People Group Services
CIS
POLICY DOCUMENT LIBRARY
Company Policy Documents
People Group Services Limited
Company Number: 11570329

Data Incident Response Policy

Purpose

The purpose of this Data Incident Response Policy is to establish a clear and structured framework for identifying, reporting, managing, and resolving data security incidents involving personal or sensitive information processed by People Group Services Ltd.

This policy ensures that any actual or suspected data breach is handled swiftly and effectively to:

  • Protect individuals whose data may be affected
  • Maintain compliance with UK GDPR
  • Meet statutory reporting obligations under the Data Protection Act 2018
  • Minimise operational, financial, and reputational damage
  • Ensure transparency and accountability across the organisation

Scope

This policy applies to:

  • All employees
  • Contractors and consultants
  • Temporary staff
  • Agency workers
  • Third-party service providers
  • Technology partners and system administrators

It applies to all systems, data, and information assets owned, managed, or processed by People Group Services Ltd including:

  • Payroll systems
  • Agency portals
  • MSP platforms
  • Compliance systems
  • Contractor onboarding platforms
  • Cloud storage services
  • Internal company systems
  • Email and communications systems

Definition of a Data Incident

A data incident is any event that compromises or may compromise the:

  • Confidentiality
  • Integrity
  • Availability
  • Security

of personal data or company information.

Examples include:

Personal Data Breach

A breach involving:

  • Unauthorised access to personal data
  • Accidental disclosure of personal information
  • Loss of devices containing personal data
  • Hacking or cyber-attack
  • Unauthorised system access

Data Loss

Loss or destruction of data due to:

  • Hardware failure
  • System malfunction
  • Human error
  • Malware or ransomware

Data Exposure

Situations where personal or confidential data may have been viewed or accessed without authorisation.

Examples:

  • Email sent to the wrong recipient
  • Shared folders exposed publicly
  • Misconfigured databases
  • Incorrect permissions

Legal and Regulatory Framework

This policy is designed to ensure compliance with:

  • UK GDPR
  • Data Protection Act 2018
  • Information Commissioner's Office guidance
  • UK cyber-security best practice issued by the National Cyber Security Centre

Where required, data breaches must be reported to the ICO within 72 hours.

Roles and Responsibilities

Data Protection Officer / Compliance Lead

Responsible for:

  • Assessing the severity of incidents
  • Determining reporting requirements
  • Liaising with regulators
  • Managing breach notifications
  • Maintaining breach records

 IT Security Team

Responsible for:

  • Investigating the technical cause of the incident
  • Securing affected systems
  • Preventing further compromise
  • Preserving forensic evidence
  • Restoring services

5.3 Management Team

Responsible for:

  • Oversight of incident handling
  • Escalation decisions
  • Client communications
  • Regulatory reporting approval

Employees and Contractors

All staff must:

  • Immediately report any suspected data incident
  • Cooperate with investigations
  • Follow security and reporting procedures

Failure to report incidents promptly may result in disciplinary action.

Incident Reporting Procedure

Any employee or contractor who becomes aware of a potential data incident must report it immediately.

Reports should include:

  • Description of the incident
  • Date and time identified
  • Systems or data affected
  • Individuals potentially impacted
  • Steps already taken

Reports must be sent to:

Email: compliance@peoplegroupservices.com
Escalation: Data Protection Officer / Senior Management

Where necessary, incidents may also be reported through internal incident reporting systems.

Incident Response Process

The People Group Services Data Incident Response Process follows five stages.

Stage 1 — Identification

The organisation must identify:

  • What happened
  • When it occurred
  • What data may be affected
  • Whether personal data is involved

Sources may include:

  • Staff reports
  • System alerts
  • Security monitoring tools
  • Third-party notifications

Stage 2 — Containment

Immediate steps will be taken to prevent further damage, including:

  • Restricting system access
  • Resetting passwords
  • Isolating affected systems
  • Removing exposed files
  • Blocking compromised accounts

Stage 3 — Investigation

A detailed investigation will determine:

  • Root cause of the incident
  • Data affected
  • Individuals impacted
  • Risk level
  • Whether malicious activity occurred

Evidence will be preserved for forensic analysis if required.

Stage 4 — Notification

If the incident constitutes a personal data breach likely to result in risk to individuals, the organisation will:

Notify the Information Commissioner's Office within 72 hours.

Where the breach presents high risk, affected individuals will also be informed.

Notifications will include:

  • Nature of the breach
  • Types of data involved
  • Likely consequences
  • Actions taken
  • Advice for affected individuals

Stage 5 — Recovery and Remediation

Following the incident, the organisation will:

  • Restore systems and data
  • Implement corrective measures
  • Strengthen security controls
  • Update procedures
  • Conduct staff training where necessary

Incident Severity Classification

Incidents will be categorised according to severity:

Level

Description

Low

Minor incident with no personal data exposure

Medium

Limited personal data exposure with low risk

High

Significant personal data exposure

Critical

Large scale breach or serious cyber attack

Critical incidents will be escalated immediately to senior management.

Record Keeping

All incidents must be documented in the organisation’s Data Breach Register.

Records must include:

  • Date and time of incident
  • Description
  • Investigation findings
  • Risk assessment
  • Actions taken
  • Notifications made

Records will be retained for regulatory compliance.

Third-Party Incidents

Where an incident originates from a supplier, partner, or service provider, People Group Services Ltd will:

  • Require immediate notification
  • Conduct its own investigation
  • Ensure corrective measures are implemented
  • Assess contractual obligations and liability

Third-party processors must comply with data processing agreements.

Training and Awareness

All staff must receive data protection and cyber security training covering:

  • Data breach recognition
  • Reporting procedures
  • Secure handling of personal data
  • Incident response responsibilities

Training will be refreshed annually.

Policy Review

This policy will be reviewed:

  • Annually
  • Following any major incident
  • Following regulatory updates
  • Following organisational changes

Contact Information

Data protection and incident reporting enquiries should be directed to:

Compliance Team
People Group Services Ltd

Email: compliance@peoplegroupservices.com
Website: www.peoplegroupservices.com

 

Declaration

This Policy is approved by the Board of Directors of: People Group Services Limited Company Number: 11570329

Last updated: 10th March 2026