After a personal data breach, a business should contain the incident, preserve evidence, identify what data was affected and assess the risk to the people involved.
Not every breach must be reported to the ICO, but where a breach is likely to create a risk to people’s rights and freedoms, notification is generally required within 72 hours of becoming aware of it. Higher-risk breaches may also require affected individuals to be informed.
Use the ICO personal data breach guidance. Kazzoo provides IT security support for Leicester businesses.
What should a business do after a ransomware attack?
What should be included in an IT business continuity plan?
Does a small business need cyber insurance?