Log EVERY breach, not just reportable ones. Article 33(5) UK GDPR requires you to document all personal data breaches, including near misses and incidents below the reporting threshold. A breach that goes unlogged is a compliance failure in itself, regardless of its severity.
Record the breach reference number, date and time discovered, and date and time the incident occurred (or best estimate). This establishes the clock for the 72-hour ICO notification window under Article 33(1) UK GDPR. Number entries sequentially (e.g. DB-2024-001) for easy retrieval.
Record the nature of the breach: whether it is a confidentiality breach (unauthorised disclosure), integrity breach (unauthorised alteration), or availability breach (accidental loss or destruction). Include the categories and approximate number of individuals affected, and the categories and approximate volume of personal data records involved, as required by Article 33(3)(a) UK GDPR.
Record the risk assessment outcome. The test is whether the breach is 'likely to result in a risk to the rights and freedoms of individuals' (ICO notification threshold, Article 33(1)) and, separately, whether it poses a 'high risk' requiring notification to individuals (Article 34(1)). Record who made the risk decision, their role, and the date.
Record whether the ICO was notified: yes, no, or not required. If yes, record the date and time of notification (must be within 72 hours of becoming aware; if later, record the reason for delay). Log the ICO reference number once issued. If not required, record in one sentence why the risk threshold was not met.
Record whether affected individuals were notified: yes, no, or not required. The 'high risk' threshold for individual notification under Article 34(1) UK GDPR is higher than the ICO threshold. If notification was delayed or withheld, record the specific exemption relied on (Article 34(3)) and who authorised that decision.
All checks done
Team
Data Breach & Request Log
This log is the organisation's centralised record of every personal data breach and information rights request (including subject access requests), kept to satisfy Article 33(5) of the UK GDPR and the accountability principle under Article 5(2). Without it, the ICO has no evidence of compliance: fines of up to £17.5 million (or 4% of global annual turnover, whichever is higher) and enforcement notices are the cost of a gap.
12 checksPDF + printReviewed August 2026
Built on published UK guidance Show sources
UK GDPR Article 5(2) (accountability principle); UK GDPR Article 12(3) (rights response timescales); UK GDPR Article 33(1)(3)(4)(5) (breach notification to ICO and documentation); UK GDPR Article 34(1)(3) (notification to individuals); UK GDPR Article 38(4) (DPO consultation); Data Protection Act 2018 Section 155 (ICO penalty notices and fine tiers); Data (Use and Access) Act 2025 (fine tier extension to PECR, SAR stop-the-clock provisions)
£34one-off, yours forever
Replaces a DIY doc, and you get every future update free when the guidance changes.
3 for 2 on documents and packs. Add 3 and your cheapest is free.
A clean one-page PDF, ready to print
Opens and ticks off on any phone
Clear, no jargon, easy to follow
Free updates whenever the guidance changes
Secure checkout30-day money-backInstant downloadNo subscriptionCard & Apple Pay
Best valueSave 42%
Or get all 56 templates
The Everything Bundle: every template today and every future one.£399 one-off, instead of £686 bought separately.
Made for places like this
What’s on it
12 things to check.
Everything that matters, nothing that does not. Here is the full list, exactly as it appears on the template.
1Log EVERY breach, not just reportable ones. Article 33(5) UK GDPR requires you to document all personal data breaches, including near misses and incidents below the reporting threshold. A breach that goes unlogged is a compliance failure in itself, regardless of its severity.
2Record the breach reference number, date and time discovered, and date and time the incident occurred (or best estimate). This establishes the clock for the 72-hour ICO notification window under Article 33(1) UK GDPR. Number entries sequentially (e.g. DB-2024-001) for easy retrieval.
3Record the nature of the breach: whether it is a confidentiality breach (unauthorised disclosure), integrity breach (unauthorised alteration), or availability breach (accidental loss or destruction). Include the categories and approximate number of individuals affected, and the categories and approximate volume of personal data records involved, as required by Article 33(3)(a) UK GDPR.
4Record the risk assessment outcome. The test is whether the breach is 'likely to result in a risk to the rights and freedoms of individuals' (ICO notification threshold, Article 33(1)) and, separately, whether it poses a 'high risk' requiring notification to individuals (Article 34(1)). Record who made the risk decision, their role, and the date.
5Record whether the ICO was notified: yes, no, or not required. If yes, record the date and time of notification (must be within 72 hours of becoming aware; if later, record the reason for delay). Log the ICO reference number once issued. If not required, record in one sentence why the risk threshold was not met.
