← Back to insights
INCIDENT RESPONSE

PDPA Data Breach Response Plan: What Organisations Should Prepare

A practical operating model for detecting, containing, assessing, communicating, and learning from personal-data incidents.

Written by Lahiru Livera, Cybersecurity Advisor · Last reviewed: August 2026
Educational guidance only — not legal advice. Notification duties, timelines, and communication requirements must be verified against current official sources and professional advice.

A data breach plan is a business resilience plan

Personal-data incidents are rarely only technical events. They can affect customers, employees, service delivery, reputation, legal risk, suppliers, and leadership confidence. A tested plan gives teams a common language, clear responsibilities, and a disciplined way to make decisions under pressure.

PHASE 1

Prepare

Define the incident team, contact list, escalation path, decision authority, legal and communications support, evidence handling, and tabletop exercise schedule.

PHASE 2

Detect and triage

Create routes for staff, suppliers, monitoring tools, and customers to report suspected incidents. Record the time, source, systems involved, and immediate risk.

PHASE 3

Contain

Take proportionate action to stop further exposure or unauthorised activity. Preserve evidence while isolating affected accounts, systems, integrations, or access paths.

PHASE 4

Assess impact

Identify what happened, which data may be involved, whose data may be affected, how long the exposure lasted, whether data was accessed or exfiltrated, and what harm may result.

PHASE 5

Decide and escalate

Use a documented decision process involving privacy, security, legal, business owners, and leadership. Verify notification and communication requirements against current official guidance.

PHASE 6

Communicate

Prepare clear, factual communications for leadership, affected people, customers, suppliers, regulators, or other stakeholders where required and appropriate.

PHASE 7

Recover

Restore services safely, remove attacker access or technical weaknesses, reset credentials where needed, and confirm that containment measures are effective.

PHASE 8

Learn and improve

Document lessons learned, update controls, improve training, revise supplier requirements, and test the revised response plan.

Minimum evidence to retain

Maintain a timeline, decision log, affected systems, data categories, known or suspected impact, containment actions, communications, supporting evidence, and improvement actions. This is essential for learning, management oversight, and demonstrating a disciplined response.

Incident readiness

Know your gaps before an incident tests them.

Assess readiness across governance, security, incident response, supplier management, and privacy operations.

Start free assessment →