Template id: breach-notice-ico-gb.v1 owner: Lilith-Privacy lead + UK
counsel deadline: 72 hours from confirmation submission: ICO personal data
breach report (online form or the ICO breach helpline for urgent cases)
Phased reporting is permitted: submit known facts within 72 hours and follow up; record the justification if any element is late.
Required content (UK GDPR Art. 33(3), ICO form structure)#
- Organisation details: controller name, registration (ICO fee reference), and the UK contact from the en-GB privacy policy.
- Nature of the breach: what happened; categories and approximate
numbers of data subjects and of personal-data records.
- V3 data-class checklist: V1 account records / e-mail addresses / payment metadata / voice transcripts / recordings / consent-ledger entries / DSAR exports / Pixel Streaming session logs (IP addresses).
- When: breach start, detection, confirmation (clock anchor), and why the report is late if past 72 hours.
- Likely consequences for data subjects, including any minors affected (call this out explicitly — Tara minor-safety scope).
- Measures taken or proposed: containment, mitigation, recurrence prevention.
- Data-subject notification plan: whether affected UK users are being told, how, and when; the high-risk assessment behind that decision.
- DPO / contact point for the ICO to follow up.
Internal routing#
- Drafted by: Lilith-Privacy lead. Reviewed by: UK counsel (mandatory). Submitted by: counsel or DPO.
- Evidence: submitted report, ICO reference number, and timestamps filed in the incident evidence bucket and referenced from the Operator Console case.