Excerpt 1
DATA BREACH RESPONSE
Immediate Response Identify the source of the breach Isolate the affected system(s) Take steps to prevent further data loss Notify IT department and other relevant parties
A Word checklist of incident-response steps: contain, record, assess, and follow up. Keep it next to your register. Notification duties depend on the incident, not on ticking every box.
Free
More in Worksheets · Also see Policies

Preview
English. Word file (Data-Breach-Response-Checklist-rqqmoa.docx). Excerpts below are copied from this upload.
Excerpt 1
Immediate Response Identify the source of the breach Isolate the affected system(s) Take steps to prevent further data loss Notify IT department and other relevant parties
Excerpt 2
Identify the type(s) of data compromised Identify the number of individuals affected Determine the cause of the breach Notify law enforcement, if necessary Notify affected individuals, if required by law or regulation
Excerpt 3
Notify third-party vendors, if applicable Implement remediation procedures to prevent a similar breach from occurring in the future Assess the effectiveness of current security measures and make necessary changes Consider offering identity theft protection and credit monitoring services to affected individuals Review and revise privacy and security policies, procedures, and training
Excerpt 4
Conduct a post-incident review to identify areas for improvement Report the breach to senior management and/or the board of directors Note: This checklist is provided as a sample by privacytemplate.com and should be customized to fit the specific needs and circumstances of your organization.
Text copied from the uploaded file. It is not the complete download.
A free Word checklist for the first hours of a suspected breach: contain, record, escalate, communicate. Print it or keep it in the incident channel. Use it with the paid action plan when you need more narrative.
For one organization's internal use. You may customize the files. You may not resell or redistribute them as products. They are starting documents or training clips, not legal advice, not a certification, and not a guarantee of compliance — have qualified counsel review them for your situation.

A Word checklist of GDPR program tasks, from records of processing to incident handling. Use it to see what is still blank. Completing the list is not a certification and does not by itself prevent a fine.
Free
No checkout

An Excel register of processing activities (ROPA-style). Add your systems, purposes, and retention periods. It does not inventory your estate for you.
Free
No checkout

A Word checklist to help you decide whether a DPIA is likely required. Answer the questions for the processing in front of you. A “yes” is a prompt to assess, not a completed DPIA.
Free
No checkout
Data Breach Response - Checklist
Free