# Breach Notification Template — United Kingdom (UK GDPR, ICO)

Template id: `breach-notice-ico-gb.v1` owner: Lilith-Privacy lead + UK
counsel deadline: 72 hours from confirmation submission: ICO personal data
breach report (online form or the ICO breach helpline for urgent cases)

Phased reporting is permitted: submit known facts within 72 hours and follow
up; record the justification if any element is late.

## Required content (UK GDPR Art. 33(3), ICO form structure)

1. **Organisation details**: controller name, registration (ICO fee
   reference), and the UK contact from the en-GB privacy policy.
2. **Nature of the breach**: what happened; categories and approximate
   numbers of data subjects and of personal-data records.
   - V3 data-class checklist: V1 account records / e-mail addresses / payment
     metadata / voice transcripts / recordings / consent-ledger entries /
     DSAR exports / Pixel Streaming session logs (IP addresses).
3. **When**: breach start, detection, confirmation (clock anchor), and why
   the report is late if past 72 hours.
4. **Likely consequences** for data subjects, including any minors affected
   (call this out explicitly — Tara minor-safety scope).
5. **Measures taken or proposed**: containment, mitigation, recurrence
   prevention.
6. **Data-subject notification plan**: whether affected UK users are being
   told, how, and when; the high-risk assessment behind that decision.
7. **DPO / contact point** for the ICO to follow up.

## Internal routing

- Drafted by: Lilith-Privacy lead. Reviewed by: UK counsel (mandatory).
  Submitted by: counsel or DPO.
- Evidence: submitted report, ICO reference number, and timestamps filed in
  the incident evidence bucket and referenced from the Operator Console case.
