Responding to Data Breaches: Root Cause Analyses

The first instalment of our series defined what a data breach is and outlined how to report one, should it occur (if you need a refresh, we advise you go back to our first blog post, it’s an enthralling combination of compelling puns and data protection regulations, if we do say so ourselves!). 

Now that you’re all caught up, you may remember that only high-risk data breaches are required to be reported to the ICO or data subjects themselves. Often, an internal root cause analysis will be sufficient. 

So, how is it done? 

Step 1 Establish which data has been compromised, and the  potential impacts data subjects might face as a result.

It’s important to be thorough in this assessment – considering all reasonably-foreseeable possibilities at the point of the breach but also in the future.  

Personal data 

Personal data is any information which relates to an identified/identifiable natural person.  Examples include phone numbers, credit card details, personnel numbers, account data, number plates, appearance, addresses etc..

Special category data 

Special category data alludes to any personal data, sensitive enough that it requires additional protection. This data may reveal an individual’s: race, political persuasion, sexual orientation, religious or philosophical beliefs, existence of trade union membership, genetic data or biometric data (that’s body measurements to you and me!). 

A breach of special category data increases the risk of a data breach as the utilisation and exploitation of this data could wreak significant hassle on the data subject’s fundamental rights and freedoms. 

Criminal allegations 

Whilst personal data relating to criminal allegations, proceedings or convictions are not specifically listed as special category data, there are existing protocols and safeguards in place for processing this data which address the particular risks a data breach of this nature would incur. 

Step 2 – Consider proportion 

Size, in this case, does matter. A company with 50 employees and a company with 50,000 employees will be disproportionately affected by a data breach of 30 employees – the former case would be considered a high risk data breach, whereas the latter could be low risk, subject to the specific circumstances of the breach. 

Identifying the risk score of the data breach is vital as it allows us to act proportionally and swiftly when an issue arises. 

Step 3 –  Conducting a root cause analysis 

Conducting a root cause analysis refers, funnily enough, to the process of tracing a data breach back to its roots, in order to identify the appropriate resolution. This process also allows for identification of some of the common causes of data breaches and trends within your own organisation. In this sense it serves a preventative function, minimising the risk of future breaches, 

Before we move any further, ask yourself the following question: does my organisation have an established system in place to report and investigate data breaches? 

If not, you must create a data breach report template which is both understood and accessible to your whole team. If you require any assistance in the creation of such a report, incidentally, you might want to contact us. Drop us a message at info@dataprivacyadvisory.com. We can help.

The next steps are as follows: 

    • Define issue (as previously mentioned) 
    • Collect data relating to the problem – A comprehensive (and therefore successful) analysis will include a discussion with the individual(s) who caused or were otherwise involved in the the data breach occurring, as well as the individual(s) who identified it. 
    • Identify causes of the issue – Some helpful questions to ask are; Is this a recurring issue? How recently/frequently has this occurred? Can we pinpoint what led to this breach i.e. human error (high workload, time pressure, insufficient training), systematic error, social engineering etc… 
    • Prioritise the causes – Categorise each cause, without attempting to solve them (yet). The recommended categories are people, process, technology, environmental, financial… the list goes on. While prioritising, consider the impact that each cause had on the data breach. 
  • Identify solutions and implement sustained change – This is the stage where we consider mitigating actions which will reduce the possibility of a similar data breach occurring in the future. Some helpful questions to ask here are; Who will be responsible for implementing mitigating actions? What will the time frame for implementation be? Who will monitor the implementation of remedial actions? How can we make sure our process for identifying data breaches is not merely reactive, but preemptive? How can we adopt a culture of preventing data breaches in our organisation? 

If you require additional support with a data breach you can contact us at info@dataprivacyadvisory.com or by calling our office at 0203 301 3384. Alternatively, consider enrolling in our course: Data Breach Root Cause Analysis.

You can see a case study of a previous root cause analysis with one of our clients here to read about how we helped them.

related posts

Alex Haslam

DPAS Data Protection Bulletin – July 2026

Welcome back to our monthly DPAS bulletin, where we cover the latest data protection news and developments from around the world.

Ever wondered how a routine government spreadsheet leak turns into a two-year covert court order? How about why the police might feel your mother-in-law’s contact details were key to national security? Have you ever pondered how many working weeks it takes to read a cookie banner? Whether Wall Street knows about your last GP visit? Or if you’re in Australia (g’day) why an AI is sending notes on your worst rashes to faraway cloud servers?

Read about all this and more in our latest DPAS Data Protection Bulletin.

Read More »
Alex Haslam

Root Cause Analysis: A Practical Guide

A practical guide to data breach reporting under UK GDPR, covering when you must notify the ICO, how to report a breach (and what to do if you don’t need to), and when affected individuals need to be told. Includes the key steps, timeframes, and documentation requirements to keep your organisation compliant.

Read More »
Alex Haslam

How to Report a Data Breach: A Practical Guide

A practical guide to data breach reporting under UK GDPR, covering when you must notify the ICO, how to report a breach (and what to do if you don’t need to), and when affected individuals need to be told. Includes the key steps, timeframes, and documentation requirements to keep your organisation compliant.

Read More »
Jack Penaligon

How to Respond to a Data Breach: A Practical Guide

This blog provides an overview of the practical steps organisations can take to reduce the impact of a data breach once it has been identified. It focuses on the actions that should be taken during the early stages of an incident to contain the breach, protect affected individuals, and meet regulatory requirements.

The article discusses a range of mitigation measures, including contacting unintended recipients of personal data, securing the deletion or recovery of exposed information, isolating compromised systems, and maintaining clear records of actions taken. It also explores the challenges posed by both digital and physical data breaches, highlighting the importance of balancing operational needs with data protection obligations.

Finally, the blog emphasises the value of preparation, explaining how established procedures, communication templates, and predefined response plans can help organisations respond more effectively and demonstrate accountability during a regulatory investigation.

Read More »

Get a Free Consultation