Opening and managing an incident
How to report a data breach, gather evidence and coordinate the internal response.
What to record as a data breach
The GDPR requires documenting all data breaches, even those that don’t trigger the obligation to notify the authority. Privacta helps you keep the internal incident register complete and always up to date.
Data breaches include:
- Unauthorized access to personal data
- Accidental loss or destruction of data
- Unintended disclosure to third parties
- Data exfiltration (cyberattacks, phishing)
- Accidental sending to the wrong recipient
Opening a new incident
- From the Data Breach section, click New incident
- Fill in the initial information: date and time of detection, description of the event, systems involved
- Assign a response owner — they will receive an immediate notification
- The system automatically starts the 72-hour countdown to assess notification to the authority
The 72 hours run from when the organization becomes aware of the incident, not necessarily from when it occurred. Document the date and time of detection immediately.
Gathering evidence
In the incident record you can attach:
- Screenshots, system logs, technical reports
- Internal communications about the incident
- Documentation of measures taken immediately
Every attachment is recorded in the audit trail with date, time and the user who uploaded it.
Assessing the impact
Fill in the Impact assessment section, specifying:
- Number and categories of data subjects involved
- Type of personal data exposed
- Potential consequences for data subjects
- Measures already taken to limit the damage
Privacta automatically calculates the risk level and indicates whether notification to the authority is mandatory, recommended or not required.
📄 Add an example of a completed incident record with impact assessment