GDPR Personal Data Breach Notification Procedure

Draft: Millwood Bowling Club: Data Breach Procedure

1. Definition of a Breach

A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of member data.

  • Examples: A lost USB stick containing member addresses, sending a club-wide email where all addresses are visible, or a break-in at the clubhouse where membership forms are stolen.

2. Immediate Response (The First 24 Hours)

Once a potential breach is identified, the Data Protection Officer (DPO) or a designated Committee Member must:

  1. Contain: Take immediate steps to stop the leak (e.g., change passwords, remote-wipe a device, or ask a recipient to delete an incorrectly sent email).
  2. Assess: Determine what data was involved and how many members are affected.
  3. Record: Log the breach in the club’s Internal Breach Register, even if it doesn't need to be reported externally.

3. Risk Assessment Matrix

The Committee must decide if the breach needs to be reported to the Information Commissioner’s Office (ICO).

Risk LevelDescriptionAction Required
Low RiskUnlikely to result in a risk to members (e.g., an encrypted file is lost).Record internally; no notification needed.
Medium RiskCould cause inconvenience (e.g., names and phone numbers leaked).Notify affected members; record internally.
High RiskCould result in identity theft or fraud (e.g., bank details or health info leaked).Must notify the ICO and affected members.

Related Posts

Privacy Policy

Millwood Bowling Club: Website Privacy Policy 1. Introduction Millwood Bowling Club ("we", […]

Application Form

Click to download. View & print our Membership Application form (print the […]

Code of Conduct

DRAFT Millwood Bowling Club: Code of Conduct 1. Core Principles All members, […]

Room Hire Policy

Coming Soon

Selection Policy

Coming Soon

GDPR Personal Data Breach Notification Procedure

Draft: Millwood Bowling Club: Data Breach Procedure 1. Definition of a Breach […]

SOCIAL MEDIA POLICY

Draft: Millwood Bowling Club: Social Media Policy 1. Purpose This policy ensures […]

Anti-bullying-harassment policy

This is perhaps the most important document for maintaining the "friendly club" […]

Constitution

MILLWOOD BOWLING CLUBCONSTITUTION 2023 (latest version) TITLEThe Club shall be called “Millwood […]