Data Breach Response Checklist Template

Once personal data is involved, several legal clocks start at once, each with its own trigger, audience and deadline. Missing one often costs more than the breach itself.

A security team can contain an intrusion in an afternoon and still leave the organisation exposed for weeks because nobody worked out who had to be told, and by when. This free data breach response checklist is the notification, legal and communications workstream that starts when a breach of personal data is suspected or confirmed. The DPO, privacy lead or general counsel runs it alongside the technical response: the risk assessment, legal privilege, regulator notices under GDPR, UK GDPR, US state laws, HIPAA and SEC rules, card brand and contractual notices, letters and support for the people affected, and the breach register entry that closes it. Each regime appears only when the facts recorded at the start say it applies.

Use This Template Free See Live Example
No Credit Card Required

Incident Response and Breach Response Are Two Workstreams

The Cybersecurity Incident Response Checklist is the technical playbook: triage the alert, contain the attacker, preserve evidence, eradicate and recover. It answers the question “is the threat gone?”. A personal data breach raises a different set of questions that the technical team is rarely equipped to answer. Whose data was it? Where do those people live? Are we the controller or a processor acting for a customer? Is the risk to them high enough that they must be told directly? Is the incident material to investors? Those answers decide which laws apply, and the laws decide the deadlines.

The two workstreams run at the same time and feed each other. Running them from one list tends to fail in one of two ways: the notification tasks wait until the investigation is “finished”, by which time the 72-hour GDPR window has gone, or the lawyers are pulled into containment calls and slow them down. A separate checklist with its own owner, linked to the incident record, lets each team move at its own pace.

Incident response

Is the threat contained?

Owner: the security lead or incident manager.

Starts: when a security event is declared an incident.

Output: a contained, eradicated and recovered environment, with evidence preserved.

Data breach response

Who must be told, and by when?

Owner: the DPO, privacy lead or general counsel.

Starts: as soon as personal data may have been compromised, often before the investigation ends.

Output: documented notification decisions, notices sent, support for individuals and a breach register entry.

Privacy programme review

Are we ready for the next one?

Owner: the DPO or compliance team.

Starts: on a schedule, usually annually.

Output: a tested breach procedure, current records of processing and processor contracts with notice clauses.

Start this checklist as soon as the incident record says personal data may be involved, including when the answer is “not yet known”. Ransomware cases usually arrive from the Ransomware Response Checklist once data theft is suspected, and compromised mailboxes from the Phishing Incident Response Checklist. Readiness, meaning a breach procedure, records of processing and processor contracts that would stand up to scrutiny, belongs in the annual GDPR Compliance Audit Checklist.

What the Data Breach Response Checklist Covers

Seven phases take a personal data breach from the first suspicion to a closed register entry. The answers recorded in Phase 1 decide which notification tasks appear.

Phase 1

Phase 1: Establish the Facts & Start the Clocks

Owned by the DPO or privacy lead. Each yes/no answer in this phase switches on the matching notification tasks later.

  • Record the date and time the organisation became aware of the breach — GDPR and most US laws run from awareness or discovery, not from the end of the investigation
  • Link this record to the technical incident record — one timeline, one incident reference, and a named contact on each side
  • Describe what happened in plain terms — unauthorised access, theft, accidental disclosure, loss of a device or loss of availability
  • List the categories of personal data and people involved — customers, staff, patients; names, contact details, government IDs, financial, health or card data
  • Record where the affected people live and the role you played — EU/EEA, UK, which US states, other countries; controller, processor or both
  • Record whether the data includes health information, payment card data or customer financial information — yes, no or not yet known for each
Phase 2

Phase 2: Engage Counsel & Protect the Record

Assigned to general counsel. Task 2 needs approval from counsel before any outside firm starts work.

  • Bring in legal counsel and decide whether outside breach counsel is needed — many cyber policies require use of the insurer’s panel firms
  • Have counsel engage the forensic firm where privilege is wanted — with a separate scope from routine security work and a restricted distribution list
  • Notify the cyber insurer within the policy’s notice period — record the claim reference and any consent needed before costs are incurred
  • Set a holding statement and a single spokesperson — staff are told not to discuss the breach outside the response team
  • Place a legal hold on relevant records — logs, emails and documents the investigation or later litigation may need
Phase 3

Phase 3: Assess the Risk to Individuals

The decision in task 5 needs approval from the DPO. A yes switches on Phase 6.

