Once personal data is involved, several legal clocks start at once, each with its own trigger, audience and deadline. Missing one often costs more than the breach itself.
A security team can contain an intrusion in an afternoon and still leave the organisation exposed for weeks because nobody worked out who had to be told, and by when. This free data breach response checklist is the notification, legal and communications workstream that starts when a breach of personal data is suspected or confirmed. The DPO, privacy lead or general counsel runs it alongside the technical response: the risk assessment, legal privilege, regulator notices under GDPR, UK GDPR, US state laws, HIPAA and SEC rules, card brand and contractual notices, letters and support for the people affected, and the breach register entry that closes it. Each regime appears only when the facts recorded at the start say it applies.
Incident Response and Breach Response Are Two Workstreams
The Cybersecurity Incident Response Checklist is the technical playbook: triage the alert, contain the attacker, preserve evidence, eradicate and recover. It answers the question “is the threat gone?”. A personal data breach raises a different set of questions that the technical team is rarely equipped to answer. Whose data was it? Where do those people live? Are we the controller or a processor acting for a customer? Is the risk to them high enough that they must be told directly? Is the incident material to investors? Those answers decide which laws apply, and the laws decide the deadlines.
The two workstreams run at the same time and feed each other. Running them from one list tends to fail in one of two ways: the notification tasks wait until the investigation is “finished”, by which time the 72-hour GDPR window has gone, or the lawyers are pulled into containment calls and slow them down. A separate checklist with its own owner, linked to the incident record, lets each team move at its own pace.
Incident response
Is the threat contained?
Owner: the security lead or incident manager.
Starts: when a security event is declared an incident.
Output: a contained, eradicated and recovered environment, with evidence preserved.
Data breach response
Who must be told, and by when?
Owner: the DPO, privacy lead or general counsel.
Starts: as soon as personal data may have been compromised, often before the investigation ends.
Output: documented notification decisions, notices sent, support for individuals and a breach register entry.
Privacy programme review
Are we ready for the next one?
Owner: the DPO or compliance team.
Starts: on a schedule, usually annually.
Output: a tested breach procedure, current records of processing and processor contracts with notice clauses.
Start this checklist as soon as the incident record says personal data may be involved, including when the answer is “not yet known”. Ransomware cases usually arrive from the Ransomware Response Checklist once data theft is suspected, and compromised mailboxes from the Phishing Incident Response Checklist. Readiness, meaning a breach procedure, records of processing and processor contracts that would stand up to scrutiny, belongs in the annual GDPR Compliance Audit Checklist.
What the Data Breach Response Checklist Covers
Seven phases take a personal data breach from the first suspicion to a closed register entry. The answers recorded in Phase 1 decide which notification tasks appear.
Phase 1
Phase 1: Establish the Facts & Start the Clocks
Owned by the DPO or privacy lead. Each yes/no answer in this phase switches on the matching notification tasks later.
Record the date and time the organisation became aware of the breach — GDPR and most US laws run from awareness or discovery, not from the end of the investigation
Link this record to the technical incident record — one timeline, one incident reference, and a named contact on each side
Describe what happened in plain terms — unauthorised access, theft, accidental disclosure, loss of a device or loss of availability
List the categories of personal data and people involved — customers, staff, patients; names, contact details, government IDs, financial, health or card data
Record where the affected people live and the role you played — EU/EEA, UK, which US states, other countries; controller, processor or both
Record whether the data includes health information, payment card data or customer financial information — yes, no or not yet known for each
Phase 2
Phase 2: Engage Counsel & Protect the Record
Assigned to general counsel. Task 2 needs approval from counsel before any outside firm starts work.
Bring in legal counsel and decide whether outside breach counsel is needed — many cyber policies require use of the insurer’s panel firms
Have counsel engage the forensic firm where privilege is wanted — with a separate scope from routine security work and a restricted distribution list
Notify the cyber insurer within the policy’s notice period — record the claim reference and any consent needed before costs are incurred
Set a holding statement and a single spokesperson — staff are told not to discuss the breach outside the response team
Place a legal hold on relevant records — logs, emails and documents the investigation or later litigation may need
Phase 3
Phase 3: Assess the Risk to Individuals
The decision in task 5 needs approval from the DPO. A yes switches on Phase 6.
