![]() |
People Group Services Limited Company Number: 11570329 |
Data Incident Response Policy
Purpose
The purpose of this Data Incident Response Policy is to establish a clear and structured framework for identifying, reporting, managing, and resolving data security incidents involving personal or sensitive information processed by People Group Services Ltd.
This policy ensures that any actual or suspected data breach is handled swiftly and effectively to:
- Protect individuals whose data may be affected
- Maintain compliance with UK GDPR
- Meet statutory reporting obligations under the Data Protection Act 2018
- Minimise operational, financial, and reputational damage
- Ensure transparency and accountability across the organisation
Scope
This policy applies to:
- All employees
- Contractors and consultants
- Temporary staff
- Agency workers
- Third-party service providers
- Technology partners and system administrators
It applies to all systems, data, and information assets owned, managed, or processed by People Group Services Ltd including:
- Payroll systems
- Agency portals
- MSP platforms
- Compliance systems
- Contractor onboarding platforms
- Cloud storage services
- Internal company systems
- Email and communications systems
Definition of a Data Incident
A data incident is any event that compromises or may compromise the:
- Confidentiality
- Integrity
- Availability
- Security
of personal data or company information.
Examples include:
Personal Data Breach
A breach involving:
- Unauthorised access to personal data
- Accidental disclosure of personal information
- Loss of devices containing personal data
- Hacking or cyber-attack
- Unauthorised system access
Data Loss
Loss or destruction of data due to:
- Hardware failure
- System malfunction
- Human error
- Malware or ransomware
Data Exposure
Situations where personal or confidential data may have been viewed or accessed without authorisation.
Examples:
- Email sent to the wrong recipient
- Shared folders exposed publicly
- Misconfigured databases
- Incorrect permissions
Legal and Regulatory Framework
This policy is designed to ensure compliance with:
- UK GDPR
- Data Protection Act 2018
- Information Commissioner's Office guidance
- UK cyber-security best practice issued by the National Cyber Security Centre
Where required, data breaches must be reported to the ICO within 72 hours.
Roles and Responsibilities
Data Protection Officer / Compliance Lead
Responsible for:
- Assessing the severity of incidents
- Determining reporting requirements
- Liaising with regulators
- Managing breach notifications
- Maintaining breach records
IT Security Team
Responsible for:
- Investigating the technical cause of the incident
- Securing affected systems
- Preventing further compromise
- Preserving forensic evidence
- Restoring services
5.3 Management Team
Responsible for:
- Oversight of incident handling
- Escalation decisions
- Client communications
- Regulatory reporting approval
Employees and Contractors
All staff must:
- Immediately report any suspected data incident
- Cooperate with investigations
- Follow security and reporting procedures
Failure to report incidents promptly may result in disciplinary action.
Incident Reporting Procedure
Any employee or contractor who becomes aware of a potential data incident must report it immediately.
Reports should include:
- Description of the incident
- Date and time identified
- Systems or data affected
- Individuals potentially impacted
- Steps already taken
Reports must be sent to:
Email: compliance@peoplegroupservices.com
Escalation: Data Protection Officer / Senior Management
Where necessary, incidents may also be reported through internal incident reporting systems.
Incident Response Process
The People Group Services Data Incident Response Process follows five stages.
Stage 1 — Identification
The organisation must identify:
- What happened
- When it occurred
- What data may be affected
- Whether personal data is involved
Sources may include:
- Staff reports
- System alerts
- Security monitoring tools
- Third-party notifications
Stage 2 — Containment
Immediate steps will be taken to prevent further damage, including:
- Restricting system access
- Resetting passwords
- Isolating affected systems
- Removing exposed files
- Blocking compromised accounts
Stage 3 — Investigation
A detailed investigation will determine:
- Root cause of the incident
- Data affected
- Individuals impacted
- Risk level
- Whether malicious activity occurred
Evidence will be preserved for forensic analysis if required.
Stage 4 — Notification
If the incident constitutes a personal data breach likely to result in risk to individuals, the organisation will:
Notify the Information Commissioner's Office within 72 hours.
Where the breach presents high risk, affected individuals will also be informed.
Notifications will include:
- Nature of the breach
- Types of data involved
- Likely consequences
- Actions taken
- Advice for affected individuals
Stage 5 — Recovery and Remediation
Following the incident, the organisation will:
- Restore systems and data
- Implement corrective measures
- Strengthen security controls
- Update procedures
- Conduct staff training where necessary
Incident Severity Classification
Incidents will be categorised according to severity:
|
Level |
Description |
|---|---|
|
Low |
Minor incident with no personal data exposure |
|
Medium |
Limited personal data exposure with low risk |
|
High |
Significant personal data exposure |
|
Critical |
Large scale breach or serious cyber attack |
Critical incidents will be escalated immediately to senior management.
Record Keeping
All incidents must be documented in the organisation’s Data Breach Register.
Records must include:
- Date and time of incident
- Description
- Investigation findings
- Risk assessment
- Actions taken
- Notifications made
Records will be retained for regulatory compliance.
Third-Party Incidents
Where an incident originates from a supplier, partner, or service provider, People Group Services Ltd will:
- Require immediate notification
- Conduct its own investigation
- Ensure corrective measures are implemented
- Assess contractual obligations and liability
Third-party processors must comply with data processing agreements.
Training and Awareness
All staff must receive data protection and cyber security training covering:
- Data breach recognition
- Reporting procedures
- Secure handling of personal data
- Incident response responsibilities
Training will be refreshed annually.
Policy Review
This policy will be reviewed:
- Annually
- Following any major incident
- Following regulatory updates
- Following organisational changes
Contact Information
Data protection and incident reporting enquiries should be directed to:
Compliance Team
People Group Services Ltd
Email: compliance@peoplegroupservices.com
Website: www.peoplegroupservices.com
Declaration
This Policy is approved by the Board of Directors of: People Group Services Limited Company Number: 11570329
Last updated: 10th March 2026

