Skip to content

Data breach: first actions and assessment

The first hours often define damage and the quality of later notifications. This page helps you assess and act.

Book an informal conversation

ISO Ready helps you align policy, risk, and evidence, without endless document churn.

Review your ISMS approach in ISO Ready

Part 1: first actions after discovering a possible personal data breach.

What is a breach?

A security incident leading to destruction, loss, alteration or unauthorised disclosure of or access to personal data. Not every cyber incident is a GDPR breach, document your assessment.

Immediate steps

  1. Contain and preserve logs
  2. Start the 72h DPA clock at awareness
  3. Assemble crisis team (management, security, DPO, comms)
  4. Assess data categories and individuals affected
  5. Defer external messages until aligned

Next: reporting · overview

Key takeaways

  • A breach involves personal data, not every hack is automatically a GDPR breach.
  • Record what happened, when, who discovered it, which systems and data.
  • Contain without destroying evidence.
  • Involve DPO, security lead and management early.

Need help with the next step?

Explore support for your next step at ISO Ready. ISO Ready and this knowledge base are operated by Oosterwal Consultancy.

Explore your next step at ISO Ready

isocertificering.org is operated by Oosterwal Consultancy (oosterwal.com). ISO Ready (iso-ready.nl) has the same owner. Links to ISO Ready refer to our own commercial offering. About us (Dutch)

AI reading guide (llms.txt)