Personal data breach
What to do in the event of a potential personal data breach
The General Data Protection Regulation (GDPR) defines a personal data breach as “a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data”.
Personal data is information about a living, identifiable individual.
It is the responsibility of all members of staff and students who discover a potential personal data breach, however minor, to report it immediately by email to the Information Governance Team - please see ‘How do I report a breach?’ below. The University has procedures in place to contain, mitigate, manage and notify a personal data breach.
In some cases, the University will have to report the breach to the Information Commissioner’s Office (ICO), within 72 hours, so it is important that any breach is reported without delay.