Data and privacy · Privacy team, DPO, general counsel, supervising partner
A personal data breach, the 72-hour assessment
An export containing HR records for 214 people was sent to the wrong address. The Article 33 clock started at awareness, and the assessment has to be defensible within the 72-hour window, whichever way the decision goes.
- Agents
- First draft
- A grounded research answer in under a minute, then a Regulator Response assessment signed off within the hour.
- Steps
- 5
The problem
Step 01 of 05
Open the matter and record the clock
Awareness and the Article 33 deadline go on the matter as key dates; the incident note, the export manifest, the mail log and the firm's own board minutes are added.


Step 02 of 05
Ask the assessment question
The 72-hour trigger, the phased notification allowance under Article 33(4), and the Article 34 threshold for telling the individuals are set out against the specific data categories involved.


Step 03 of 05
Produce the assessment
The Privacy & Data Protection Agent runs with Prepare for: Regulator Response, covering the chronology, the risk assessment, the notification recommendation and the Article 33(5) record entry.


Step 04 of 05
Read the recommendation
Notify the ICO by the deadline, communicate to the affected individuals under Article 34 prioritising the special-category data subjects, and do not wait for the recipient to respond.


Step 05 of 05
Sign off and share
The partner ticks the action items, clicks Verify all, and shares the assessment with the client on a passcode link with the view logged.


What comes back
A document, not a transcript.
- A recommendation on notifying the ICO and on communicating to data subjects, with the reasoning against Articles 33 and 34 written out.
- A numbered chronology and a note of the categories of data and the number of people affected.
- Remediation action items with owners and dates, including the Article 33(5) internal record entry.
- An unrelated compliance gap surfaced from the firm's own board minutes, an overdue subject access request.
Authorities it checks
- UK GDPR, Art 9, Art 33, Art 34
- Data Protection Act 2018
- ICO guidance on personal data breaches
What it does not do
- It does not decide the notification for the firm; the recommendation is a draft for the DPO to act on within the window.
- It does not confirm whether the recipient has deleted the data; that is an outstanding action item, not an assumption.
- It records the exemption reasoning rather than asserting risk is low without stating why.