Data Breach Response Procedure
Recruitment Direct UK Limited
Herkimer House
Mill Road Industrial Estate
Linlithgow
EH49 7SF
Scotland
United Kingdom
Purpose
This procedure sets out how RD1 identifies, contains, assesses, and reports a personal data breach affecting candidate, client, or worker data, in line with UK GDPR Articles 33 and 34 and the Data Protection Act 2018.
What Counts as a Breach
A personal data breach is any incident leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data — this includes, for example, a misdirected email containing candidate CVs, a lost or stolen device holding candidate data, unauthorised access to RD1's applicant tracking system or CallPilot screening records, or a client or supplier reporting a breach affecting shared data.
Immediate Response
On discovering or being told of a suspected breach, the person who discovers it must report it to a Director immediately. RD1 will act to contain the breach as quickly as possible — for example revoking access, recalling an email, or isolating an affected system — and begin an assessment of what data and how many individuals are affected.
Risk Assessment
RD1 assesses the likely risk to the rights and freedoms of the individuals affected, considering the type and sensitivity of the data involved, how many people are affected, and whether the data could be misused (for example to enable identity theft or fraud).
Notifying the ICO
Where a breach is assessed as likely to result in a risk to individuals, RD1 notifies the Information Commissioner's Office within 72 hours of becoming aware of it, in line with UK GDPR Article 33, using the ICO's breach reporting service. Where a decision cannot be finalised within 72 hours, RD1 reports what is known at that stage and provides further information as it becomes available.
Notifying Affected Individuals
Where a breach is assessed as likely to result in a high risk to individuals, RD1 also notifies those individuals directly and without undue delay, explaining what happened, what data was involved, and what steps they can take to protect themselves, in line with UK GDPR Article 34.
Internal Record
RD1 keeps a record of every personal data breach, including those not reportable to the ICO, covering the facts, effects, and remedial action taken, as required by UK GDPR accountability obligations.
Learning From a Breach
Following any breach, RD1 reviews what allowed it to happen and takes reasonable steps to prevent a recurrence, including updates to this or related policies where appropriate.
Responsibility
The Directors act as RD1's data protection lead and are responsible for coordinating the response to any suspected or confirmed breach.
Director Approval
I confirm that this Data Breach Response Procedure has been reviewed and approved on behalf of Recruitment Direct UK Limited.
__________________________________________


