2. When data go missing — breaches

What a breach is

A personal-data breach is a security incident that leads to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. A laptop on a train, a misdirected email, a ransomware lock, a reception list left in a taxi, or a staff member looking up a neighbour “out of curiosity” can all qualify.

First hour

Contain it: remote wipe if you can, recover the envelope, lock the account, stop the forwarding rule. Tell the IG lead. Write down facts — what, when, how many people, what type of data, whether it is encrypted, whether it has been seen. Do not wait a week hoping nobody notices.

ICO

If the breach is likely to result in a risk to people’s rights and freedoms, UK GDPR expects notification to the ICO without undue delay and, where feasible, within 72 hours of becoming aware. If you miss 72 hours, notify anyway and explain why. Not every incident meets the threshold — that is a reasoned decision, not a shrug. High-risk breaches may also require you to tell the people affected.

Patients and staff

Be factual. Do not hide it, and do not over-apologise into a legal admission you have not checked with indemnity. Support staff who reported it. Punishing the messenger is how the next USB stick stays secret.

Learn

Change the process: encryption, a checklist for home visits, a ban on personal email. Put it through a practice meeting without naming patients in an open forum.