Ga naar inhoud

Data breach: first actions and assessment

The first hours often define damage and the quality of later notifications. This page helps you assess and act.

Book an informal conversation

ISO Ready helps you align policy, risk, and evidence — without endless document churn.

Review your ISMS approach in ISO Ready

Part 1: first actions after discovering a possible personal data breach.

What is a breach?

A security incident leading to destruction, loss, alteration or unauthorised disclosure of or access to personal data. Not every cyber incident is a GDPR breach — document your assessment.

Immediate steps

  1. Contain and preserve logs
  2. Start the 72h DPA clock at awareness
  3. Assemble crisis team (management, security, DPO, comms)
  4. Assess data categories and individuals affected
  5. Defer external messages until aligned

Next: reporting · overview

Key takeaways

  • A breach involves personal data — not every hack is automatically a GDPR breach.
  • Record what happened, when, who discovered it, which systems and data.
  • Contain without destroying evidence.
  • Involve DPO, security lead and management early.

Run the ISO 27001 readiness scan

See where you stand before investing in documents or consultants.

Start the readiness scan