Governance · Personal data

Personal Data Breach Response Policy

How UK Bailiff Services Ltd identifies, contains, assesses, records and reports incidents involving personal data.

Purpose and scope

What this policy covers

A personal data breach is a security incident that leads to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

Examples may include a misdirected email, lost paperwork, unauthorised account access, inappropriate disclosure during case handling or loss of an unencrypted device containing personal data.

Immediate action

Our response procedure

Contain

Stop further access or disclosure, revoke links, recover material and secure affected systems where possible.

Escalate

Notify the Data Protection Lead and relevant management or technical personnel without delay.

Assess

Establish what happened, the information involved, who may be affected and the likely consequences.

Record

Document the facts, effects, decisions, remedial action and any regulator or individual notifications.

Decision framework

How risk is assessed

The assessment considers both the likelihood and severity of harm to people’s rights and freedoms.

The data

Type, sensitivity, volume, identifiability, encryption and whether special-category, financial or legal information is involved.

The exposure

Who accessed or may access it, whether it can be retrieved, whether misuse is likely and how long exposure continued.

The people

Number and circumstances of affected people, including any vulnerability, and possible financial, physical or emotional impact.

Regulatory duties

When notification is required

If a breach is likely to result in a risk to people’s rights and freedoms, we notify the Information Commissioner’s Office as soon as possible and, where feasible, within 72 hours of becoming aware of it.

Where complete information is not yet available, an initial accurate report may be followed by further details without undue delay. If the likely risk is high, we also inform affected people without undue delay, unless a lawful exception applies.

Every incident is documented

  • What happened and when
  • Categories and approximate volume of data and people
  • Likely consequences
  • Containment and remedial steps
  • Reasons for reporting or not reporting
  • Notifications and continuing actions
For recipients

If you receive information from us by mistake

01

Do not share it

Do not copy, forward, print or disclose the information to another person.

02

Tell us promptly

Email help@ukbailiffs.org or call 0330 133 1818 and explain what was received.

03

Follow instructions

Securely delete, return or destroy the information when asked, and confirm completion where appropriate.

Contact and escalation

Raise a data protection concern

Email help@ukbailiffs.org or call 0330 133 1818. Mark urgent incidents clearly so they can be escalated.

If you remain dissatisfied, you may complain to the Information Commissioner’s Office.

Questions

Data breach FAQs

Does every incident have to be reported to the ICO?
No. Reporting depends on whether the breach is likely to create a risk to people’s rights and freedoms. All breaches must still be assessed and documented.
When are affected individuals told?
Where a breach is likely to result in a high risk, affected individuals are informed without undue delay unless a statutory exception applies.
What if a processor identifies the breach?
A processor acting for us must notify us without undue delay and assist with investigation, containment and any required notifications.