Triage a personal data breach and preserve the notification decision

Record awareness, risk, containment and notification facts, calculate the controller’s 72-hour point and create an editable breach working record.

UKEUData protection and privacy
Free to useChoose a guidance set belowAbout 10 minutes7 working filesStart this tool

Tool available. Run the complete browser-local workflow and inspect the result. Paid export is not active. Entries and files stay in this browser. Sources reviewed 7 August 2026.

Inspect a real output

Built from fictional sample information using the same exporter as the tool.

UK breach triage report sampleEU breach triage report sample

What’s included

Orient the response

Keep the supported route, file inventory and review sequence with the incident record.

  • Start Here guide
  • 72-hour calendar reminder

Document the decision

Prepare the editable incident record and a formal report of the notification position.

  • Editable breach response working record
  • Breach triage and notification decision report

Manage and retain evidence

Assign actions and preserve the structured facts, sources and assumptions.

  • Breach actions workbook
  • Structured breach record
  • Sources and assumptions record
View every output and format
  • Start Here guide
  • 72-hour calendar reminder
  • Editable breach response working record
  • Breach triage and notification decision report
  • Breach actions workbook
  • Structured breach record
  • Sources and assumptions record

Who this tool is for

Privacy, security and operations teams responding to a suspected personal data breach under UK or EU GDPR. Reach and evidence a time-critical notification decision without losing the awareness time, risk rationale or response chronology.

Supported use

  • One suspected or confirmed personal data breach under the selected UK or EU route
  • A controller notification assessment or an EU processor-to-controller notification record
  • Awareness, containment, risk, notification content, affected-person communication and breach-register evidence

Have ready

  • Organisation, incident reference, responsible owner and incident summary
  • The recorded awareness date and time and, for EU routes, controller or processor role
  • A reasoned answer and evidence note for each classification, risk and response subject

Needs separate review

  • Whether the event is legally a personal data breach or creates a likely or high risk
  • The competent or lead EU supervisory authority where the factual route is disputed
  • Sector-specific reporting, contractual notices, cyber-incident reporting and legal privilege

How it works

  1. Record awareness and roleSet the incident, awareness time and controller or processor position for the selected route.
  2. Assess risk and responseRecord the evidence behind classification, likely risk, high risk, containment and communication answers.
  3. Review the notification routeInspect the calculated elapsed 72-hour point, regulator route and unresolved evidence.
  4. Retain the working recordDownload the editable response record, report, action workbook, reminder and source manifest.

Where does this task apply?

Choose the guidance set this tool should use. The interface and outputs stay in English.

Available guidance sets

Choose one before you start.

Choose the jurisdiction above to open the correct tool.The fields, clock and source record change with the selected guidance set.

What this tool checks

The scope stays narrow so the result is clear and reproducible.

  • Start Here guide
  • 72-hour calendar reminder
  • Editable breach response working record
  • Breach triage and notification decision report
  • Breach actions workbook
  • Structured breach record
  • Sources and assumptions record

From official material to a working record

Official material sets the basis

Official UK and EU sources set the notification, communication and breach-record duties.

The tool prepares the operational record

The tool fixes the recorded awareness time, routes controller and processor duties separately and keeps every decision with its supporting evidence.

Official sources stay visible

Each supported check shows its jurisdiction, source title, source version and review date beside the result. Unsupported cases are rejected rather than estimated.

View this product's official sources

Questions before you use the tool

Scope, files, evidence and browser-local handling.

Does the tool decide whether a breach must be notified?

No. It applies the supported route to the risk position and evidence recorded by the responsible team. Uncertain or unsupported answers remain unresolved.

Does an EU processor receive its own 72-hour deadline?

No. The EU processor route records notification to the controller without undue delay. The Article 33 supervisory-authority duty belongs to the controller.

Are weekends excluded from the 72 hours?

No. The displayed point is 72 elapsed hours from the recorded awareness time. It does not stop for weekends or public holidays.

Where do incident facts go?

The entered facts, evidence notes and generated files remain in this browser.

Triage the breach now

Record the awareness time and evidence, then inspect the notification position before keeping the response pack.

Open the breach triage