After a data breach: the decisions taken before the facts arrive
A report arrives that something has been exposed. It may come from a customer, from a security researcher, from a supplier, or from an alert nobody can immediately explain. The instinct is to find out whether it is true before saying anything to anybody, and that instinct is where the difficulty starts.
The word breach suggests an attacker. United Kingdom data protection law reaches a good deal wider than that. Personal data sent to the wrong recipient, a laptop or a file lost, records reachable by staff who had no business reaching them, and data destroyed or made unavailable when it should not have been are all capable of qualifying. An administrative error can engage the same duties as an intrusion, even though nobody involved thought of it as a security matter at all.
The second difficulty is that the quickest route back to normal service is frequently the route that removes the record of what happened. Systems get rebuilt, snapshots are restored, accounts are reset and mailboxes are cleared, all of it done by capable people trying to limit harm. Preserving the position and restoring the service pull against one another in the first hours, and the choice between them is usually made by whoever happens to be awake rather than by anyone weighing it.
The third difficulty is the one organisations least expect, which is that the response generates a record of its own. What follows is why the order of these decisions matters, and where the judgement sits that is hard to make from inside a business having a bad week.
Awareness starts the clock, and awareness is a legal question
United Kingdom data protection law does not allow an organisation as long as it needs to understand what has happened. Where a personal data breach is likely to result in a risk to the rights and freedoms of the people concerned, a controller must notify the Information Commissioner's Office without undue delay, and the law fixes an outer limit expressed in hours. That limit runs from the point at which the organisation becomes aware of the breach.
Awareness and certainty are different things, and the gap between them is where organisations get into trouble. What amounts to awareness is a legal question rather than a technical one, and it is a question businesses tend to answer generously in their own favour. A credible report that has not yet been confirmed can be enough to start matters running. Waiting for forensic certainty and then moving promptly produces an organisation that is well informed, confident and late.
Separately, where a breach is likely to result in a high risk to the individuals concerned, those individuals must themselves be told, without undue delay. Whether a particular incident crosses that threshold is an assessment, and the organisation's own view of it is not the only view that will matter later.
Which party actually owes the duty
Obligations follow the role a business occupies in relation to the data, and that role is determined by what the business actually does rather than by the description in its contracts. An organisation deciding why and how personal data is processed is a controller, and its duties run to the regulator and to the individuals. An organisation processing on somebody else's instructions is a processor, and its duty runs to its customer, promptly, so that the customer can meet its own.
Most businesses occupy both positions at once: controller of their own staff and customer records, processor of whatever their clients load into their platform. A single incident can engage both, on different timescales, owed to different people.
The consequence that catches businesses out is the one that runs through suppliers. Where a supplier suffers the incident but you are the controller of the data involved, the notification obligation is generally still yours. Your ability to meet it depends on information held by an organisation whose commercial interests at that moment are not aligned with yours, and whose first concern is its own position. What your contract with that supplier says about incident reporting, and whether anybody has read it since it was signed, becomes a live question on the worst possible day.
Group structures produce the same problem internally, because which company in a group controls which data set is rarely settled in advance, and settling it while a limit is running is an expensive way to spend the first morning.
The commercial clocks usually bite before the legal one
Statutory duties attract the attention, yet the obligations that arrive first are commonly the ones the business agreed to itself.
Corporate customers routinely impose their own incident notification terms in data processing agreements and in master services agreements, and those terms are frequently tighter than the statutory position, because the customer needs time to make its own assessment before its own duties are engaged. A supplier that comfortably meets the regulatory limit can be in breach of contract with its largest account on the same facts.
Insurance is the other one, and it is the one that costs real money quietly. Cyber policies commonly make cover conditional on prompt notification to the insurer, and often on the use of the insurer's own panel of responders, or on consent being obtained before significant costs are incurred. A business that instructs its usual advisers and starts spending on the first morning can find that some of what it spent falls outside cover. The policy is worth reading while nothing is happening, because it is rarely read usefully while something is.
Then there is the chain. Telling a corporate customer starts obligations inside that customer's organisation, and regulated customers may have reporting duties of their own that your message triggers. The wording of what you send them is a substantive decision with consequences that travel, rather than a question of tone.
What is written during the response is read afterwards
How an organisation conducted itself is assessed alongside what happened to it, and the record made while the facts were still moving is most of the evidence of that conduct. It is broader than people assume. It takes in the messages exchanged between colleagues at the time, the early estimates of scale that later prove wrong, the internal remark about a risk that had been raised before and never funded, and the statement that was drafted and not sent. Material of that kind can be disclosable in later proceedings, and can be sought by a regulator.
Whether any of it attracts legal privilege turns on how the work was set up at the beginning. It is not conferred by copying an adviser into an email, and it cannot be applied retrospectively to material that already exists. Arranging matters so that the most sensitive parts of an investigation carry appropriate protection is a decision taken at the outset or not at all, which is one of the reasons the calls made on the first morning matter more than they appear to.
The other half of the record is the half that disappears. Restoring from a clean backup, rebuilding a compromised machine or resetting an account can remove exactly the material that would have shown the scope of what occurred, and it is done for the best of reasons by people trying to get customers back online. The instruction that is safe to give early, and which costs almost nothing, is to stop anything that overwrites the position until somebody has decided what is worth keeping.
Telling people starts something of its own
Notification tends to be treated internally as the conclusion of the response, and it generally marks the beginning of the next phase of it. Individuals who are told will make contact, and that volume arrives while the same small group of people is still dealing with the incident itself. Customers ask for assurances in writing, and some of those assurances are quoted back later. In England and Wales, individuals can bring claims arising from the mishandling of their personal data, and claims firms take an interest in breaches once they are notified or reported. Staff will read the announcement before customers do, and will form a view about whether they were told the truth.
Which of those pressures dominates depends on whose data was involved. An incident touching employee records behaves differently from one touching customers, and one involving special category information, such as health data, behaves differently again. The tolerance available to an organisation is set largely by the sensitivity of what was exposed rather than by the sophistication of whatever caused the exposure.
What is not worth doing
Not every incident warrants the full apparatus, and treating each one as though it does is its own kind of failure, because it exhausts the people who will be needed when something serious does happen.
Where an incident is genuinely contained and the exposure is bounded, a broad forensic engagement can cost more than the harm and produce a report confirming what was already known. Scoping that work is a judgement, and it is made badly when it is made by whoever is most frightened.
Notifying reflexively, on the basis that it must be the safer course, is not free either. A notification is a formal statement to a regulator about your own conduct, it can trigger contractual obligations to customers, and it can become public. Where the honest assessment is that the threshold is not met, that assessment needs to be reasoned and recorded so that it can be defended, rather than avoided by reporting everything. The choice between those two courses is precisely the kind that is difficult to make about yourself in the hours when you are also trying to restore a service.
Publishing a holding statement before the facts are stable is rarely worth the day it buys. A scope or a number given early and corrected later does more damage than saying that the position is being established and that you will say more once you can say it accurately.
Two things are worth doing in almost every case, and neither is expensive. Stop the overwriting while it is still possible to stop it. Then have the question of whether duties are engaged answered by somebody who does that work, quickly, while every option remains open.
Asking the supplier whose system failed to investigate and report on what happened. It is the natural request, they hold the access, and a report will duly arrive. It will also have been scoped by the party with the most to lose from its conclusions, and it becomes the document you relied on when a regulator asks what steps you took to establish the facts.
This guide is general information about how these matters usually run. It is not advice, and nothing becomes advice until terms are agreed in writing. Brandleys Legal Ltd delivers reserved legal activities alongside regulated partners.