Immediate response plan
Six steps create control and a reliable evidence trail.
Contain without destroying evidence
Block affected access, isolate systems and stop further loss. Avoid premature deletion or reinstallation where this could remove important evidence.
Preserve the timeline and facts
Record discovery time, known events, affected systems, data categories, groups of people and initial actions with timestamps. Protect logs, screenshots and reports.
Bring accountable people together
Connect privacy, information security, management and relevant business owners through one clear decision path. Ask service providers for specific facts and containment actions.
Assess risk to individuals
Consider possible consequences such as identity misuse, financial loss, discrimination, reputational harm or loss of control. Record data type, scale, safeguards and likelihood.
Decide on notification duties
Where notification to the authority is required, it must generally be made without undue delay and, where feasible, within 72 hours of awareness. A high risk may also require communication to affected individuals.
Evidence the decision and effectiveness
A reasoned decision not to notify must also be documented. After containment, assign root-cause actions, owners, dates and an effectiveness test.
What belongs in the incident file
The decision path matters as much as the outcome.
What happened and when?
Source of the report, systems, data, affected groups, scale, timeline and containment measures already taken.
Why was this action taken?
Risk assessment, notification decision, approvals, open uncertainties, owners and the planned effectiveness review.
Official legal basis
GDPR Articles 33 and 34 govern notification and communication.
This guide provides general orientation and does not replace individual legal advice. Do not send sensitive incident data or documents through the general contact form.