Compliance

Personal Data Breach Procedure

Last reviewed: 28 June 2026

All compliance documents

1. Definition

A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored, or otherwise processed (UK GDPR Article 4(12)).

2. Detection sources

  • Automated alerts (auth failure spikes, RLS policy errors, AI-gateway anomalies).
  • Supabase / Lovable Cloud provider notifications.
  • Vulnerability reports to security@classprayer.app.
  • School DSL or DPO report to info@classprayer.app.
  • Internal engineering observation.

3. Response timeline

WhenActionOwner
T+0 (detection)Triage; open incident record; classify severity.On-call engineer
T+1hContain (rotate keys, disable affected feature, isolate accounts).On-call engineer
T+4hNotify Class Prayer DPO; begin written breach log.On-call engineer → DPO
T+24hNotify each affected school's nominated contact with what is known so far.DPO
T+72hICO notification (Art. 33) where the breach is likely to risk individuals' rights and freedoms.DPO
Without undue delayDirect notification to data subjects (Art. 34) where high risk.DPO + school
T+30dPost-incident review and remediation plan.Engineering + DPO

4. Notification content

  • Nature of the breach, including categories and approximate number of data subjects and records.
  • Name and contact details of the DPO and any other contact point.
  • Likely consequences of the breach.
  • Measures taken or proposed to address it and to mitigate adverse effects.

5. Records

All breaches, including those judged not notifiable, are recorded in the internal breach log together with the facts, effects, and remedial action taken (Article 33(5)). Records are kept for a minimum of 6 years.

Questions? Email info@classprayer.app.