![]() |
People Group Services Limited Company Number: 11570329 |
Data Breach Notification Procedure
Purpose
This document defines the operational process for reporting and managing a personal data breach in compliance with UK GDPR.
What is a Data Breach
A personal data breach is defined as:
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
Examples include:
- Sending payroll information to the wrong person
- Unauthorised access to contractor records
- Lost laptop containing personal data
- Cyber-attack exposing system databases
Immediate Action
If a data breach is suspected:
- Stop the incident if possible
- Secure the affected system
- Preserve evidence
- Report immediately
Reporting Timeline
Employees must report a suspected breach immediately.
The organisation must assess and, if required, notify the Information Commissioner's Office within 72 hours.
Internal Escalation
The following individuals must be notified:
- Compliance Officer / Data Protection Lead
- IT Security Lead
- Senior Management
If the incident involves client data, the relevant client may also need to be notified.
Breach Assessment
The following factors are assessed:
- Type of data involved
- Number of individuals affected
- Sensitivity of data
- Likelihood of harm to individuals
- Whether the data was encrypted
ICO Notification
If the breach poses risk to individuals, notification will include:
- Nature of the breach
- Categories of data affected
- Approximate number of individuals impacted
- Measures taken to mitigate damage
Notification to Individuals
Individuals will be notified where the breach may result in:
- Identity theft
- Financial loss
- Confidentiality compromise
Notifications will explain:
- What happened
- What information was involved
- Actions taken
- Advice to protect themselves
Incident Register
All breaches must be recorded in the company’s Data Breach Register.
This record includes:
- Date and time
- Nature of breach
- Investigation findings
- Corrective actions
Declaration
This Policy is approved by the Board of Directors of: People Group Services Limited Company Number: 11570329
Last updated: 10th March 2026

