This Precedent personal data breach plan can be used by organisations to inform their staff and managers of the actions to take on discovering a personal data breach (including a cybersecurity breach). It reflects reporting requirements in the EU General Data Protection Regulation (GDPR) and takes into account relevant guidance from the Data Protection Commission (DPC). It incorporates a process for dealing with actual or suspected personal data breaches. A personal data breach plan may also be known as a data breach policy. This Precedent can also be used for cybersecurity breaches that involve the loss of, damage to or unauthorised access to personal data. On discovering a data breach, the first thing you should do is assemble a data breach team comprising the various people within your organisation who are best placed to respond to the breach, eg the data protection officer (if you have one), risk partner, head of IT, head of compliance, head of legal and, if employee data is involved, your head of HR. Having assembled your data breach team, you can then take appropriate