This Flowchart illustrates how to manage a data protection breach (including a cybersecurity breach) under the UK General Data Protection Regulation (UK GDPR). It reflects personal data breach reporting and recording requirements under the UK GDPR together with data breach management guidance issued by the Information Commissioner's Office (ICO). It maps out a data breach process, providing guidance and links to relevant precedents for each stage of that process. See Precedents: Personal data breach plan, Data breach report form—internal and Data breach assessment and action plan, which guide you through each stage of this workflow. Note 1—assemble data breach team The first step is to assemble your data breach team. Consider who within the organisation would be best placed to react swiftly to the breach and who should be involved with the subsequent investigation. This will often involve input from specialists across the business such as IT, HR and compliance/legal and, in some cases, contact with external stakeholders and suppliers. Precedent: Personal data breach plan encourages you to assemble a skeleton data breach team in advance