[...] it acted diligently in complying with the obligations imposed on it in the event of a personal data breach [translation]
Phase 0 · Before anything happens
0.1. Have the protocol in writing, approved and dated
A protocol that exists only in the heads of two people is not a protocol: it is a memory. It must be written, approved by someone with authority to do so and visibly dated. What it leaves documented: the approved document, the date of approval, who approved it and the version history. (Rule A · SAP Madrid 371/2023, of 28 July)
0.2. Name in writing who activates the protocol and who decides
With a name and a deputy. Doubt about who is in charge costs hours, and the hours are counted. What it leaves documented: the appointment by name, dated, and a record that those appointed know about it. (Rule D · SAP Asturias 412/2024, of 3 October)
0.3. Identify, processing operation by processing operation, who is controller and who is processor
Security obligations are imposed only on the controller or the processor. Knowing which position you are in with respect to each supplier decides who answers when the claim arrives. What it leaves documented: the map of processing operations and suppliers, and the Article 28 GDPR data processing agreement signed with each of them. (Rule B · SAP Madrid 371/2023, of 28 July)
Hour 0 to 1 · Detection and activation
1. Note the exact time of detection and who detected it
The seventy-two hour clock starts when you become aware of the incident, not when you decide to react. That moment must be fixed in writing on the same day, not reconstructed afterwards. Who decides: nobody; it is recorded. What it leaves documented: the date and time of detection, the person who detected it, how it was detected and who they told. (Rule D · SAP Asturias 412/2024, of 3 October)
2. Activate the protocol and record the activation
Activation is in itself an act of diligence: prove it. Who decides: the person appointed under point 0.2. What it leaves documented: the time of activation, who ordered it, who was called in and by what means. (Rule A · SAP Madrid 371/2023, of 28 July)
3. Open the incident file and give it a number
A single file, with a single person responsible for its custody, into which everything goes: emails, minutes, screen captures, communications and decisions. Whatever is scattered across personal folders cannot be produced in court. Who decides: the person appointed. What it leaves documented: the index of the file from the first minute, with the person who holds it. (Rule D · SAP Madrid 123/2026)
Hour 1 to 6 · Containment and first decisions
4. Decide the containment measures and give reasons in writing
What you considered and rejected, and why, matters as much as what you did. A reasoned decision, even one that later proves improvable, can be defended; a decision with no trace cannot. Who decides: management, with the technical input required. What it leaves documented: brief minutes with the time, the options considered, the measure adopted, the reason and the person who decided. (Rule A · SAP Madrid 371/2023, of 28 July)
5. Preserve the information about the incident before touching anything
The access records and the communications from those first hours are, later on, your evidence. Keep them intact and note who collected them and when. Who decides: the person responsible for the file. What it leaves documented: what was preserved, on what date, who did it and where it is kept. (Rule D · SAP Asturias 412/2024, of 3 October)
6. Notify the suppliers involved in writing and ask them for their account
If the incident happens at a processor's premises, the Article 28 contract obliges it to assist you and to inform you without delay. Demand it in writing, even if they have called you by telephone. Who decides: the person responsible for the file. What it leaves documented: the communication sent with its date, the reply received and the applicable data processing agreement. (Rule B · SAP Madrid 371/2023, of 28 July)
7. Document the measures that already applied to the affected data
The courts assess in the specific case, one case at a time, and have found modest measures sufficient where they were proven: a file protected by a password known only to two people was enough for an acquittal. Gather now the proof of what protection the affected data had before the incident. What it leaves documented: the dated inventory of measures applicable to that data and who had access to it. (Rule A · SAP Madrid 371/2023, of 28 July)
[...] the data [...] was handed over by means of an Excel file encoded with a password known only to the Chair and the Secretary of the Committee [translation]
Hour 6 to 24 · Risk assessment
8. Determine which data has been affected and how many people
Without that perimeter you cannot assess the risk or draft a notification. If in the first hours you have only an estimate, record it as an estimate and note the time at which the final number was settled. Who decides: the person responsible for the file. What it leaves documented: the categories of data, the approximate number of people, and how that number evolved with its times. (Rule D · SAP Asturias 412/2024, of 3 October)
9. Assess the risk to people and give reasons for the decision whether or not to notify
The decision not to notify is as legitimate as the opposite one, provided it is reasoned and dated. What cannot be defended is not having decided. Who decides: management, with the legal input required. What it leaves documented: the risk analysis, the conclusion, the date, the time and the signature of whoever decided. (Rule D · SAP Madrid 123/2026)
