A cross-sector standard operating procedure for containing, assessing, reporting and recording personal data breaches under the UK General Data Protection Regulation and the Data Protection Act 2018
This standard operating procedure is fully drafted and structured, ready to brand and complete for your service. It covers:
1. Purpose
2. Scope
3. Definitions
4. Responsibilities
5. Procedure
6. Records and documentation
7. Related documents
8. Training and competence
9. Monitoring and audit
10. Glossary
11. References
Legislation & standards it maps to
UK General Data Protection Regulation (UK GDPR)
Data Protection Act 2018
Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
Care Quality Commission (Registration) Regulations 2009
Privacy and Electronic Communications Regulations 2003 (PECR)
Computer Misuse Act 1990
Human Rights Act 1998
Common law duty of confidentiality
Who it applies to
All employed staff, bank and agency workers, directors, volunteers, contractors and data processors who handle personal data on behalf of [Organisation Name]
How it works
Buy securely with Stripe - instant, no VAT, no account needed.
Download your editable Word file from the link we email you straight away.
Complete the placeholders for your service, then have it approved before use.
Add the optional updates subscription and we keep it current as guidance changes.