GDPR & Data
Breach Notification Process
Internal process for detecting, assessing, containing, and notifying personal data breaches affecting InstaSurv.
Last updated: 21 August 2026
1. What is a breach
A personal data breach is a security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
2. Detection & containment
Incidents may be identified via monitoring, staff reports, customer reports, or provider notices. We prioritise containment, evidence preservation, and impact assessment.
3. Notifying practices (Customer Data)
Where a breach affects Customer Data we process as processor, we will notify the affected practice without undue delay after becoming aware, with available details on nature, approximate affected data, likely consequences, and measures taken or proposed.
4. Regulatory notification
Where we are the controller and a breach is likely to result in a risk to individuals’ rights and freedoms, we will notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware, and inform affected individuals when required by law.
5. Reporting an incident
If you suspect a security or data incident involving InstaSurv, email support@instasurv.co.uk immediately with “Security incident” in the subject line. Do not include unnecessary sensitive content in the initial email.
Website: https://instasurv.co.uk.
See all documents in GDPR & Data, or our Privacy Policy.