CCI Joy Family Church, Juja · Data Protection
Personal Data Breach Response Procedure
Version 1.0
Effective date: [to be inserted once adopted by the Board] · Owner: Data Protection Officer
Personal Data Breach Response Procedure
Version 1.0 · Effective date: [to be inserted once adopted by the Board] · Owner: Data Protection Officer
1. Purpose
This procedure sets out the steps the church will take when a personal data breach is suspected or confirmed. It ensures we contain the incident quickly, protect members, and meet our legal duty under Section 43 of the Data Protection Act, 2019 to notify the Office of the Data Protection Commissioner (ODPC) and affected persons where required.
2. What is a Personal Data Breach?
A personal data breach is any security incident that leads to the accidental or unlawful:
- Destruction, loss or alteration of personal data, or
- Unauthorised disclosure of, or access to, personal data.
Examples include:
- A laptop or phone containing member lists being lost or stolen
- An administrator account being accessed by an unauthorised person
- A shared group link being forwarded to the wrong people
- Accidental sending of a member list or attendance register to the wrong WhatsApp group or email
- A system error that exposes children’s data or sensitive pastoral notes
3. Immediate Reporting (First 1 Hour)
Anyone who discovers or suspects a breach must report it immediately — without waiting to confirm the full details.
Report to:
- The Data Protection Officer (name and mobile number to be published once appointed)
- If the DPO cannot be reached, report to any Overall Administrator or the Church Secretary/CEO
How to report:
- Phone call first (do not delay)
- Follow up with a short written note (WhatsApp or email) stating: what happened, when it was discovered, what data may be affected, and what steps (if any) have already been taken
Standing instruction: Report immediately. Do not wait to “investigate first”.
4. Immediate Containment (Within the First Few Hours)
The DPO (or Overall Administrator) will take the following steps at once:
| Action | Who can do it | Notes |
|---|---|---|
| Deactivate any compromised login accounts | Overall Administrator | Prevents further access |
| Force password reset for affected users | Overall Administrator | — |
| Rotate or deactivate any shared group access links that may have been exposed | Overall Administrator | Especially important for Sunday School registers |
| Revoke active sessions across the portal | Overall Administrator | Available in the system |
| Preserve evidence (do not delete logs or emails) | DPO / Administrator | Needed for the later assessment |
These steps can be completed within minutes using the existing portal tools.
5. Risk Assessment (Within 24–48 Hours)
The DPO will assess whether the breach poses a real risk of harm to the data subjects. Consider:
- What categories of data were involved (especially children’s data, contact details, pastoral notes, or family relationships)?
- How many people are affected?
- How easily could the data be used to cause harm (identity theft, distress, discrimination, etc.)?
- Has the data already been recovered or made inaccessible?
Record the decision in writing, including the reasons. This record is itself evidence of accountability.
6. Notification to the ODPC (Within 72 Hours)
If the assessment shows there is a real risk of harm, the DPO must notify the Office of the Data Protection Commissioner within 72 hours of becoming aware of the breach.
The notification should include:
- Nature of the breach
- Categories and approximate number of data subjects affected
- Categories of personal data involved
- Likely consequences
- Measures already taken or proposed to address the breach
- Contact details of the Data Protection Officer
Even if the risk is judged low and notification is not required, the decision and reasons must still be recorded in the Breach Register.
7. Notification to Affected Members
Where there is a real risk of harm, the church will also inform the affected data subjects in writing (letter, email or official church communication) without undue delay.
The notice should be in plain language and include:
- What happened
- What data was involved
- What the church is doing about it
- Advice on steps the member can take (e.g. change passwords, be alert to unusual messages)
- Contact details of the Data Protection Officer for further questions
8. Breach Register
Every incident — whether notifiable or not — must be recorded in a Breach Register kept by the DPO.
Minimum information to record:
- Date and time the breach was discovered
- Description of the incident
- Categories of data and approximate number of people affected
- Risk assessment outcome and reasons
- Whether the ODPC and data subjects were notified (and on what date)
- Containment and remedial actions taken
- Lessons learned and any changes made to prevent recurrence
9. Roles and Responsibilities
| Role | Responsibility |
|---|---|
| All staff & ministry leaders | Report any suspected breach immediately |
| Data Protection Officer | Receive reports, lead containment, assess risk, notify ODPC and members, maintain the Breach Register |
| Overall Administrators | Carry out technical containment steps in the portal when directed by the DPO |
| Church Board | Ensure a DPO is appointed, review serious breaches, and support any necessary policy or system changes |
10. Review
This procedure will be reviewed at least once a year, or immediately after any material breach, to incorporate lessons learned.
Adoption
Adopted by the Church Board on: ________________________________
Chairperson: ________________________________
Data Protection Officer: ________________________________