  • Confirm what the attacker accessed or took — from forensic findings, not assumptions; update this task as the evidence changes
  • Assess the likely consequences for the people affected — identity theft, fraud, discrimination, distress, physical harm or loss of confidentiality
  • Check mitigating factors — strong encryption with the key not compromised, data recovered, recipient trusted and confirmed deleted
  • For health data under HIPAA, complete the four-factor risk assessment — nature of the data, who obtained it, whether it was actually viewed and how far the risk was mitigated
  • Rate the risk to individuals and decide whether they must be told — high risk under GDPR or UK GDPR, or a US state or HIPAA trigger; record yes or no with the reasoning
Phase 4

Phase 4: Notify Regulators & Authorities

Assigned to the DPO and counsel. Tasks 1 to 3 appear only when Phase 1 records EU or UK residents, US residents or health data. Remove tasks 4 and 5 from your copy if you are not an SEC registrant, a financial institution or an NIS2 or DORA entity.

  • Notify the lead supervisory authority or the ICO where required — without undue delay and, where feasible, within 72 hours of awareness; send what you know and follow up in phases
  • Notify US state attorneys general and other state regulators where thresholds are met — check each affected state’s deadline, content rules and resident count
  • Report to HHS under the HIPAA Breach Notification Rule — within 60 days of discovery for 500 or more people; smaller breaches go in the annual log
  • Decide on SEC disclosure and Regulation S-P notices with counsel — Form 8-K within four business days of a materiality decision; individual notices under Reg S-P within 30 days
  • File sector reports that apply — NIS2 early warning, DORA major ICT incident reports, the FTC Safeguards Rule notice for non-bank financial institutions
  • Record every decision not to notify, with the reasons and who made it — regulators ask for these as often as for the notices themselves
Phase 5

Phase 5: Contractual, Payment & Partner Notices

The card brand task appears only when Phase 1 records payment card data. The controller task appears only when Phase 1 records that you acted as a processor.

  • If you are a processor, notify each affected controller without undue delay — the controller owns the regulator decision, so give them facts early
  • Report suspected payment card compromise to your acquirer and the card brands — Visa requires notice within three calendar days of reasonable suspicion
  • Check customer and supplier contracts for breach notice clauses — some set deadlines of 24 to 72 hours and specify the content
  • Tell law enforcement where the breach involves crime — and record any request to delay notification, which several laws allow; tell partners whose shared credentials or data feeds were affected
Phase 6

Phase 6: Notify & Support Individuals

Appears only when Phase 3 records that individuals must be told. Letters need approval from counsel before they are sent.

  • Draft the notice in plain language — what happened, what data, what you are doing, what they should do and who to contact; check each law’s required content
  • Confirm the mailing list and contact method — current addresses, email where permitted, and substitute notice where contact details are missing
  • Arrange credit monitoring or identity protection where required or offered — Connecticut, for example, requires at least 24 months where Social Security numbers were breached
  • Set up a call centre or helpline with a script and escalation path — staffed before the letters land, with a log of complaints and questions
  • Send the notices and record the date, method and number sent — keep a copy of each version and the list it went to
  • Publish a website notice or media statement where the law requires it — HIPAA requires media notice for 500 or more residents of a state or jurisdiction
Phase 7

Phase 7: Register, Review & Close

Closure needs approval from the DPO and general counsel.

  • Complete the breach register entry — facts, effects and remedial action, as GDPR Article 33(5) requires for every breach, reported or not
  • Answer regulator follow-up questions and record each exchange — correspondence, deadlines and any undertakings given
  • Hold a lessons-learned review with legal, security and communications — what slowed the decisions, where the facts were wrong, what the letters missed
  • Raise improvement actions with owners and dates — data minimisation, encryption, retention, processor contracts and the breach procedure itself
  • Approve closure — confirming every notice is sent, every decision is recorded and evidence is retained for the required period

Who Has to Be Told, and How Fast

The table summarises the main deadlines as of October 2026. Which apply depends on your sector, location and customers, so confirm the list with counsel and treat it as a starting point, not legal advice.

