AIAH Health Limited · Company No. 17322326
How AIAH.Health identifies, contains, investigates and reports personal data breaches under UK GDPR.
Last updated: 7 July 2026
This Plan defines the actions AIAH Health Limited takes when a personal data breach is suspected or confirmed. It ensures we meet the 72-hour notification obligation to the Information Commissioner's Office (ICO) under Article 33 UK GDPR and, where required, notify affected individuals under Article 34.
A 'personal data breach' is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
Any suspected incident must be reported immediately to the Security Incident Lead at [security@aiah.health]. The Incident Lead convenes the response team (Engineering, DPO, Legal, Communications) and starts an incident log.
The DPO assesses the likelihood and severity of risk to individuals' rights and freedoms, considering: type and volume of data affected; identifiability; ease of exploitation; special category data involvement; and potential consequences (financial, reputational, safeguarding, physical).
If the breach is likely to result in a risk to individuals, the DPO notifies the ICO without undue delay and, where feasible, within 72 hours of becoming aware. Notification includes: nature of the breach, categories and approximate number of individuals and records, contact for the DPO, likely consequences, and measures taken or proposed. Where information is not immediately available it is provided in phases.
Where the breach is likely to result in a high risk to individuals, we notify affected people without undue delay in clear and plain language, describing what happened, likely consequences, measures taken and steps they can take to protect themselves. Where direct notification is disproportionate we make a public communication or equivalent measure.
Every incident (whether or not notifiable) is recorded in the personal data breach register with: facts, effects, remedial action, decisions taken and rationale. Records are retained for 6 years.
Engineering leads a technical investigation to establish root cause. The DPO documents findings and required remediation. Where a third-party processor is involved, we require them to co-operate and provide evidence.
A post-incident review is completed within 30 days of closure and its actions tracked to completion. Lessons feed into policy, controls and training updates.
We test this plan through a tabletop exercise at least annually and after any material change in systems or team.