Confirm what the attacker accessed or took — from forensic findings, not assumptions; update this task as the evidence changes
Assess the likely consequences for the people affected — identity theft, fraud, discrimination, distress, physical harm or loss of confidentiality
Check mitigating factors — strong encryption with the key not compromised, data recovered, recipient trusted and confirmed deleted
For health data under HIPAA, complete the four-factor risk assessment — nature of the data, who obtained it, whether it was actually viewed and how far the risk was mitigated
Rate the risk to individuals and decide whether they must be told — high risk under GDPR or UK GDPR, or a US state or HIPAA trigger; record yes or no with the reasoning
Phase 4
Phase 4: Notify Regulators & Authorities
Assigned to the DPO and counsel. Tasks 1 to 3 appear only when Phase 1 records EU or UK residents, US residents or health data. Remove tasks 4 and 5 from your copy if you are not an SEC registrant, a financial institution or an NIS2 or DORA entity.
Notify the lead supervisory authority or the ICO where required — without undue delay and, where feasible, within 72 hours of awareness; send what you know and follow up in phases
Notify US state attorneys general and other state regulators where thresholds are met — check each affected state’s deadline, content rules and resident count
Report to HHS under the HIPAA Breach Notification Rule — within 60 days of discovery for 500 or more people; smaller breaches go in the annual log
Decide on SEC disclosure and Regulation S-P notices with counsel — Form 8-K within four business days of a materiality decision; individual notices under Reg S-P within 30 days
File sector reports that apply — NIS2 early warning, DORA major ICT incident reports, the FTC Safeguards Rule notice for non-bank financial institutions
Record every decision not to notify, with the reasons and who made it — regulators ask for these as often as for the notices themselves
Phase 5
Phase 5: Contractual, Payment & Partner Notices
The card brand task appears only when Phase 1 records payment card data. The controller task appears only when Phase 1 records that you acted as a processor.
If you are a processor, notify each affected controller without undue delay — the controller owns the regulator decision, so give them facts early
Report suspected payment card compromise to your acquirer and the card brands — Visa requires notice within three calendar days of reasonable suspicion
Check customer and supplier contracts for breach notice clauses — some set deadlines of 24 to 72 hours and specify the content
Tell law enforcement where the breach involves crime — and record any request to delay notification, which several laws allow; tell partners whose shared credentials or data feeds were affected
Phase 6
Phase 6: Notify & Support Individuals
Appears only when Phase 3 records that individuals must be told. Letters need approval from counsel before they are sent.
Draft the notice in plain language — what happened, what data, what you are doing, what they should do and who to contact; check each law’s required content
Confirm the mailing list and contact method — current addresses, email where permitted, and substitute notice where contact details are missing
Arrange credit monitoring or identity protection where required or offered — Connecticut, for example, requires at least 24 months where Social Security numbers were breached
Set up a call centre or helpline with a script and escalation path — staffed before the letters land, with a log of complaints and questions
Send the notices and record the date, method and number sent — keep a copy of each version and the list it went to
Publish a website notice or media statement where the law requires it — HIPAA requires media notice for 500 or more residents of a state or jurisdiction
Phase 7
Phase 7: Register, Review & Close
Closure needs approval from the DPO and general counsel.
Complete the breach register entry — facts, effects and remedial action, as GDPR Article 33(5) requires for every breach, reported or not
Answer regulator follow-up questions and record each exchange — correspondence, deadlines and any undertakings given
Hold a lessons-learned review with legal, security and communications — what slowed the decisions, where the facts were wrong, what the letters missed
Raise improvement actions with owners and dates — data minimisation, encryption, retention, processor contracts and the breach procedure itself
Approve closure — confirming every notice is sent, every decision is recorded and evidence is retained for the required period
The table summarises the main deadlines as of October 2026. Which apply depends on your sector, location and customers, so confirm the list with counsel and treat it as a starting point, not legal advice.
