Compliance
Personal Data Breach Procedure
Last reviewed: 28 June 2026
1. Definition
A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored, or otherwise processed (UK GDPR Article 4(12)).
2. Detection sources
- Automated alerts (auth failure spikes, RLS policy errors, AI-gateway anomalies).
- Supabase / Lovable Cloud provider notifications.
- Vulnerability reports to security@classprayer.app.
- School DSL or DPO report to info@classprayer.app.
- Internal engineering observation.
3. Response timeline
| When | Action | Owner |
|---|---|---|
| T+0 (detection) | Triage; open incident record; classify severity. | On-call engineer |
| T+1h | Contain (rotate keys, disable affected feature, isolate accounts). | On-call engineer |
| T+4h | Notify Class Prayer DPO; begin written breach log. | On-call engineer → DPO |
| T+24h | Notify each affected school's nominated contact with what is known so far. | DPO |
| T+72h | ICO notification (Art. 33) where the breach is likely to risk individuals' rights and freedoms. | DPO |
| Without undue delay | Direct notification to data subjects (Art. 34) where high risk. | DPO + school |
| T+30d | Post-incident review and remediation plan. | Engineering + DPO |
4. Notification content
- Nature of the breach, including categories and approximate number of data subjects and records.
- Name and contact details of the DPO and any other contact point.
- Likely consequences of the breach.
- Measures taken or proposed to address it and to mitigate adverse effects.
5. Records
All breaches, including those judged not notifiable, are recorded in the internal breach log together with the facts, effects, and remedial action taken (Article 33(5)). Records are kept for a minimum of 6 years.
Questions? Email info@classprayer.app.