Resources · Ireland
Ireland · GDPR

How to manage data breaches

How to record a personal-data breach, classify the risk, notify the Data Protection Commission and affected people when you must, and evidence how you contained it.

1 Obligations under the regulations

A personal-data breach is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. In an insurance firm that is often a claims file sent to the wrong recipient, an exposed mailbox, or a supplier incident — as well as a cyber-attack.

GDPR Articles 33 and 34 · Data Protection Act 2018

Notify the Data Protection Commission without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons (Article 33). If you notify after 72 hours, explain the delay. Where the breach is likely to result in a high risk, communicate it to the affected people without undue delay (Article 34). Article 33(5) requires you to document every breach — facts, effects and remedial action — including those you decide not to notify.

The same event can also be a consumer error under the Consumer Protection Code 2025, or a major ICT-related incident under DORA. Those clocks are separate from the 72 hours. See errors and incidents for the CPC and DORA path. Health data on a claim file is special-category data and should push the risk assessment up.

2 What do I need to do

Open the record when you become aware. The DPC notification is easier to make on time if containment, numbers and likely consequences are already written down.

1. Record the breach and the moment you became aware

What happened, which system or supplier, and a first list of who is affected. The 72-hour period runs from awareness, not from the end of the investigation. Regzact can assist: record the breach on the Data Breaches register immediately, with the awareness time that starts the 72-hour clock.

2. Contain it and classify the risk

Stop further loss or disclosure. Classify the breach as unlikely to result in a risk, a risk (notify the DPC), or a high risk (notify the DPC and the individuals). Record the reasons either way. Regzact can assist: classify the breach and assign owners and tasks for containment.

3. Notify the DPC and, where the risk is high, the people affected

Notify the DPC within 72 hours where there is a risk: nature of the breach, categories and approximate numbers, likely consequences, and the measures taken or proposed. Tell individuals where Article 34 applies, unless you have recorded a valid exception. If the event is also a CPC error or a DORA incident, run those notifications on their own clocks. Regzact can assist: track notification tasks, deadlines and the record of what was sent.

4. Mitigate and close the file

Recover what you can, support the people affected, fix the control, and write down the facts, effects and remedial action. That record is required even when you did not notify. Regzact can assist: track mitigation through to close-out, and keep the decision not to notify beside the facts.

3 What records do I need to keep

Article 33(5) applies to every breach. The DPC can ask for the ones you assessed as below the notification line.

  • Facts, including when you became aware and how the breach was discovered
  • Categories of personal data and of data subjects, with approximate numbers
  • The risk classification and the reasons, including a decision that notification was not required
  • Containment and the people responsible
  • The DPC notification, the time it was sent, and any explanation for delay
  • Communications to individuals, or the Article 34 exception relied on
  • Any parallel CPC or DORA notification
  • Effects, remedial action, root cause and the control that changed

Keep these with your Article 30 record of processing. Retain them for the life of any DPC inquiry and in line with your retention schedule after that.

4 Using AI to streamline the process

Whether a breach meets the DPC or customer-notification test is a decision for the firm. AI can get the file into shape inside the 72 hours:

  • Structure a first report into facts, data types and a timeline
  • Flag special-category data, large volumes, or wording that suggests high risk
  • Draft a DPC notification or a customer notice for approval
  • Group similar breaches so repeat causes show up in reporting

Do not let a model decide whether to notify. Use it to assemble the file; keep the risk decision with the data-protection lead.

5 How Regzact can help

The Data Breaches register is built to record, classify, notify and mitigate: from the first report through containment, notification and close-out.

  • Immediate capture, including the time you became aware
  • Classification of risk and tasks for containment and notification
  • A record of DPC and customer notifications, and of decisions not to notify
  • Mitigation tracked to close-out, with reporting and file export

Subject access requests, errors and complaints sit on the same platform when a breach triggers a second process.

Open the Registers solution · Book a demo

This is a practical how-to for compliance managers. It is not legal advice. Always check the current text of the regulations and your own policies before you act.

Keep going

Other how-tos for Ireland compliance teams.

Start Your Trial Today.

Join insurers, MGAs, and brokers across the UK and Ireland who have made compliance a strategic advantage. Book a personalised demo and see Regzact working with your own network.

No credit card required All regulatory frameworks included Set up in under a day

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.