Data breach: what to do in the first hours

What to do when a personal data breach happens: containing the damage, assessing the risk, notifications and documentation.

A lost laptop, an email sent to the wrong person or a ransomware attack are all personal data breaches. What you do in the first hours decides how large the damage will be, for people and for the organization.

First steps

  • Stop the leak: isolate the system, change passwords, recall the email if you can.
  • Delete nothing. You need the logs and evidence to understand what happened.
  • Immediately inform the person responsible for incidents and the DPO.

Assess what happened

  • What data is affected and how sensitive is it?
  • How many people are affected?
  • Is the data encrypted or unreadable to anyone else?
  • What could the consequences be for people: fraud, discrimination, financial loss?

Notifications

Under the GDPR, with which Law 124/2024 is aligned, a breach is notified to the supervisory authority within 72 hours of the organization becoming aware of it, unless it is unlikely to result in a risk to people. When the risk is high, the affected people are also told, in plain language and with advice on how to protect themselves.

72 hours pass quickly, especially over a weekend. Decide in advance who makes the notification decision and who prepares it.

Document everything

Record what happened, what the effects were and what measures you took, even when you decide not to notify. After the incident, review what allowed it to happen and update your response plan.

Related serviceLaw 124 and GDPR ComplianceData mapping, record of processing activities, policies, DPIAs and readiness for an inspection by the Commissioner.Learn more

Let's talk about your next engagement.

Tell us about your engagement — we typically respond within one business day.

WhatsApp +355 69 522 4573