Section 13 of the template

Breaches & serious incidents

What happens when something goes wrong: the disciplinary and escalation routes, set out before you need them.

Home › Breaches & serious incidents

Your policy needs to be clear about what happens when it’s broken. Set the routes out in advance and you can respond calmly and consistently when you’re under pressure.

What it is

The consequences and the escalation routes: how a breach of the policy is handled through your disciplinary framework; how a personal-data breach is reported and, where required, escalated to the ICO; and how a serious incident, such as a safeguarding matter or a significant data loss, is escalated internally and to the relevant authorities.

Why it’s important

Personal-data breaches carry statutory reporting deadlines, and safeguarding incidents carry duties of their own. Deciding the routes now — who’s told, in what order, and within what time — means a stressful event is handled as a process you already have, rather than one you invent on the day. It also makes clear to staff that the rules are real, which is a deterrent in itself.

What you decide here

  • Your disciplinary route for the misuse of AI.
  • Your personal-data breach reporting route, including escalation to the ICO where required.
  • Your serious-incident escalation route, aligned to your safeguarding and cyber procedures.

Guidance it speaks to