Legal

What to Do If Your Business Faces a Data Breach (Legal Checklist)

A first-response legal and operational checklist for containing a breach, preserving evidence, involving counsel, assessing notification duties and communicating accurately.

✓ Practical checklist✓ Primary sources where available✓ No signup✓ Clear limitations
Decision framework

What this guide helps you evaluate

Businesses responding to suspected unauthorized access, disclosure or loss of personal or confidential data.

This page is designed to help you compare the moving parts, organize due diligence and ask better questions before you commit money, sign a contract or change an operating process.

What to compare first

  • Immediate containment without destroying evidence
  • Forensic scope, affected systems and data types
  • Legal privilege and specialist counsel
  • Notification duties by jurisdiction and contract
  • Accurate communications to affected parties, partners and regulators

Step-by-step process

  1. 01

    Activate the incident-response team and preserve a decision log.

  2. 02

    Contain affected systems in coordination with forensic specialists.

  3. 03

    Identify what data was affected, whose data it was and where those people are located.

  4. 04

    Have counsel assess regulatory, contractual and law-enforcement notifications.

  5. 05

    Remediate root cause, document actions and review communications for accuracy.

Common mistakes and risk checks

  • Wiping or powering down systems before evidence is preserved when experts advise otherwise.
  • Sending a premature notification with incorrect facts.
  • Assuming one notification rule applies to every affected person.

Primary and official references

Rules, pricing and requirements can change. Use these sources to verify the latest details that apply to your situation.