Data Protection

Data Breach Response

Two things decide how this goes. **Which regime applies** — federal PDPL, DIFC or ADGM, each with its own regulator and its own timeline. And whether people **report immediately or try to fix it quietly first**, which is what loses containment time and destroys the logs needed to establish scope.

Download as Word6 pages20 KBFree
[HEADER — replace with your organisation’s letterhead, if used]

Data Breach Response

Containment, assessment and notification

Two things decide how this goes. Which regime applies — federal PDPL, DIFC or ADGM, each with its own regulator and its own timeline. And whether people report immediately or try to fix it quietly first, which is what loses containment time and destroys the logs needed to establish scope.

ItemDetail
Organisation[COMPANY NAME], [licence] [NUMBER]
Applicable regime[Federal PDPL / DIFC / ADGM]
Regulator[UAE Data Office / DIFC Commissioner / ADGM Office of Data Protection]
Data Protection Officer[NAME], [EMAIL], [PHONE]
Report a breach to[EMAIL] / [PHONE]immediately, 24 hours
Incident lead[NAME]
IT contact[NAME]
External support[Forensics / legal / insurer]
Working notification deadline72 hours from awarenesssee the notes
Plan tested on[DATE]

1. What Counts as a Breach

1.1A personal data breach is any incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.

TypeExamples
ConfidentialityEmail sent to the wrong recipient; misconfigured storage; account compromise; lost unencrypted device; data taken by a leaver
IntegrityRecords altered without authority; ransomware encryption
AvailabilityData deleted without backup; systems unavailable for an extended period
PhysicalFiles taken; unattended documents; discarded records not securely disposed
Third partyA processor or vendor breached, exposing your data

1.2Availability is the type most often missed. Ransomware that encrypts personal data without exfiltrating it is still a breach.

2. First Hour

Generated from www.helionerp.com1

5 more pages in the Word file

This is page 1 of the Word document, exactly as it appears when you open it. Fields shown like THIS are placeholders for you to complete.

Notes for use

These notes accompany the template and explain the drafting choices, the compliance points and the mistakes most often made with this document. They appear as a final page in the Word file, intended to be deleted before the document is executed.

Report first, investigate second

The instruction to staff must be to report immediately without attempting to assess or resolve. The most damaging delays come from a well-intentioned attempt to fix something quietly, which loses containment time and often destroys the logs needed to establish what was accessed.

Awareness starts the clock

The notification deadline runs from when the organisation first became aware, not from when the investigation concluded. Record the time of discovery and by whom, contemporaneously — reconstructing it later is both unconvincing and usually unfavourable.

Confirm the deadline for your regime

Federal PDPL notification timing depends in part on the Executive Regulations, whose status is reported inconsistently. DIFC requires notification as soon as practicable in the circumstances. Adopting 72 hours as an internal working standard is defensible while the position is confirmed; guessing a longer period is not.

Preserve logs before remediating

Rebuilding a compromised machine or restoring from backup destroys the evidence needed to determine whether personal data was actually accessed — which is the question the whole assessment turns on. Image or preserve first.

Encryption can change the assessment materially

Where the data was encrypted and the keys were not compromised, the risk to individuals may be substantially lower and the notification analysis different. This is one of the strongest arguments for encrypting at rest before anything happens.

Availability breaches count

Ransomware that encrypts personal data without exfiltrating it, or deletion without a backup, is a breach. Organisations focused on data theft miss this category entirely and conclude no breach occurred.

Record why you did not notify

Organisations document notified breaches and record nothing about those assessed and dismissed. If the decision is later questioned, an absent record is indistinguishable from never having assessed. Log the reasoning either way.

Do not delay to complete the investigation

Initial notification should be prompt and incomplete, with detail following. Waiting until the picture is clear routinely blows the deadline, and regulators treat late notification more seriously than an incomplete first report.

Processor breaches are your breach

Where a vendor is compromised, the controller carries the regulatory obligation. Require immediate notification in the contract — 24 hours — and full information rather than accepting "under investigation" while your own deadline runs.

More than one regulator may apply

A group with mainland and DIFC entities may face two regimes, and affected individuals in other countries may bring other regulators into play. Establish the map before an incident, not during one.

Write to individuals so they can act

A notification full of hedged language tells people nothing. Say plainly what happened, what data was involved, what the realistic risk is, and what specific step they should take. Minimising the description is the thing people remember afterwards.

Find the cause, not the culprit

An investigation aimed at identifying who is to blame produces defensive accounts and no learning, and it discourages the next person from reporting quickly. Aim at the cause — the misconfiguration, the missing control, the process gap.

Notify the insurer early

Cyber policies carry their own notification deadlines and often provide access to forensics and legal support that materially improves the response. Late notification can prejudice cover at the moment it is most needed.

Test the plan before you need it

A plan nobody has walked through fails on the basics — who has authority to disable an account at 2am, who holds the regulator contact details, where the incident log lives. An annual tabletop exercise surfaces all of it cheaply.

Current as of

Reflects UAE, DIFC and ADGM positions current as of {{DATE OF USE}}. **The federal PDPL Executive Regulations status is reported inconsistently and the notification deadline must be verified.** DIFC and ADGM requirements and penalty levels change — confirm with the relevant regulator or a UAE data protection adviser and update this plan accordingly.

This is a ready-to-use template provided for convenience. Laws and requirements change, and every situation is different — please have it reviewed by a qualified professional (a lawyer, corporate secretary, or accountant as relevant) before you rely on it.