[HEADER — replace with your organisation’s letterhead, if used]
Data Breach Response Plan
[COMPANY NAME]
Two clocks run. Assessment must be prompt and reasonable, completed within 30 days. Where the breach is determined notifiable, the Commission must be notified within 3 calendar days of that determination, and affected individuals as soon as practicable. The three days runs from determination, not discovery — which is why the determination date must be recorded.
| Item | Detail |
|---|
| Organisation | [COMPANY NAME], UEN [UEN] |
| Data Protection Officer | [NAME], [EMAIL], [PHONE] |
| Deputy | [NAME], [EMAIL], [PHONE] |
| Report a suspected breach to | [EMAIL] and [PHONE] — immediately, at any hour |
| Incident response team | [DPO, IT lead, legal, communications, business owner] |
| External support on call | [Forensic provider / Legal adviser / Insurer — names and numbers] |
| Cyber insurance | [Insurer, policy number, notification requirement] |
| Approved by | [NAME], [DESIGNATION], on [DATE] |
| Last tested | [DATE] |
1. What Counts as a Data Breach
1.1A data breach is the unauthorised access, collection, use, disclosure, copying, modification or disposal of personal data, or the loss of a storage medium or device on which personal data is stored where unauthorised access is likely.
| Type | Examples |
|---|
| Malicious | Hacking, ransomware, phishing leading to account compromise, insider theft, credential stuffing |
| Accidental | Email sent to the wrong recipient, attachment containing more data than intended, misconfigured cloud storage, mis-set access permissions |
| Physical | Lost or stolen laptop, phone or USB drive; documents left behind; unsecured disposal of records |
| Vendor | A breach at a processor holding data on our behalf — our obligation, not only theirs |
| System | A software fault exposing data to the wrong users; a database left accessible without authentication |
1.2A near miss — where a breach was prevented or the data recovered before access occurred — should still be reported internally and recorded.
2. Report Immediately — Do Not Assess First
2.1Any person who suspects a breach must report it immediately to the Data Protection Officer, at any hour, using the contacts above.
2.2Do not attempt to assess whether it is serious, investigate the cause, or fix it before reporting. Containment time is the most valuable resource in a breach, and well-meaning attempts to resolve something quietly are the most common cause of its loss.