- Supports the operational workflow for starting the breach clock, logging facts, assessing risk, containing the breach, and submitting an ICO report if required.
References and citations
- Explains the UK GDPR duty to report certain personal data breaches to the ICO within 72 hours where feasible and to inform individuals where high risk is likely.
"report certain personal data breaches to the relevant supervisory authority"
- Supports the report-early, update-later approach where the organisation cannot provide a complete picture within the 72-hour reporting period.