People Group Services
SOLE
EMPLOYMENT
POLICY DOCUMENT LIBRARY
Company Policy Documents
People Group Services Limited
Company Number: 11570329

Data Breach Notification Procedure

Purpose

This document defines the operational process for reporting and managing a personal data breach in compliance with UK GDPR.

What is a Data Breach

A personal data breach is defined as:

A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.

Examples include:

  • Sending payroll information to the wrong person
  • Unauthorised access to contractor records
  • Lost laptop containing personal data
  • Cyber-attack exposing system databases

Immediate Action

If a data breach is suspected:

  • Stop the incident if possible
  • Secure the affected system
  • Preserve evidence
  • Report immediately

Reporting Timeline

Employees must report a suspected breach immediately.

The organisation must assess and, if required, notify the Information Commissioner's Office within 72 hours.

Internal Escalation

The following individuals must be notified:

  • Compliance Officer / Data Protection Lead
  • IT Security Lead
  • Senior Management

If the incident involves client data, the relevant client may also need to be notified.

Breach Assessment

The following factors are assessed:

  • Type of data involved
  • Number of individuals affected
  • Sensitivity of data
  • Likelihood of harm to individuals
  • Whether the data was encrypted

ICO Notification

If the breach poses risk to individuals, notification will include:

  • Nature of the breach
  • Categories of data affected
  • Approximate number of individuals impacted
  • Measures taken to mitigate damage

Notification to Individuals

Individuals will be notified where the breach may result in:

  • Identity theft
  • Financial loss
  • Confidentiality compromise

Notifications will explain:

  • What happened
  • What information was involved
  • Actions taken
  • Advice to protect themselves

Incident Register

All breaches must be recorded in the company’s Data Breach Register.

This record includes:

  • Date and time
  • Nature of breach
  • Investigation findings
  • Corrective actions

Declaration

This Policy is approved by the Board of Directors of: People Group Services Limited Company Number: 11570329

Last updated: 10th March 2026