Regime
Who is told
Deadline
Phase
GDPR / UK GDPR Art. 33
Supervisory authority (the ICO in the UK)
Without undue delay, where feasible within 72 hours of awareness, unless the breach is unlikely to result in a risk to individuals
Phase 4
GDPR / UK GDPR Art. 33(2)
The controller, by its processor
Without undue delay after the processor becomes aware
Phase 5
GDPR / UK GDPR Art. 34
Affected individuals
Without undue delay where the breach is likely to result in a high risk to them
Phase 6
HIPAA Breach Notification Rule
Individuals; HHS; media
Without unreasonable delay and no later than 60 calendar days from discovery; HHS within 60 days for 500 or more people, otherwise within 60 days of year end; media for 500 or more residents of a state
Phases 4 and 6
US state breach laws
Residents; often the attorney general
Varies by state. 30 days in California (from 1 January 2026), Colorado, Florida, New York and Washington; the Texas attorney general within 30 days for 250 or more Texans
Phases 4 and 6
SEC Form 8-K Item 1.05
Investors
Four business days after determining the incident is material
Phase 4
SEC Regulation S-P
Affected individuals
No later than 30 days after becoming aware; service providers tell the covered institution within 72 hours
Phases 4 and 6
FTC Safeguards Rule
The FTC
As soon as possible and no later than 30 days after discovery, for unencrypted data of 500 or more consumers
Phase 4
NIS2 Art. 23 / DORA
CSIRT or competent authority
NIS2: 24-hour early warning, 72-hour notification, final report in one month. DORA: initial report within 4 hours of classifying an incident as major and no later than 24 hours from awareness
Phase 4
Visa rules
Visa and your acquirer
Within three calendar days of reasonable suspicion of a compromise of Visa account data
Phase 5
All 50 US states and the District of Columbia have breach notification laws; Alabama was the last state to pass one, in 2018. Many still require notice “without unreasonable delay” rather than within a fixed number of days, but the trend is towards hard deadlines: California’s SB 446 set 30 calendar days from 1 January 2026, plus a sample notice to the attorney general within 15 days where more than 500 Californians are affected. Regulation S-P’s amendments applied to larger entities from 3 December 2025 and smaller ones from 3 June 2026. Under HIPAA, a business associate must tell the covered entity within 60 days of discovery, and the covered entity then owns the notices.
NIS2 and DORA reports cover significant or major incidents whether or not personal data is involved, so in-scope entities may already be filing them from the incident response checklist; cross-reference them here so regulators receive one consistent account. The EDPB’s Guidelines 9/2022 confirm that a controller outside the EU with no EU establishment must notify every authority where affected people live.
Why Run Breach Response in CheckFlow?
1
Only the regimes that apply appear
Phase 1 records where the affected people live, your role and whether health, card or financial data is involved. Conditional logic shows the matching notification tasks and hides the rest, so a UK-only staff breach does not carry twenty US tasks.
2
Decisions not to notify are recorded
Each notification task has a required yes/no answer and a text field for the reasoning, so a decision not to tell a regulator is as visible in the audit trail as a decision to tell one, with a name and a time.
3
Counsel approves before anything goes out
Letters, regulator submissions and the risk rating are approval steps assigned to counsel or the DPO by name. The checklist halts until they approve, so a well-meaning manager cannot send a customer email that contradicts the regulator notice.
CheckFlow is not a legal research tool or a breach notification service. It runs the human side of the response: who decides, who drafts, who approves and what was sent, with each step timestamped. For the recurring privacy and security reviews around it, CheckFlow’s compliance checklist software keeps owners, evidence and approvals in one place.
What should a data breach response checklist include?
+
It should record when you became aware of the breach, what personal data and which people are affected, and where they live. It then needs a documented assessment of the risk to those people, a decision for each regulator and each group of individuals on whether to notify, the notices themselves, support such as a helpline or credit monitoring, and a breach register entry. Containing the attacker belongs in a separate incident response checklist running alongside it.
Does every data breach have to be reported within 72 hours?
+
No. Under GDPR and UK GDPR you must notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to individuals. A report that arrives after 72 hours must explain the delay. Breaches you decide not to report still have to be documented under Article 33(5), with the facts, the effects and what you did about them, so the regulator can check your reasoning later.
How long do US companies have to notify people after a data breach?
+
It depends on which law applies. Every state has its own breach notification law; some set a fixed limit, such as 30 days in California, Colorado, Florida, New York and Washington, while others require notice without unreasonable delay. The HIPAA Breach Notification Rule allows no more than 60 calendar days from discovery, and the SEC’s Regulation S-P allows no more than 30 days for covered financial firms. Where several apply, the shortest deadline drives the plan. Confirm the position with counsel, as state laws change often.
Do we have to offer credit monitoring after a breach?
+
Sometimes. A few US states require it when Social Security numbers are involved; Connecticut, for example, requires at least 24 months of identity theft prevention and mitigation services at no cost. Elsewhere it is usually optional but commonly offered where government ID or financial data was taken. Record the decision and the reasons either way.
Is CheckFlow free for this template?
+
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.
Know Who to Tell Before the Clock Starts
Free trial — no credit card required.
Do you like cookies? 🍪 We use cookies to ensure you get the best experience on our website. Learn more