Preparing a Breach Response Plan Print

  • 0

Before you need it.

WHAT IT SHOULD CONTAIN

How a breach is reported internally Who assesses it Who decides on notification Who contacts the regulator Who contacts individuals Who handles media enquiries Contact details for all of them, including out of hours

WHY OUT OF HOURS SPECIFICALLY

Breaches are discovered at inconvenient times.

WHAT TO DEFINE

What staff should do on suspecting a breach.

WHAT THE INSTRUCTION SHOULD BE

Report it immediately, to a named route.

WHY IMMEDIATELY

The notification clock runs from organisational awareness.

WHAT TO AVOID

A culture where reporting leads to blame.

WHY

Concealed breaches become far worse.

WHAT TO PREPARE

Templates for regulator and individual notification A record form capturing the required details

WHAT TO RECORD FOR EVERY BREACH

Including those not notified.

WHY

You may need to demonstrate the assessment.

WHAT TO PRACTISE

A walkthrough with a realistic scenario.

WHAT THAT REVEALS

Gaps in contacts, authority and understanding.

WHAT TO REVIEW AFTERWARDS

The plan, against what actually happened.

WHAT TO ESTABLISH WITH PROCESSORS

That they notify you without undue delay.

WHY

Your clock depends on theirs.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot