Data Breach Response Procedure

    Recruitment Direct UK Limited

    Herkimer House

    Mill Road Industrial Estate

    Linlithgow

    EH49 7SF

    Scotland

    United Kingdom

    Document Owner:Recruitment Direct UK Ltd
    Version:1.0
    Effective Date:7 September 2026
    Review Date:September 2027

    Purpose

    This procedure sets out how RD1 identifies, contains, assesses, and reports a personal data breach affecting candidate, client, or worker data, in line with UK GDPR Articles 33 and 34 and the Data Protection Act 2018.

    What Counts as a Breach

    A personal data breach is any incident leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data — this includes, for example, a misdirected email containing candidate CVs, a lost or stolen device holding candidate data, unauthorised access to RD1's applicant tracking system or CallPilot screening records, or a client or supplier reporting a breach affecting shared data.

    Immediate Response

    On discovering or being told of a suspected breach, the person who discovers it must report it to a Director immediately. RD1 will act to contain the breach as quickly as possible — for example revoking access, recalling an email, or isolating an affected system — and begin an assessment of what data and how many individuals are affected.

    Risk Assessment

    RD1 assesses the likely risk to the rights and freedoms of the individuals affected, considering the type and sensitivity of the data involved, how many people are affected, and whether the data could be misused (for example to enable identity theft or fraud).

    Notifying the ICO

    Where a breach is assessed as likely to result in a risk to individuals, RD1 notifies the Information Commissioner's Office within 72 hours of becoming aware of it, in line with UK GDPR Article 33, using the ICO's breach reporting service. Where a decision cannot be finalised within 72 hours, RD1 reports what is known at that stage and provides further information as it becomes available.

    Notifying Affected Individuals

    Where a breach is assessed as likely to result in a high risk to individuals, RD1 also notifies those individuals directly and without undue delay, explaining what happened, what data was involved, and what steps they can take to protect themselves, in line with UK GDPR Article 34.

    Internal Record

    RD1 keeps a record of every personal data breach, including those not reportable to the ICO, covering the facts, effects, and remedial action taken, as required by UK GDPR accountability obligations.

    Learning From a Breach

    Following any breach, RD1 reviews what allowed it to happen and takes reasonable steps to prevent a recurrence, including updates to this or related policies where appropriate.

    Responsibility

    The Directors act as RD1's data protection lead and are responsible for coordinating the response to any suspected or confirmed breach.

    Director Approval

    I confirm that this Data Breach Response Procedure has been reviewed and approved on behalf of Recruitment Direct UK Limited.

    Name:Steven Peddie
    Position:Director
    Date:7 September 2026
    Signature:
    Steven Peddie Signature__________________________________________

    Compliance, Quality & Security

    Recognised standards supporting consistent, compliant recruitment delivery.

    Constructionline Gold

    Gold Member

    1324569

    Cyber
    Essentials

    Certified

    4686a995

    ISO
    9001:2015

    Quality Management

    GB2006088

    REC
    Membership

    Corporate Member

    00207320

    Verified credentials. Transparent proof. Trusted delivery.