Triage a personal data breach and preserve the notification decision
Record awareness, risk, containment and notification facts, calculate the controller’s 72-hour point and create an editable breach working record.
Tool available. Run the complete browser-local workflow and inspect the result. Paid export is not active. Entries and files stay in this browser. Sources reviewed 7 August 2026.
Built from fictional sample information using the same exporter as the tool.
UK breach triage report sampleEU breach triage report sampleWhat’s included
Orient the response
Keep the supported route, file inventory and review sequence with the incident record.
- Start Here guide
- 72-hour calendar reminder
Document the decision
Prepare the editable incident record and a formal report of the notification position.
- Editable breach response working record
- Breach triage and notification decision report
Manage and retain evidence
Assign actions and preserve the structured facts, sources and assumptions.
- Breach actions workbook
- Structured breach record
- Sources and assumptions record
View every output and format
- Start Here guide
- 72-hour calendar reminder
- Editable breach response working record
- Breach triage and notification decision report
- Breach actions workbook
- Structured breach record
- Sources and assumptions record
Who this tool is for
Privacy, security and operations teams responding to a suspected personal data breach under UK or EU GDPR. Reach and evidence a time-critical notification decision without losing the awareness time, risk rationale or response chronology.
Supported use
- One suspected or confirmed personal data breach under the selected UK or EU route
- A controller notification assessment or an EU processor-to-controller notification record
- Awareness, containment, risk, notification content, affected-person communication and breach-register evidence
Have ready
- Organisation, incident reference, responsible owner and incident summary
- The recorded awareness date and time and, for EU routes, controller or processor role
- A reasoned answer and evidence note for each classification, risk and response subject
Needs separate review
- Whether the event is legally a personal data breach or creates a likely or high risk
- The competent or lead EU supervisory authority where the factual route is disputed
- Sector-specific reporting, contractual notices, cyber-incident reporting and legal privilege
How it works
- Record awareness and roleSet the incident, awareness time and controller or processor position for the selected route.
- Assess risk and responseRecord the evidence behind classification, likely risk, high risk, containment and communication answers.
- Review the notification routeInspect the calculated elapsed 72-hour point, regulator route and unresolved evidence.
- Retain the working recordDownload the editable response record, report, action workbook, reminder and source manifest.
Where does this task apply?
Choose the guidance set this tool should use. The interface and outputs stay in English.
What this tool checks
The scope stays narrow so the result is clear and reproducible.
- Start Here guide
- 72-hour calendar reminder
- Editable breach response working record
- Breach triage and notification decision report
- Breach actions workbook
- Structured breach record
- Sources and assumptions record
From official material to a working record
Official material sets the basis
Official UK and EU sources set the notification, communication and breach-record duties.
The tool prepares the operational record
The tool fixes the recorded awareness time, routes controller and processor duties separately and keeps every decision with its supporting evidence.
Official sources stay visible
Each supported check shows its jurisdiction, source title, source version and review date beside the result. Unsupported cases are rejected rather than estimated.
View this product's official sourcesQuestions before you use the tool
Scope, files, evidence and browser-local handling.
Does the tool decide whether a breach must be notified?
No. It applies the supported route to the risk position and evidence recorded by the responsible team. Uncertain or unsupported answers remain unresolved.
Does an EU processor receive its own 72-hour deadline?
No. The EU processor route records notification to the controller without undue delay. The Article 33 supervisory-authority duty belongs to the controller.
Are weekends excluded from the 72 hours?
No. The displayed point is 72 elapsed hours from the recorded awareness time. It does not stop for weekends or public holidays.
Where do incident facts go?
The entered facts, evidence notes and generated files remain in this browser.
Triage the breach now
Record the awareness time and evidence, then inspect the notification position before keeping the response pack.