10. Check whether the affected data was accurate and up to date
A breach usually exposes data that should no longer have been there, or that was wrong. The accuracy principle requires it to be erased or rectified without delay, and that obligation does not wait for the incident to close. What it leaves documented: the check carried out, what was corrected, on what date and who did it. (Rule E · SAP Asturias 412/2024, of 3 October)
Under Article 5.1(d) GDPR, data shall be accurate and, where necessary, kept up to date, which obliges controllers to take every reasonable step to ensure that inaccurate data is erased or rectified without delay [translation]
Hour 24 to 72 · Communications
11. Notify the supervisory authority within the deadline and keep the receipt
The submission receipt, with its date and time, is the proof that you complied. Keep it in the file, not in the mailbox of whoever submitted it. Who decides: management. What it leaves documented: the form submitted, the receipt and the person who submitted it. (Rule D · SAP Asturias 412/2024, of 3 October)
12. If you notify late or in phases, explain the reason in writing
Delay can be justified; silence cannot. What it leaves documented: the reason for the delay or for sending in phases, with the dates of each submission. (Rule D · SAP Madrid 123/2026)
13. Where appropriate, inform the people affected and keep the exact text
Keep the full text that was sent, the list of recipients, the date and the channel. Months later nobody will remember exactly what was said, and that wording will be read out in court. Who decides: management. What it leaves documented: the text, the date, the channel, the number of recipients and evidence of the sending. (Rule A · SAP Madrid 371/2023, of 28 July)
14. Verify the identity of anyone who makes a claim or asks you for data as a result of the incident
Impersonation proliferates after a breach. The controller's fault is presumed, and to be exonerated you must prove the diligence applied, including the diligence directed against identity impersonation. What it leaves documented: what identity check you made, using what document and who carried it out. (Rule C · SAP Madrid 273/2024)
From hour 72 onwards · Rights and closing
15. Set up the route for handling erasure requests and other rights requests
The procedure must be simple and free of charge, and you must decide expressly even where you hold no data on the applicant. The deadline is one month, extendable by a further two months only on grounds of complexity and provided the extension is communicated within the first month. What it leaves documented: the date each request was received, the express reply, the date of reply and, where applicable, the communication of the extension. (Rule F · SAP Barcelona 307/2023 · SAP Alicante 33/2024)
The controller is obliged to give the data subject a simple and free procedure for dealing with the exercise of these rights. [translation]
16. Erase or rectify without delay whatever has been left inaccurate
And prove the date on which you did it. Processing that was lawful at the outset may cease to be so through the mere passage of time. What it leaves documented: what was erased or rectified, when, at whose request and who carried it out. (Rule E · SAP Asturias 412/2024, of 3 October · SAP Alicante 33/2024)
17. Close the file with an index, dates and a person responsible for custody
Closing is the moment when the file stops being a working folder and becomes a means of evidence. It must be capable of being handed over complete, ordered and dated, without depending on whether the people who lived through it are still with the company. What it leaves documented: the final index, the date of closing, the person responsible for custody and the retention period. (Rule D · SAP Asturias 412/2024, of 3 October)
18. Review the protocol in the light of what happened and record the review
A dated review after the incident is one of the most eloquent pieces of evidence of diligence you can produce. What it leaves documented: what was changed, why, who approved it and on what date. (Rule A · SAP Madrid 371/2023, of 28 July)
Who decides what
- Management: activating the protocol, adopting the containment measures, deciding whether notification is given and approving the text of the communications.
- The person responsible for the file: opening and holding the file, dating each entry, making demands of the suppliers and closing the file.
- Legal advisers: assessing the risk to people, drafting and reviewing the communications and handling the exercise of rights.
- Nobody, on their own initiative: deleting records, replying to an affected person without keeping a copy or agreeing something verbally with a supplier.
How to use this protocol
- Print it and keep it accessible outside your systems: on the day you need it you may not be able to open it from inside.
- Note the time of each step while it happens. What is reconstructed afterwards is worth far less than what is noted at the time.
- Do not wait for certainty before documenting: record what you know and what you do not yet know, with the time at which each piece of information was settled.
- Go through it once a year and after every incident, and leave a dated record of that review.
Indicative model. It does not replace legal advice. Read the no-advice disclaimer. © ILP Abogados — www.ilpabogados.com
Do you have someone to pick up the phone in hour 1?
The ILP Abogados 72-Hour Standby is with your company from detection to the closing of the file, making sure at every step that the evidence you will later need is left behind.
See the 72-Hour Standby