# Data breach response policy

Source: https://aestech.com.au/policy-templates/#data-breach-response-policy
Markdown URL: https://aestech.com.au/policy-templates/data-breach-response-policy.md

Use for ISO 27001 A.5.24 to A.5.28, SOC 2 incident handling, privacy notification, and PCI DSS requirement 12.10.

Frameworks: ISO 27001, SOC 2, PCI DSS

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines how the company responds to a suspected or confirmed data breach involving personal, customer, cardholder or other sensitive data, including assessment, containment, notification and review. It complements the incident response policy with breach-specific notification duties.

2. Scope
This policy applies to any event that may have resulted in unauthorised access to, disclosure of, loss of or alteration of personal or sensitive data, whether caused internally, by a supplier or by an external attacker.

3. Policy statements
- Any suspected data breach must be reported immediately through the incident channel.
- The company must assess whether personal or sensitive data was involved and the likely harm to affected individuals.
- Containment must take priority, while preserving evidence for investigation.
- The company must determine its notification obligations to regulators, affected individuals, customers, card brands and acquiring banks, and the applicable timeframes.
- Where notification to a regulator is required, it must be made within the legally required timeframe, for example without undue delay and within [72] hours of becoming aware where that applies.
- Affected individuals must be notified where required, with clear information on the breach and recommended actions.
- All breach decisions, assessments and communications must be documented.
- A post-breach review must identify root cause and corrective actions.

4. Roles and responsibilities
- The [Incident Manager] coordinates the overall response.
- The [Data Protection Lead or Legal] determines notification obligations and timeframes.
- The [Communications Lead] manages internal and external messaging.
- Executive management approves regulatory and customer notifications.

5. Procedures
- Triage the report and confirm whether sensitive data is involved.
- Contain the breach and preserve evidence.
- Assess scope, data categories, number of affected individuals and likely harm.
- Decide and execute required notifications within the applicable timeframes.
- Maintain a record of the breach and all decisions.
- Hold a post-breach review and track corrective actions to closure.

6. Evidence and records
Keep the breach record, assessment of harm, notification decisions and content, regulator and customer correspondence, timelines, root cause analysis and corrective actions.

7. Review cadence
This policy is reviewed at least annually and after any significant breach or change to notification law.

Owner: [role]
Version: [x.y]   Approved by: [name/role]   Date: [date]
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md