the playbook cover?
It covers confidentiality, integrity and availability breaches, from misdirected emails and lost devices to ransomware and unauthorised access.
Does it include practical response templates?
Yes. It includes a RACI, contact sheet, incident report, first-24-hours checklist, risk matrix, notification letter, closure review and breach register entry.
How does it support the 72-hour deadline?
The workflow starts at first awareness, records key decisions and evidence, and guides regulator notification without waiting for every fact to be confirmed.
Should non-reportable breaches go in the register?
Yes. The playbook explains why every confirmed breach should be recorded, including the reasoning when notification is not required.
How is the playbook delivered?
Complete the form with a business email address and the PDF download link will be provided immediately and sent by email.
Co-produced by Formiti and Privacy360
A complete workflow, delivered or operationalised.
Formiti brings the advisory side: Legal Consultants who interpret the rules, Privacy Architects who convert them into a working governance programme, and Technical Operations engineers who implement the controls. Privacy360 is the platform that operationalises the same building blocks into an audit-ready system of record, connecting live incident response, risk decisions, notifications and the permanent breach register in one audit-ready record.
Next step
Breach response, ready before you need it
Once you have reviewed the Playbook, talk to us about preparing your response team, strengthening breach controls and supporting live incidents with experienced privacy specialists.