RegimeWho is toldDeadlinePhase
GDPR / UK GDPR Art. 33Supervisory authority (the ICO in the UK)Without undue delay, where feasible within 72 hours of awareness, unless the breach is unlikely to result in a risk to individualsPhase 4
GDPR / UK GDPR Art. 33(2)The controller, by its processorWithout undue delay after the processor becomes awarePhase 5
GDPR / UK GDPR Art. 34Affected individualsWithout undue delay where the breach is likely to result in a high risk to themPhase 6
HIPAA Breach Notification RuleIndividuals; HHS; mediaWithout unreasonable delay and no later than 60 calendar days from discovery; HHS within 60 days for 500 or more people, otherwise within 60 days of year end; media for 500 or more residents of a statePhases 4 and 6
US state breach lawsResidents; often the attorney generalVaries by state. 30 days in California (from 1 January 2026), Colorado, Florida, New York and Washington; the Texas attorney general within 30 days for 250 or more TexansPhases 4 and 6
SEC Form 8-K Item 1.05InvestorsFour business days after determining the incident is materialPhase 4
SEC Regulation S-PAffected individualsNo later than 30 days after becoming aware; service providers tell the covered institution within 72 hoursPhases 4 and 6
FTC Safeguards RuleThe FTCAs soon as possible and no later than 30 days after discovery, for unencrypted data of 500 or more consumersPhase 4
NIS2 Art. 23 / DORACSIRT or competent authorityNIS2: 24-hour early warning, 72-hour notification, final report in one month. DORA: initial report within 4 hours of classifying an incident as major and no later than 24 hours from awarenessPhase 4
Visa rulesVisa and your acquirerWithin three calendar days of reasonable suspicion of a compromise of Visa account dataPhase 5

All 50 US states and the District of Columbia have breach notification laws; Alabama was the last state to pass one, in 2018. Many still require notice “without unreasonable delay” rather than within a fixed number of days, but the trend is towards hard deadlines: California’s SB 446 set 30 calendar days from 1 January 2026, plus a sample notice to the attorney general within 15 days where more than 500 Californians are affected. Regulation S-P’s amendments applied to larger entities from 3 December 2025 and smaller ones from 3 June 2026. Under HIPAA, a business associate must tell the covered entity within 60 days of discovery, and the covered entity then owns the notices.

NIS2 and DORA reports cover significant or major incidents whether or not personal data is involved, so in-scope entities may already be filing them from the incident response checklist; cross-reference them here so regulators receive one consistent account. The EDPB’s Guidelines 9/2022 confirm that a controller outside the EU with no EU establishment must notify every authority where affected people live.

Why Run Breach Response in CheckFlow?

1

Only the regimes that apply appear

Phase 1 records where the affected people live, your role and whether health, card or financial data is involved. Conditional logic shows the matching notification tasks and hides the rest, so a UK-only staff breach does not carry twenty US tasks.

2

Decisions not to notify are recorded

Each notification task has a required yes/no answer and a text field for the reasoning, so a decision not to tell a regulator is as visible in the audit trail as a decision to tell one, with a name and a time.

3

Counsel approves before anything goes out

Letters, regulator submissions and the risk rating are approval steps assigned to counsel or the DPO by name. The checklist halts until they approve, so a well-meaning manager cannot send a customer email that contradicts the regulator notice.

CheckFlow is not a legal research tool or a breach notification service. It runs the human side of the response: who decides, who drafts, who approves and what was sent, with each step timestamped. For the recurring privacy and security reviews around it, CheckFlow’s compliance checklist software keeps owners, evidence and approvals in one place.

A breach response is only as quick as the facts behind it. The GDPR Compliance Audit Checklist confirms you know what personal data you hold and where, the Vendor Risk Assessment Checklist checks that suppliers will tell you promptly about their breaches, and the Incident Response Tabletop Exercise Checklist lets you rehearse the 72-hour decision before it is real. Healthcare teams can read our HIPAA compliance checklist guide for the wider Security Rule programme.

Frequently Asked Questions

What should a data breach response checklist include?

+

It should record when you became aware of the breach, what personal data and which people are affected, and where they live. It then needs a documented assessment of the risk to those people, a decision for each regulator and each group of individuals on whether to notify, the notices themselves, support such as a helpline or credit monitoring, and a breach register entry. Containing the attacker belongs in a separate incident response checklist running alongside it.

Does every data breach have to be reported within 72 hours?

+

No. Under GDPR and UK GDPR you must notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to individuals. A report that arrives after 72 hours must explain the delay. Breaches you decide not to report still have to be documented under Article 33(5), with the facts, the effects and what you did about them, so the regulator can check your reasoning later.

How long do US companies have to notify people after a data breach?

+

It depends on which law applies. Every state has its own breach notification law; some set a fixed limit, such as 30 days in California, Colorado, Florida, New York and Washington, while others require notice without unreasonable delay. The HIPAA Breach Notification Rule allows no more than 60 calendar days from discovery, and the SEC’s Regulation S-P allows no more than 30 days for covered financial firms. Where several apply, the shortest deadline drives the plan. Confirm the position with counsel, as state laws change often.

Do we have to offer credit monitoring after a breach?

+

Sometimes. A few US states require it when Social Security numbers are involved; Connecticut, for example, requires at least 24 months of identity theft prevention and mitigation services at no cost. Elsewhere it is usually optional but commonly offered where government ID or financial data was taken. Record the decision and the reasons either way.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Know Who to Tell Before the Clock Starts

Free trial — no credit card required.