Data protection procedure

Read, keep or print this procedure

Word downloads immediately. PDF and Print open your browser’s print window; choose “Save as PDF” for a PDF copy.

CCI Joy Family Church, Juja · Data Protection

Personal Data Breach Response Procedure

Version 1.0

Effective date: [to be inserted once adopted by the Board] · Owner: Data Protection Officer

1. Purpose

This procedure sets out the steps the church will take when a personal data breach is suspected or confirmed. It ensures we contain the incident quickly, protect members, and meet our legal duty under Section 43 of the Data Protection Act, 2019 to notify the Office of the Data Protection Commissioner (ODPC) and affected persons where required.

2. What is a Personal Data Breach?

A personal data breach is any security incident that leads to the accidental or unlawful:

  • Destruction, loss or alteration of personal data, or
  • Unauthorised disclosure of, or access to, personal data.

Examples include:

  • A laptop or phone containing member lists being lost or stolen
  • An administrator account being accessed by an unauthorised person
  • A shared group link being forwarded to the wrong people
  • Accidental sending of a member list or attendance register to the wrong WhatsApp group or email
  • A system error that exposes children’s data or sensitive pastoral notes

3. Immediate Reporting (First 1 Hour)

Anyone who discovers or suspects a breach must report it immediately — without waiting to confirm the full details.

Report to:

  1. The Data Protection Officer (name and mobile number to be published once appointed)
  2. If the DPO cannot be reached, report to any Overall Administrator or the Church Secretary/CEO

How to report:

  • Phone call first (do not delay)
  • Follow up with a short written note (WhatsApp or email) stating: what happened, when it was discovered, what data may be affected, and what steps (if any) have already been taken

Standing instruction: Report immediately. Do not wait to “investigate first”.

4. Immediate Containment (Within the First Few Hours)

The DPO (or Overall Administrator) will take the following steps at once:

ActionWho can do itNotes
Deactivate any compromised login accountsOverall AdministratorPrevents further access
Force password reset for affected usersOverall Administrator
Rotate or deactivate any shared group access links that may have been exposedOverall AdministratorEspecially important for Sunday School registers
Revoke active sessions across the portalOverall AdministratorAvailable in the system
Preserve evidence (do not delete logs or emails)DPO / AdministratorNeeded for the later assessment

These steps can be completed within minutes using the existing portal tools.

5. Risk Assessment (Within 24–48 Hours)

The DPO will assess whether the breach poses a real risk of harm to the data subjects. Consider:

  • What categories of data were involved (especially children’s data, contact details, pastoral notes, or family relationships)?
  • How many people are affected?
  • How easily could the data be used to cause harm (identity theft, distress, discrimination, etc.)?
  • Has the data already been recovered or made inaccessible?

Record the decision in writing, including the reasons. This record is itself evidence of accountability.

6. Notification to the ODPC (Within 72 Hours)

If the assessment shows there is a real risk of harm, the DPO must notify the Office of the Data Protection Commissioner within 72 hours of becoming aware of the breach.

The notification should include:

  • Nature of the breach
  • Categories and approximate number of data subjects affected
  • Categories of personal data involved
  • Likely consequences
  • Measures already taken or proposed to address the breach
  • Contact details of the Data Protection Officer

Even if the risk is judged low and notification is not required, the decision and reasons must still be recorded in the Breach Register.

7. Notification to Affected Members

Where there is a real risk of harm, the church will also inform the affected data subjects in writing (letter, email or official church communication) without undue delay.

The notice should be in plain language and include:

  • What happened
  • What data was involved
  • What the church is doing about it
  • Advice on steps the member can take (e.g. change passwords, be alert to unusual messages)
  • Contact details of the Data Protection Officer for further questions

8. Breach Register

Every incident — whether notifiable or not — must be recorded in a Breach Register kept by the DPO.

Minimum information to record:

  • Date and time the breach was discovered
  • Description of the incident
  • Categories of data and approximate number of people affected
  • Risk assessment outcome and reasons
  • Whether the ODPC and data subjects were notified (and on what date)
  • Containment and remedial actions taken
  • Lessons learned and any changes made to prevent recurrence

9. Roles and Responsibilities

RoleResponsibility
All staff & ministry leadersReport any suspected breach immediately
Data Protection OfficerReceive reports, lead containment, assess risk, notify ODPC and members, maintain the Breach Register
Overall AdministratorsCarry out technical containment steps in the portal when directed by the DPO
Church BoardEnsure a DPO is appointed, review serious breaches, and support any necessary policy or system changes

10. Review

This procedure will be reviewed at least once a year, or immediately after any material breach, to incorporate lessons learned.

Adoption

Adopted by the Church Board on: ________________________________

Chairperson: ________________________________

Data Protection Officer: ________________________________

CCI Joy Family Church, Juja · Personal Data Breach Response Procedure · Version 1.0