Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Privacy breach & incident response

What should I do after a data breach?

Reviewed by the Privacy Horizon team · Last reviewed

Quick answer

After a data breach, move through four stages: contain the incident to stop further loss, investigate what data and people were affected, notify the right parties within your legal deadlines, and remediate the root cause. Document every decision as you go — regulators and customers will ask what happened and how you responded. If personal information was involved, you may have a legal duty to notify regulators and affected individuals, so determine your obligations early.

On this page

1. Contain the incident

Your first priority is to stop the bleeding. Isolate affected systems, revoke compromised credentials, and preserve evidence rather than wiping machines — logs and disk images are essential to understanding scope and meeting notification duties.

Resist the urge to immediately rebuild everything; act deliberately so you do not destroy the evidence you will need to investigate and report.

2. Investigate scope and severity

Determine what was accessed or exfiltrated, whose personal information was involved, and how the attacker got in. This assessment drives every later decision — especially whether the breach meets the legal threshold for notification.

3. Meet your notification obligations

Notification duties depend on the law that applies to the data and the people affected. Identify these early, because deadlines can be short:

  • PIPEDA (Canada, private sector): you must report breaches that pose a 'real risk of significant harm' to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible, and keep records of all breaches.
  • Provincial and health privacy laws (e.g., PHIPA in Ontario) impose their own breach-notification rules for health information custodians.
  • GDPR (EU/EEA personal data): notify the relevant supervisory authority within 72 hours of becoming aware where there is a risk to individuals, and notify affected individuals when the risk is high.
  • HIPAA (US protected health information): breach notification to individuals, and to regulators within defined timeframes, applies to covered entities and business associates.

4. Remediate and learn

Fix the root cause — not just the symptom. Patch the exploited vulnerability, reset and strengthen credentials, close the misconfiguration, and add monitoring so you would detect a repeat.

Hold a post-incident review and update your incident response plan, controls, and training based on what you learned. A breach handled well and transparently can preserve customer trust; one handled poorly compounds the damage.

Frequently asked questions

Not always — obligations usually hinge on whether the breach creates a real risk of significant harm to affected individuals. But under several laws you must keep a record of all breaches even when notification is not required, and the threshold can be lower than people expect. Assess each incident against the specific law that applies.

It varies by law: GDPR sets a 72-hour clock to notify the supervisory authority; PIPEDA requires reporting and notification 'as soon as feasible' after determining a real risk of significant harm. Treat the clock as starting when you become aware of the incident.

Paying is discouraged: it does not guarantee data recovery or deletion, may fund further crime, and can carry legal risk. Reliable, tested backups are the defence that lets you recover without paying. Involve legal counsel and, where appropriate, law enforcement.

Cybersecurity basics

How can I protect my personal and business information from cyberattacks?

A practical, layered approach to protecting personal and business information from cyberattacks: MFA, patching, backups, training, and a tested incident plan.

Read
Cybersecurity basics

How can I protect my business from ransomware and phishing?

Defend against ransomware and phishing with immutable backups, patching, MFA, email filtering, least privilege, network segmentation, and staff training.

Read
Privacy breach & incident response

When should you hire a privacy breach response consultant?

When should you hire a privacy breach response consultant? Hire one the moment you suspect a breach, lack in-house expertise, or want a retainer ready first.

Read
Privacy breach & incident response

Do you need an incident response plan, and what should it include?

Do you need an incident response plan, and what should it include? Yes — here are the six core components every plan needs and why regulators and buyers expect one.

Read
Privacy & security assessments

Do you need a TRA before moving sensitive data to a new cloud provider?

Do you need a TRA before moving sensitive data to a new cloud provider? When it's required, what it covers, and how it differs from a PIA — explained plainly.

Read
Cybersecurity basics

What's the difference between data privacy and cybersecurity?

Data privacy governs how personal information is collected, used, and shared; cybersecurity protects information and systems from threats. Here's how they differ and overlap.

Read

How Privacy Horizon can help

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.