Report a Data Breach

Are you notifying personal data breach?

  • I am notifying a personal data breach to the ODPC as a data controller / on behalf of a data controller.
  • I am notifying a personal data breach to the ODPC as a data processor / on behalf of a data processor
Note
  • Only use this form if you are, or acting on behalf of, a data controller or data processor reporting a data breach in line with Section 43 of the Data Protection Act.

If you wish to report an entity for misuse of data or any concerns related to data handling, please file a formal complaint through the following link: 

File a Complaint

Section I: Details of the Controller

Mobile Number
Other Contact Details
Email Address
First & Last Name
First & Last Name

Section II: Details of the Breach

Description of Data Breach
Categories of persons affected by the data breach (e.g. customers, patients, employees, clients, children, vulnerable groups; etc.)
Additional details of the type of personal information involved in the data breach

Provide a detailed description of any action, including remedial action, you are taking, or intend to take to assist data subjects whose personal data was involved in the data breach.

(a) Short-term Measures (Immediate Actions):

Outline the immediate steps taken to secure the data and limit any potential damage.

(b) Medium-term Measures (System Improvements):

Detail the actions planned or in progress to strengthen data security systems.

(c) Long-term Measures (Policy and Training):

Describe the strategies for enhancing organizational data protection policies, including staff training programs on data security, updating incident response plans and regular compliance reviews.
Provide detailed description of any action you have taken, or are intending to take, to prevent reoccurrence
Date the breach occurred: (provide your best estimate if the exact date is not known)
Was the data breach reported after 72 hours of discovery?
Date the breach was discovered (provide your best estimate if the exact date is not known)
If other, please specify
Description of how the data breach occurred
Exact number of data subjects whose personal data is involved in the breach (please provide your best estimate)
Is there any other information you wish to provide at this stage, or any matters that you wish to draw to the ODPC’S attention?
Other entities affected: (if the data breach described above was also a data breach of another organization, provide their identity and contact details)
List of any other data protection authorities, law enforcement bodies or regulatory bodies that you have reported, or intend to report, this data breach to:

Section III: Communication With Data Subjects

Has the entity communicated with the data subjects affected by the breach?
Specify the steps your organization/ agency recommends that individuals take to reduce the risk that they experience serious harm as a result of this data breach

Section IV: Attachements

Drag & Drop Files, Choose Files to Upload You can upload up to 3 files.
Please attach any relevant documents that support your notification and actions regarding the data breach. This can include but is not limited to: (a) Sample Agreements (b) Incident Response Policy (c) Incident Reports
Drag & Drop Files, Choose Files to Upload You can upload up to 3 files.
Please attach any relevant documents that support your notification and actions regarding the data breach. This can include but is not limited to: (a) Sample Agreements (b) Incident Response Policy (c) Incident Reports
Drag & Drop Files, Choose Files to Upload
Attach Copy of Report to Other Regulator or Institutions, such as police or data protection authorities.

Section V: Request for Confidentiality

Request for Confidentiality
Declaration
The ODPC will respect the confidence of commercially or operationally sensitive information provided voluntarily in support of a data breach notification, and will only disclose this information after consulting with you, and with your agreement or where required by law.

Section VI: Review and Submit

Please review the information that you have provided about the data breach. If you would like to change anything, you can return to the relevant section and update.
Linda Data
ODPC Bot