Data Breach Procedure
Last updated: May 2024
1. Purpose
This procedure outlines how Digital 3000 Ltd identifies, manages, investigates and reports actual or suspected personal data breaches.
The objective is to:
- Protect individuals whose information may be affected
- Minimise harm
- Meet obligations under UK GDPR and the Data Protection Act 2018
- Maintain accurate records of incidents
- Reduce the likelihood of future breaches
This procedure applies to all employees, contractors, consultants and third-party providers acting on behalf of Digital 3000 Ltd.
2. What Constitutes a Data Breach?
A personal data breach is any security incident that results in the accidental or unlawful:
- Loss of personal data
- Destruction of personal data
- Alteration of personal data
- Disclosure of personal data
- Access to personal data
Examples include:
- Sending information to the wrong recipient
- Lost or stolen laptops, phones or storage devices
- Misconfigured systems exposing personal information
- Unauthorised access to CRM systems
- Hacking, malware or ransomware attacks
- Phishing attacks
- Accidental deletion of records
- Disclosure of client information without authorisation
- Website security incidents
3. Immediate Reporting Requirements
Anyone who becomes aware of an actual or suspected breach must report it immediately.
Reports should be made to:
Data Protection Lead
Andrew Prophet
privacy@digital3000.co.uk
The report should include:
- Date and time of discovery
- Description of the incident
- Systems affected
- Information potentially affected
- Number of individuals affected (if known)
- Actions already taken
Staff or contractors must not attempt to conceal, delete or alter evidence relating to the incident.
4. Containment and Recovery
Upon becoming aware of a breach, Digital 3000 will take immediate action to contain the incident.
Examples may include:
- Resetting passwords
- Revoking user access
- Locking accounts
- Disconnecting compromised systems
- Restoring backups
- Suspending integrations
- Blocking malicious activity
The priority is to prevent further unauthorised access or disclosure.
5. Assessment of Risk
Digital 3000 will assess:
- The type of information involved
- The volume of information affected
- Whether special category data is involved
- Whether information was encrypted
- The likelihood of misuse
- Potential harm to affected individuals
Potential risks may include:
- Identity theft
- Financial loss
- Reputational damage
- Confidentiality breaches
- Unauthorised disclosure of business information
6. ICO Notification Requirements
Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, Digital 3000 will notify the Information Commissioner's Office (ICO) without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
Where notification is made after 72 hours, reasons for the delay will be documented.
7. Notification of Affected Individuals
Where a breach is likely to result in a high risk to individuals' rights and freedoms, Digital 3000 will notify affected individuals without undue delay.
Notifications may include:
- Description of the breach
- Information affected
- Likely consequences
- Steps already taken
- Recommended actions individuals should take
- Contact details for further information
8. Investigation and Documentation
Digital 3000 will maintain a Breach Register containing:
- Date and time of incident
- Nature of breach
- Cause of breach
- Information affected
- Individuals affected
- Risk assessment
- Containment measures
- Notification decisions
- Remedial actions
All breaches will be documented regardless of whether ICO notification is required.
9. Remediation and Prevention
Following investigation, Digital 3000 will identify opportunities to reduce future risk.
Actions may include:
- Updating security controls
- Implementing multi-factor authentication
- Improving access controls
- Additional encryption measures
- Revising procedures
- Staff awareness training
- Supplier reviews
- Technology upgrades
10. Roles and Responsibilities
Data Protection Lead
Responsible for:
- Coordinating breach responses
- Risk assessment
- ICO notifications
- Record keeping
- Implementing corrective actions
Staff and Contractors
Responsible for:
- Reporting incidents immediately
- Following security procedures
- Cooperating with investigations
Third-Party Providers
Responsible for:
- Reporting incidents affecting Digital 3000 data
- Cooperating with investigations
- Implementing agreed remedial actions
11. Contact Information
Data Protection Lead:
Andrew Prophet
Digital 3000 Ltd
privacy@digital3000.co.uk
General Enquiries:
info@digital3000.co.uk
ICO Website:
12. Review
This procedure will be reviewed annually or sooner if required due to:
- Changes in legislation
- Changes in technology
- Significant security incidents
- Changes to Digital 3000 services
Version: 1.0
Last Updated: 17 June 2026
