LegalAI Space

Data and privacy · Privacy team, DPO, general counsel, supervising partner

A personal data breach, the 72-hour assessment

An export containing HR records for 214 people was sent to the wrong address. The Article 33 clock started at awareness, and the assessment has to be defensible within the 72-hour window, whichever way the decision goes.

Agents
First draft
A grounded research answer in under a minute, then a Regulator Response assessment signed off within the hour.
Steps
5

The problem

The 72-hour trigger runs from awareness, not from full certainty about scope, and the decision on notifying data subjects under Article 34 depends on a high-risk assessment that has to be reasoned, not asserted, in the document the regulator will read.
  1. Step 01 of 05

    Open the matter and record the clock

    Awareness and the Article 33 deadline go on the matter as key dates; the incident note, the export manifest, the mail log and the firm's own board minutes are added.

    The matter page.
  2. Step 02 of 05

    Ask the assessment question

    The 72-hour trigger, the phased notification allowance under Article 33(4), and the Article 34 threshold for telling the individuals are set out against the specific data categories involved.

    A chat answer with authorities.
  3. Step 03 of 05

    Produce the assessment

    The Privacy & Data Protection Agent runs with Prepare for: Regulator Response, covering the chronology, the risk assessment, the notification recommendation and the Article 33(5) record entry.

    The run panel with plan, gates and live status.
  4. Step 04 of 05

    Read the recommendation

    Notify the ICO by the deadline, communicate to the affected individuals under Article 34 prioritising the special-category data subjects, and do not wait for the recipient to respond.

    The completed memo.
  5. Step 05 of 05

    Sign off and share

    The partner ticks the action items, clicks Verify all, and shares the assessment with the client on a passcode link with the view logged.

    A client share link and its view log.

What comes back

A document, not a transcript.

  • A recommendation on notifying the ICO and on communicating to data subjects, with the reasoning against Articles 33 and 34 written out.
  • A numbered chronology and a note of the categories of data and the number of people affected.
  • Remediation action items with owners and dates, including the Article 33(5) internal record entry.
  • An unrelated compliance gap surfaced from the firm's own board minutes, an overdue subject access request.

Authorities it checks

  • UK GDPR, Art 9, Art 33, Art 34
  • Data Protection Act 2018
  • ICO guidance on personal data breaches
Every source it may cite

What it does not do

  • It does not decide the notification for the firm; the recommendation is a draft for the DPO to act on within the window.
  • It does not confirm whether the recipient has deleted the data; that is an outstanding action item, not an assumption.
  • It records the exemption reasoning rather than asserting risk is low without stating why.

Run this on your own document

Free plan, two seats, no card.