The UK GDPR creates a legal obligation to report certain data breaches to the Information Commissioner's Office within 72 hours of identification.
In order to comply with this requirement, all staff must notify the Information Governance Team of suspected or actual data breaches immediately on identification.
In the event a breach is suspected or identified outside of core working hours, the Information Governance Team must still be notified immediately.
A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This includes breaches that are the result of both accidental and deliberate causes. It also means that a breach is more than just about losing personal data. [Article 4 UK GDPR]
A data breach may include:
Notify the Information Governance Team immediately using the report a breach form above.
You can report data breaches by email to dataprotection@york.ac.uk. Please include 'breach' in your email subject line. When reporting by email, please provide us with as much information as possible about the incident.