[HEADER — replace with your organisation’s letterhead, if used]
Data Breach Response
Containment, assessment and notification
Two things decide how this goes. Which regime applies — federal PDPL, DIFC or ADGM, each with its own regulator and its own timeline. And whether people report immediately or try to fix it quietly first, which is what loses containment time and destroys the logs needed to establish scope.
| Item | Detail |
|---|
| Organisation | [COMPANY NAME], [licence] [NUMBER] |
| Applicable regime | [Federal PDPL / DIFC / ADGM] |
| Regulator | [UAE Data Office / DIFC Commissioner / ADGM Office of Data Protection] |
| Data Protection Officer | [NAME], [EMAIL], [PHONE] |
| Report a breach to | [EMAIL] / [PHONE] — immediately, 24 hours |
| Incident lead | [NAME] |
| IT contact | [NAME] |
| External support | [Forensics / legal / insurer] |
| Working notification deadline | 72 hours from awareness — see the notes |
| Plan tested on | [DATE] |
1. What Counts as a Breach
1.1A personal data breach is any incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
| Type | Examples |
|---|
| Confidentiality | Email sent to the wrong recipient; misconfigured storage; account compromise; lost unencrypted device; data taken by a leaver |
| Integrity | Records altered without authority; ransomware encryption |
| Availability | Data deleted without backup; systems unavailable for an extended period |
| Physical | Files taken; unattended documents; discarded records not securely disposed |
| Third party | A processor or vendor breached, exposing your data |
1.2Availability is the type most often missed. Ransomware that encrypts personal data without exfiltrating it is still a breach.
2. First Hour