Lilith Metaverse · Legal

Breach Notification Template — United Kingdom (UK GDPR, ICO)

1.

2sections1 minread

On this page

Template id: breach-notice-ico-gb.v1 owner: Lilith-Privacy lead + UK counsel deadline: 72 hours from confirmation submission: ICO personal data breach report (online form or the ICO breach helpline for urgent cases)

Phased reporting is permitted: submit known facts within 72 hours and follow up; record the justification if any element is late.

Required content (UK GDPR Art. 33(3), ICO form structure)#

  1. Organisation details: controller name, registration (ICO fee reference), and the UK contact from the en-GB privacy policy.
  2. Nature of the breach: what happened; categories and approximate numbers of data subjects and of personal-data records.
    • V3 data-class checklist: V1 account records / e-mail addresses / payment metadata / voice transcripts / recordings / consent-ledger entries / DSAR exports / Pixel Streaming session logs (IP addresses).
  3. When: breach start, detection, confirmation (clock anchor), and why the report is late if past 72 hours.
  4. Likely consequences for data subjects, including any minors affected (call this out explicitly — Tara minor-safety scope).
  5. Measures taken or proposed: containment, mitigation, recurrence prevention.
  6. Data-subject notification plan: whether affected UK users are being told, how, and when; the high-risk assessment behind that decision.
  7. DPO / contact point for the ICO to follow up.

Internal routing#

  • Drafted by: Lilith-Privacy lead. Reviewed by: UK counsel (mandatory). Submitted by: counsel or DPO.
  • Evidence: submitted report, ICO reference number, and timestamps filed in the incident evidence bucket and referenced from the Operator Console case.