Workflow Template
Data Breach Response Workflow
Manages the end-to-end privacy incident response process: intake of a suspected data breach report, responder investigation and impact assessment, legal/privacy review with a notification decision, remediation and required communications, and formal incident closure with corrective actions recorded.
When a data breach is reported, teams often scramble across email threads, spreadsheets, and verbal handoffs, missing steps and losing the audit trail regulators expect. This workflow gives privacy, legal, and incident response teams a single structured process: log the breach, assign a responder, assess impact, route through legal review for a notification decision, remediate, and close with corrective actions recorded. Incident responders, legal/privacy reviewers, and operations managers run it together inside assess.one, with every decision and status change tracked.
Business Outcomes
- Cut breach response time by standardising intake through closure
- Reduce compliance risk with a documented legal/privacy notification decision at every incident
- Eliminate lost or missed steps with automatic status tracking from report to closure
- Create a full audit trail of investigation findings, decisions, and corrective actions for regulators
- Speed up reporter communication with built-in acknowledgement and closure notifications
Workflow Steps
Steps
- 1Create Breach Incident Recordcreate record
Registers the reported suspected breach as an incident record.
- 2Set Status to Reportedupdate record
Marks the incident as Reported on intake.
- 3Acknowledge Report to Reportersend email
Confirms receipt of the breach report to the reporter.
- 4Assign Responderassign user
Assigns the incident to a responder for investigation.
- 5Investigate and Assess Impactcreate task
Responder investigates the breach and records severity, root cause and impact assessment.
- 6Set Status to Under Investigationupdate record
Persists the investigation findings and updates incident status.
- 7Legal & Privacy Review and Notification Decisionrequest approval
Legal and privacy team review the breach findings and decide on approval to proceed plus the notification approach.
- 8Route on Legal & Privacy Review Outcome
Branches based on whether legal and privacy approve the response plan.
approval_status: "approved"→Capture Notification Decisionapproval_status: "rejected"→Revise Investigation FindingsDefault→End - 9Revise Investigation Findingsrestart from step
Rejected by legal/privacy review - responder must revise the investigation and impact assessment.
- 10Capture Notification Decisioncreate task
Legal and privacy record the notification decision and review notes.
- 11Persist Notification Decisionupdate record
Saves the notification decision and updates status to under review.
- 12Route on Notification Decision
Determines whether affected individuals must be notified via email.
notification_decision: "Notify Regulator and Individuals"→Notify Reporter Contact of Communication Requirementnotification_decision: "Notify Individuals Only"→Notify Reporter Contact of Communication Requirementnotification_decision: "Notify Regulator Only"→Set Status to Remediation In Progressnotification_decision: "No Notification Required"→Set Status to Remediation In ProgressDefault→Set Status to Remediation In Progress - 13Notify Reporter Contact of Communication Requirementsend email
Sends the approved notification communication requirement confirmation to the reporter for coordination.
- 14Set Status to Remediation In Progressupdate record
Updates incident status as remediation begins.
- 15Carry Out Remediation and Record Corrective Actionscreate task
Responder executes remediation, required communications, and records corrective actions to prevent recurrence.
- 16Persist Remediation and Corrective Actionsupdate record
Saves remediation and corrective action details to the record.
- 17Record Closure Summarycreate task
Privacy team records a final closure summary for the incident.
- 18Close Incidentupdate record
Sets the incident status to Closed and persists the closure summary.
- 19Notify Reporter of Closuresend email
Sends the reporter final confirmation that the incident has been resolved and closed.
Fields
- Reporter Name*
- Reporter Email*
- Discovery Details*
- Date Discovered*
- Affected Systems*
- Data Types Potentially Exposed*
- +13 more fields
Forms
Suspected Data Breach Report
9 fields
Data Views
All Breach Incidents
breach_incident_ref, incident_status, impact_severity, notification_decision +2 more
Dashboard Widgets
Recommended integrations
Setup the following integrations to extend workflow capability.
Send email in the workflow
AWS SES
Similar Categories
FAQs
How do I set up this data breach response workflow?
Publish the template in assess.one and it's live immediately — no implementation project required. Assign the roles (intake, responder, legal/privacy reviewer) and your team can log the next incident within minutes.
What do I need before I can start using this workflow?
You need to know who will act as responders and who holds legal/privacy review authority, since those roles drive the assignment and routing steps. Everything else, including status tracking and notifications, is configured inside assess.one.
How long does implementation take?
Publishing the template takes minutes. Once it's live, your team can create the first breach incident record and start running the process immediately — there's no multi-week rollout.
Can I customise the steps or approval logic?
Yes. You can edit step names, add or remove statuses, change who approves the notification decision, and adjust notification triggers directly in assess.one. This lets you match the workflow to your organisation's specific privacy policy or regulatory obligations.
Who needs access to this workflow?
At minimum, the person handling intake, the assigned responder, and the legal/privacy reviewer need access. Operations managers overseeing the incident should also have visibility into status and closure records.
What happens at the legal and privacy review step?
The reviewer assesses the investigation findings and makes a formal notification decision — whether affected parties or regulators must be informed. The workflow routes differently depending on that outcome, either sending findings back for revision or moving forward to notification and remediation.
How does the workflow handle notification decisions?
The notification decision is captured and persisted as a permanent record tied to the incident. Based on the outcome, the workflow automatically routes to notify the reporter contact if communication is required, keeping the decision and the follow-up action linked.
What gets recorded when an incident is closed?
Closure requires a recorded closure summary and documented corrective actions from remediation. This creates a complete record for audits or regulatory review, showing what happened, what was decided, and what was fixed.
Does this workflow support compliance requirements like GDPR breach notification?
The workflow's legal/privacy review and notification decision steps are built to support the kind of assessment GDPR and similar regulations require. You can customise the review criteria and notification triggers in assess.one to match your specific regulatory obligations.
Can the reporter track the status of their breach report?
Yes. The workflow includes automatic acknowledgement when the report is created and a closure notification once the incident is resolved, so reporters aren't left in the dark.
Ready to use this workflow?
Create a free account and customise this workflow for your business.
