Data Breach Policy
First Class Support is committed to protecting the personal data it processes and complying with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and guidance issued by the Information Commissioner’s Office (ICO).
Definition of a personal data breach
A personal data breach is a security incident that results in the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of, or access to, personal data.
Examples may include:
• personal information being sent to the wrong recipient
• the loss or theft of documents, computers or other equipment
• unauthorised access to systems or records;
• personal information being disclosed without appropriate authority;
• cyberattacks, malware or compromised accounts; or
• personal data becoming unavailable when it is required.
Reporting a suspected breach
All employees, workers and contractors must report any actual or suspected personal data breach immediately to the Data Protection Lead at admin@firstclass-support.co.uk.
They should take any immediate and reasonable steps necessary to contain the incident, such as recalling an email or disconnecting a compromised device. However, they must not conceal the incident, delete relevant evidence or conduct an investigation without direction from the Data Protection Lead.
A suspected breach must be reported even where:
• it appears to have been resolved;
• no harm is immediately apparent;
• only one person’s information is affected; or
• the person reporting it is unsure whether it constitutes a personal data breach
Responsibility for managing breaches
First Class Support's Data Protection Lead is responsible for overseeing the management of personal data breaches and maintaining the organisation’s data breach register.
Every actual or suspected breach will be investigated promptly. The assessment will consider:
• the nature, sensitivity and volume of the personal data involved;
• whether special-category or other particularly sensitive information is involved;
• the number and categories of individuals affected;
• how easily affected individuals could be identified;
• the possible consequences for those individuals;
• the likelihood and severity of any risk to their rights and freedoms; and
• the measures available to contain the breach and reduce potential harm.
Notification to the ICO
Where a personal data breach is likely to result in a risk to individuals’ rights and freedoms, First Class Support will notify the ICO without undue delay and, where feasible, no later than 72 hours after becoming aware of it.
If notification is not made within 72 hours, First Class Support will document and explain the reasons for the delay.
The notification will include the information required by the UK GDPR, including, where available:
• the nature of the personal data breach;
• the categories and approximate number of affected individuals;
• the categories and approximate number of affected personal data records;
• the contact details of the Data Protection Lead or another appropriate contact;
• the likely consequences of the breach; and
• the measures taken or proposed to address the breach and reduce its possible adverse effects.
Notification to affected individuals
Where a personal data breach is likely to result in a high risk to the rights and freedoms of affected individuals, First Class Support will inform those individuals without undue delay, unless an applicable legal exemption applies.
The communication will be written in clear and plain language and will explain:
• the nature of the breach;
• the likely consequences;
• the measures taken or proposed to address it;
• any steps the individual should take to protect themselves; and
• who they may contact for further information.
Processing data on behalf of another organisation
Where First Class Support is processing personal data on behalf of another organisation, it will notify the relevant data controller without undue delay after becoming aware of a personal data breach.
First Class Support will also comply with any applicable contractual notification requirements and provide reasonable assistance to the data controller in assessing, investigating and responding to the breach.
Recording data breaches
All actual personal data breaches will be recorded in the data breach register, whether or not they are reported to the ICO or affected individuals.
The record will include:
• the date and time the breach occurred and was discovered;
• the circumstances and nature of the breach;
• the personal data and individuals affected;
• the likely consequences;
• the containment and remedial action taken;
• whether the ICO and affected individuals were notified;
• the reasons for any decision not to make a notification; and
• any measures identified to prevent a recurrence.
Records relating to suspected incidents that are determined not to constitute a personal data breach will also be retained where appropriate.
Containment and prevention
First Class Support will take appropriate steps to:
• contain and investigate each breach;
• minimise harm to affected individuals;
• preserve relevant evidence;
• recover affected information or systems where possible;
• address any security or procedural weaknesses; and
• reduce the likelihood of a similar breach occurring again.
Where appropriate, First Class Support will review its policies, systems, contracts, staff training and working practices following a breach.
Policy review
This policy will be reviewed regularly and following any significant personal data breach, change in relevant legislation or change to ICO guidance.