6Record whether affected individuals were notified: yes, no, or not required. The 'high risk' threshold for individual notification under Article 34(1) UK GDPR is higher than the ICO threshold. If notification was delayed or withheld, record the specific exemption relied on (Article 34(3)) and who authorised that decision.
7Log all information rights requests in the same register or a linked register. For each SAR or other rights request (erasure, rectification, restriction, portability, objection), record: date received, type of right invoked, date acknowledged, date responded. The response deadline is one calendar month from receipt under Article 12(3) UK GDPR, extendable by a further two months for complex or multiple requests (with notification sent within the first calendar month).
8Record the name and role of the person who assessed and managed the incident or request, and the name and role of the person who authorised the risk decision or the response. For organisations with a Data Protection Officer, note whether the DPO was consulted as required by Article 38(4) UK GDPR.
9Record the remedial action taken and the outcome. For breaches, describe the containment steps, any technical or organisational measures introduced, and whether the root cause has been resolved. Mark each entry as open or closed, and record the date it was closed.
10Review and sign off the log at least quarterly. A senior person (manager, DPO, or data protection lead) should review all open entries, check that closed entries are complete, and confirm that near misses are being captured. Date and initial each quarterly review in the log.
11Set and document a retention period for the log. The ICO does not prescribe a fixed period, but a minimum of three years from the date of closure is a widely adopted and defensible standard, long enough to cover any ICO investigation or civil limitation period. Record the basis for your chosen period in the log header.
12Keep the log secure and access-controlled. The log itself contains personal data about breach victims. Restrict access to those with a legitimate need. Do not store it in an unsecured shared folder. Record the access control method in the log header.
Good to know
Under Article 33(4) UK GDPR, where it is not possible to provide full breach details to the ICO within 72 hours, you may report in phases ('phased notification'). This is explicitly permitted and does not count against you, provided you submit what you know within 72 hours and supply the remaining information without undue further delay. The ICO's guidance confirms this; many organisations waste the window by waiting until they have the complete picture.
Source: UK GDPR Article 5(2) (accountability principle); UK GDPR Article 12(3) (rights response timescales); UK GDPR Article 33(1)(3)(4)(5) (breach notification to ICO and documentation); UK GDPR Article 34(1)(3) (notification to individuals); UK GDPR Article 38(4) (DPO consultation); Data Protection Act 2018 Section 155 (ICO penalty notices and fine tiers); Data (Use and Access) Act 2025 (fine tier extension to PECR, SAR stop-the-clock provisions)
Good to know
Questions, answered
What is the Data Breach & Request Log?
This log is the organisation's centralised record of every personal data breach and information rights request (including subject access requests), kept to satisfy Article 33(5) of the UK GDPR and the accountability principle under Article 5(2). Without it, the ICO has no evidence of compliance: fines of up to £17.5 million (or 4% of global annual turnover, whichever is higher) and enforcement notices are the cost of a gap.
Why does it matter?
Under Article 33(4) UK GDPR, where it is not possible to provide full breach details to the ICO within 72 hours, you may report in phases ('phased notification'). This is explicitly permitted and does not count against you, provided you submit what you know within 72 hours and supply the remaining information without undue further delay. The ICO's guidance confirms this; many organisations waste the window by waiting until they have the complete picture.
How do I get it, and is it up to date?
The PDF downloads the moment you check out, prints sharp in black and white, and opens on any phone. It is reviewed for August 2026 and you get any future update free when the official guidance changes.
A weak handover is the most common root cause of medication errors, choking on the wrong diet texture, missed post-fall checks, and pressure damage that goes unwatched. A sheet that names the specific person, number, and action passes information the next shift can act on immediately, and it is the record CQC reads back when something goes wrong.
Onboarding done right keeps the business clear of an illegal-working civil penalty (up to £60,000 per worker), of tribunal claims for a missing written statement or unlawful pay deductions, and of the early attrition that hits when someone leaves inside 90 days because day one was a mess. This is the order an onboarder actually works through, from legal must-dos to the things that make a new starter productive.
A new starter induction that is actually done, not just signed off, prevents two kinds of expensive failure: legal exposure (a £45,000 to £60,000 illegal-working penalty, an unfair dismissal or discrimination claim, an ICO breach, an HMRC tax-records penalty) and operational failure (someone who cannot evacuate the building, cannot log in for three days, or hits month five of probation with no documented reviews). Each item below names the document, the number or deadline, and the action, so it can be ticked off and evidenced.