Managing Data Breaches – Detect, Respond and Recover

Online

Overview

With cyber threats and data breaches on the rise, organisations must be fully prepared to respond effectively to personal data breaches. This full-day training course provides a structured and practical approach to managing personal data breaches, ensuring compliance with UK GDPR and regulatory obligations. Delegates will gain an in-depth understanding of incident response processes, risk assessment, and notification requirements, learning how to minimise legal, financial, and reputational risks. The course will cover real-life breach scenarios, allowing participants to apply their learning in a practical, hands-on way.

Whether you work in compliance, data protection, IT security, or risk management, this course equips you with the tools and confidence to handle data breaches effectively. From assessing risks to affected data subjects and notifying the ICO within 72 hours to developing clear communication strategies and ensuring robust record-keeping, attendees will leave with practical knowledge to strengthen their organisation’s response and resilience. With regulatory scrutiny increasing, knowing how to act swiftly and decisively in a breach scenario is critical—making this a must-attend course for any organisation handling personal data.

Learning Outcomes:

  • Understand the definition of a personal data breach under UK GDPR.
  • Learn the incident response process, including detection, containment, recovery, and lessons learned.
  • Assess risks to affected data subjects and determine when notification is required.
  • Develop clear communication messages for data subjects and stakeholders in case of a breach.
  • Understand the ICO notification requirements and steps to follow within the 72-hour deadline.
  • Learn record-keeping requirements for documenting personal data breaches.
  • Evaluate technical and organisational controls to prevent future breaches.
  • Understand the responsibilities of data controllers and data processors in breach scenarios.
  • Identify the consequences of failing to notify the ICO of a reportable breach.
  • Explore the legal implications of data breaches, including the right to compensation for affected individuals.

For more information or to make a booking please call 0330 0947 344

Agenda

  • Registration
  • Introduction & Housekeeping
  • Preparation
    • Definitions & Principles
    • Identifying insider and external threats
    • Creating a risk register
    • Examples of technical and organisational controls
    • Identifying your incident response team
    • Creating your data breach policy
    • Staff awareness and training
    • Your Action Plan
  • Comfort Break
  • Detect & Analyse
    • Is it a personal data breach
    • Security incident vs personal data breach
    • Breach reporting decision framework
    • Understand the type of incident
    • Understand the severity of the incident
    • Investigating the breach
    • Scenario: group exercise
    • Your Action Plan
  • Lunch
  • Contain & Recover
    • Containing the breach
      • Root cause analysis
      • Managing the PR fallout
    • Scenario: group exercise
    • Communicating with data subjects and stakeholders
      • When to notify data subjects
      • What to include
      • Exemptions
    • Notification obligations
      • Notifying the Supervisory Authority
      • ICO breach reporting checklist
      • Record-keeping requirements
    • Recovery
    • Your Action Plan
  • Coffee Break
  • Implementing the Lessons Learned
    • Post-incident review
    • Consequences of failing to notify a Supervisory Authority
    • Right to Compensation
    • Lessons from High Profile Data Breaches
      • South Staffordshire Plc.
      • DPP Law
      • Advanced Health and Care Ltd
    • Your Action Plan
  • Trainer’s Summary and Q&A

    *Programme subject to change

Get in Touch

Book Now

  • Public Sector £550 + VAT
  • Private Sector £620 + VAT
  • Voluntary Sector £480 + VAT

Please select your preferred course date:

Need to book for 6 or more people?

We are now taking bookings for our wide range of training packages in-house; we also offer bespoke packages tailored for your organisation.


For more information or to discuss the available option please call 0203 926 5674 or email info@gov-pd.co.uk 

Trainer

Trainer Bio: Kellie Peters

Kellie Peters is a seasoned GDPR and Data Protection Consultant with an extensive background in data governance, compliance, and security. As the co-founder of Databasix UK Ltd, she has spent nearly a decade providing strategic data protection consultancy to organisations across multiple industries, including healthcare, public sector, and corporate enterprises. Prior to this, Kellie held senior roles in Public Health England and Solutions for Public Health, where she played a pivotal role in data management, regulatory compliance, and stakeholder engagement. She successfully led national initiatives, including the design and rollout of England’s chemotherapy national patient-based database, ensuring compliance with data protection and governance frameworks.

With over 20 years of experience, Kellie has specialised in GDPR audits, internal compliance programmes, and regulatory risk assessments. As an Outsourced Data Protection Officer (DPO), she has provided guidance on data breach management, DPIAs, vendor due diligence, and policy development. Her expertise extends to conducting internal audits, reviewing data protection impact assessments, and advising on international data transfers. Having worked in both governmental and private sector environments, Kellie brings a wealth of knowledge in navigating complex data protection regulations and ensuring organisations remain compliant. Her deep understanding of data protection law, regulatory frameworks, and risk mitigation strategies makes her exceptionally well-placed to deliver expert-led training in data protection compliance.

Browse all our training courses