Compliance

Data Breach Procedure

Last updated: May 2024

1. Purpose​‌​‌‌‌​​

This procedure outlines how Digital 3000 Ltd identifies, manages, investigates and reports actual or suspected personal data breaches.​‌​‌‌‌​​

The objective is to:​‌​‌‌‌​​

  • Protect individuals whose information may be affected​‌​‌‌‌​​
  • Minimise harm​‌​‌‌‌​​
  • Meet obligations under UK GDPR and the Data Protection Act 2018​‌​‌‌‌​​
  • Maintain accurate records of incidents​‌​‌‌‌​​
  • Reduce the likelihood of future breaches​‌​‌‌‌​​

This procedure applies to all employees, contractors, consultants and third-party providers acting on behalf of Digital 3000 Ltd.​‌​‌‌‌​​


2. What Constitutes a Data Breach?​‌​‌‌‌​​

A personal data breach is any security incident that results in the accidental or unlawful:​‌​‌‌‌​​

  • Loss of personal data​‌​‌‌‌​​
  • Destruction of personal data​‌​‌‌‌​​
  • Alteration of personal data​‌​‌‌‌​​
  • Disclosure of personal data​‌​‌‌‌​​
  • Access to personal data​‌​‌‌‌​​

Examples include:​‌​‌‌‌​​

  • Sending information to the wrong recipient​‌​‌‌‌​​
  • Lost or stolen laptops, phones or storage devices​‌​‌‌‌​​
  • Misconfigured systems exposing personal information​‌​‌‌‌​​
  • Unauthorised access to CRM systems​‌​‌‌‌​​
  • Hacking, malware or ransomware attacks​‌​‌‌‌​​
  • Phishing attacks​‌​‌‌‌​​
  • Accidental deletion of records​‌​‌‌‌​​
  • Disclosure of client information without authorisation​‌​‌‌‌​​
  • Website security incidents​‌​‌‌‌​​

3. Immediate Reporting Requirements​‌​‌‌‌​​

Anyone who becomes aware of an actual or suspected breach must report it immediately.​‌​‌‌‌​​

Reports should be made to:​‌​‌‌‌​​

Data Protection Lead​‌​‌‌‌​​
Andrew Prophet​‌​‌‌‌​​
privacy@digital3000.co.uk​‌​‌‌‌​​

The report should include:​‌​‌‌‌​​

  • Date and time of discovery​‌​‌‌‌​​
  • Description of the incident​‌​‌‌‌​​
  • Systems affected​‌​‌‌‌​​
  • Information potentially affected​‌​‌‌‌​​
  • Number of individuals affected (if known)​‌​‌‌‌​​
  • Actions already taken​‌​‌‌‌​​

Staff or contractors must not attempt to conceal, delete or alter evidence relating to the incident.​‌​‌‌‌​​


4. Containment and Recovery​‌​‌‌‌​​

Upon becoming aware of a breach, Digital 3000 will take immediate action to contain the incident.​‌​‌‌‌​​

Examples may include:​‌​‌‌‌​​

  • Resetting passwords​‌​‌‌‌​​
  • Revoking user access​‌​‌‌‌​​
  • Locking accounts​‌​‌‌‌​​
  • Disconnecting compromised systems​‌​‌‌‌​​
  • Restoring backups​‌​‌‌‌​​
  • Suspending integrations​‌​‌‌‌​​
  • Blocking malicious activity​‌​‌‌‌​​

The priority is to prevent further unauthorised access or disclosure.​‌​‌‌‌​​


5. Assessment of Risk​‌​‌‌‌​​

Digital 3000 will assess:​‌​‌‌‌​​

  • The type of information involved​‌​‌‌‌​​
  • The volume of information affected​‌​‌‌‌​​
  • Whether special category data is involved​‌​‌‌‌​​
  • Whether information was encrypted​‌​‌‌‌​​
  • The likelihood of misuse​‌​‌‌‌​​
  • Potential harm to affected individuals​‌​‌‌‌​​

Potential risks may include:​‌​‌‌‌​​

  • Identity theft​‌​‌‌‌​​
  • Financial loss​‌​‌‌‌​​
  • Reputational damage​‌​‌‌‌​​
  • Confidentiality breaches​‌​‌‌‌​​
  • Unauthorised disclosure of business information​‌​‌‌‌​​

