Data breach response: a practical checklist for UK startups
Last updated: 15 August 2026
By StartupDocs · Published 15 August 2026
Why data breaches matter for small startups
A personal data breach is not just a problem for big companies. Under the UK GDPR, a breach means accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. That could be a lost laptop, an email sent to the wrong person, a ransomware attack, or a member of staff looking at customer records without a business reason.
For a startup with 1 to 20 people, a poorly handled breach can damage customer trust, trigger contractual claims from clients, and lead to regulatory action from the Information Commissioner's Office (ICO). The good news is that a simple, pre-agreed process removes most of the panic.
This guide is not legal advice. If you are unsure about a particular breach, speak to a solicitor or a data protection specialist.
Before a breach happens
The best time to prepare is now. Keep the response simple and practical.
- Name one person as the breach lead. This is often a founder or ops lead.
- Keep a basic asset map of where personal data lives: laptops, cloud drives, email accounts, CRM tools, HR systems, paper files.
- Keep a short breach log template. A spreadsheet with clear columns is enough.
- Review your contracts with processors, such as cloud providers or payroll software, so you know who to notify and how quickly.
- Write a one-page internal procedure. It should cover how to report a suspected breach, who decides what to do, and how to document decisions.
You do not need a 40-page incident plan. A simple, accessible document that people will actually read is far more useful.
Step by step when you spot a breach
1. Contain it
Stop the breach from getting worse. Reset passwords, revoke access, take a device offline, disconnect a compromised account, or ask the unintended email recipient to delete the message. Do not destroy evidence in your rush to fix things.
2. Record the facts
Write down what happened, when you became aware of it, what personal data was involved, how many people are affected, and who discovered the issue. Stick to known facts. If something is unknown, say so rather than guessing.
3. Assess the risk to people
Think about the impact on individuals, not just your business. Could the breach lead to identity theft, financial loss, loss of confidentiality, reputational damage, or distress? Special category data, such as health information or biometric data, usually raises the risk level.
4. Decide whether to notify the ICO
You must notify the ICO within 72 hours of becoming aware of a breach if it is likely to result in a risk to people's rights and freedoms. If you decide not to notify, record your reasons in your breach log. The 72-hour clock starts when you discover the breach, not when you finish investigating.
5. Decide whether to tell affected individuals
If the breach is likely to result in a high risk to individuals, you must tell them without undue delay. Explain what happened, what the likely consequences are, what you have done, what they can do to protect themselves, and how to contact you. Clear, direct language works best.
6. Notify processors or controllers
If a processor, such as a software provider, suffers a breach involving your data, they must tell you without undue delay. If you are a processor for another business, you must tell the controller. Check your contracts, as they may set shorter timescales or specific notification requirements.
7. Fix the root cause and document lessons
After the immediate response, work out why the breach happened and make a proportionate change. That might mean enabling two-factor authentication, restricting access to certain folders, updating a process, or retraining the team. Record what you changed and why.
What to include in your breach log
Your log does not need to be complex, but it should capture enough detail to show a clear decision trail.
- Date and time you became aware
- Date and time the breach occurred, if known
- Description of what happened
- Categories of personal data involved
- Number of individuals affected, if known
- Likely cause
- Containment steps taken
- Risk assessment outcome
- Whether the ICO was notified, and when
- Whether individuals were notified, and when
- Follow-up actions and lessons learned
Keep the log secure and limit access to the people who need it.
Common mistakes to avoid
- Delaying notification because you hope the breach is not serious. Assess first, but do not sit on it.
- Guessing the cause instead of investigating. Inaccurate records create more risk.
- Notifying the ICO too broadly without a legal basis. Only notify when the risk threshold is met.
- Forgetting paper records, old backups, or devices that are no longer in use.
- Assuming your processor will handle ICO notification for you. As the controller, you remain responsible.
When to consult a solicitor
Get specific advice if the breach is large scale, involves special category data, or could lead to regulatory investigation. Also speak to a solicitor if there is a dispute with a processor, if you are unsure whether to notify, or if the breach could trigger claims from affected individuals.
A calm, documented response is the best way to protect your startup and the people whose data you hold.