6. ICO Notification Requirements​‌​‌‌‌​​

Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, Digital 3000 will notify the Information Commissioner's Office (ICO) without undue delay and, where feasible, within 72 hours of becoming aware of the breach.​‌​‌‌‌​​

Where notification is made after 72 hours, reasons for the delay will be documented.​‌​‌‌‌​​


7. Notification of Affected Individuals​‌​‌‌‌​​

Where a breach is likely to result in a high risk to individuals' rights and freedoms, Digital 3000 will notify affected individuals without undue delay.​‌​‌‌‌​​

Notifications may include:​‌​‌‌‌​​

  • Description of the breach​‌​‌‌‌​​
  • Information affected​‌​‌‌‌​​
  • Likely consequences​‌​‌‌‌​​
  • Steps already taken​‌​‌‌‌​​
  • Recommended actions individuals should take​‌​‌‌‌​​
  • Contact details for further information​‌​‌‌‌​​

8. Investigation and Documentation​‌​‌‌‌​​

Digital 3000 will maintain a Breach Register containing:​‌​‌‌‌​​

  • Date and time of incident​‌​‌‌‌​​
  • Nature of breach​‌​‌‌‌​​
  • Cause of breach​‌​‌‌‌​​
  • Information affected​‌​‌‌‌​​
  • Individuals affected​‌​‌‌‌​​
  • Risk assessment​‌​‌‌‌​​
  • Containment measures​‌​‌‌‌​​
  • Notification decisions​‌​‌‌‌​​
  • Remedial actions​‌​‌‌‌​​

All breaches will be documented regardless of whether ICO notification is required.​‌​‌‌‌​​


9. Remediation and Prevention​‌​‌‌‌​​

Following investigation, Digital 3000 will identify opportunities to reduce future risk.​‌​‌‌‌​​

Actions may include:​‌​‌‌‌​​

  • Updating security controls​‌​‌‌‌​​
  • Implementing multi-factor authentication​‌​‌‌‌​​
  • Improving access controls​‌​‌‌‌​​
  • Additional encryption measures​‌​‌‌‌​​
  • Revising procedures​‌​‌‌‌​​
  • Staff awareness training​‌​‌‌‌​​
  • Supplier reviews​‌​‌‌‌​​
  • Technology upgrades​‌​‌‌‌​​

10. Roles and Responsibilities​‌​‌‌‌​​

Data Protection Lead​‌​‌‌‌​​

Responsible for:​‌​‌‌‌​​

  • Coordinating breach responses​‌​‌‌‌​​
  • Risk assessment​‌​‌‌‌​​
  • ICO notifications​‌​‌‌‌​​
  • Record keeping​‌​‌‌‌​​
  • Implementing corrective actions​‌​‌‌‌​​

Staff and Contractors​‌​‌‌‌​​

Responsible for:​‌​‌‌‌​​

  • Reporting incidents immediately​‌​‌‌‌​​
  • Following security procedures​‌​‌‌‌​​
  • Cooperating with investigations​‌​‌‌‌​​

Third-Party Providers​‌​‌‌‌​​

Responsible for:​‌​‌‌‌​​

  • Reporting incidents affecting Digital 3000 data​‌​‌‌‌​​
  • Cooperating with investigations​‌​‌‌‌​​
  • Implementing agreed remedial actions​‌​‌‌‌​​

11. Contact Information​‌​‌‌‌​​

Data Protection Lead:​‌​‌‌‌​​

Andrew Prophet​‌​‌‌‌​​
Digital 3000 Ltd​‌​‌‌‌​​

privacy@digital3000.co.uk​‌​‌‌‌​​

General Enquiries:​‌​‌‌‌​​

info@digital3000.co.uk​‌​‌‌‌​​

ICO Website:​‌​‌‌‌​​

https://ico.org.uk​‌​‌‌‌​​


12. Review​‌​‌‌‌​​

This procedure will be reviewed annually or sooner if required due to:​‌​‌‌‌​​

  • Changes in legislation​‌​‌‌‌​​
  • Changes in technology​‌​‌‌‌​​
  • Significant security incidents​‌​‌‌‌​​
  • Changes to Digital 3000 services​‌​‌‌‌​​

Version:​‌​‌‌‌​​ 1.0​‌​‌‌‌​​
Last Updated:​‌​‌‌‌​​ 17 June 2026​‌​‌‌‌​​