Data breach policy.
Scope and definitions.
This policy applies to any personal data breach involving information held by ORBIT-RRI Ltd. Under UK GDPR a personal data breach is "a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data". That covers confidentiality breaches (data seen by someone who should not have seen it), integrity breaches (data altered or corrupted), and availability breaches (data lost or unreachable).
This is not just hostile actors. A laptop left on a train, an email sent to the wrong distribution list, or a backup that cannot be restored all count.
How we detect.
We rely on three channels:
- Automatic monitoring from our hosting provider, mail provider, and document store, with alerts piped to our shared inbox.
- Internal reporting by anyone working with us. Every member of the team and every contracted associate is briefed at onboarding to report any suspected breach to the policy owner within 24 hours of becoming aware of it, even when they are not sure whether it really counts.
- External reporting from data subjects, clients, or third-party researchers, via the channels listed below.
Triage and severity.
Within 24 hours of detection, the policy owner classifies the incident along two axes:
- Likelihood of risk to data subjects (none, possible, likely, certain).
- Severity of impact (negligible, limited, significant, severe).
An incident scoring "possible" or above on either axis is treated as a notifiable breach for triage purposes and follows the timeline below.
Detect
Incident reported to policy owner via any of the three channels.
Triage
Classification recorded. Containment actions begin.
Notify ICO
If risk to data subjects is "possible" or above, the ICO is notified.
Review
Post-incident review held. Lessons recorded and applied.
Containment.
Immediate containment actions vary by incident type and may include: revoking access tokens, rotating credentials, removing exposed data from caches and indices we control, requesting takedown from third parties, recalling messages where the provider permits, restoring from a clean backup, or isolating compromised devices.
The principle is to stop the breach growing before perfecting the diagnosis. We document the actions taken with timestamps so the post-incident review can see what worked.
Notification.
Where the breach is likely to result in a risk to the rights and freedoms of natural persons, we notify the Information Commissioner's Office within 72 hours of becoming aware of it, in line with Article 33 UK GDPR. Where the risk to data subjects is high, we notify the affected people "without undue delay" as needed by Article 34, in plain language, explaining what happened, what is at risk, what we have done, and what they can do.
For breaches affecting data we process on behalf of a client (as a processor), we notify the client without undue delay so they can decide on onward notifications.
Records.
Every reported incident is recorded in our breach log regardless of whether it meets the notification threshold, with: detection channel and timestamp, summary of facts, data categories affected, approximate number of data subjects affected, containment actions and timestamps, classification, notification decisions and dates, and post-incident review notes. The log is retained for at least six years.
Post-incident review.
Within 14 days of containment, the policy owner runs a short post-incident review covering: how the breach happened, whether the response worked, what could have stopped or detected it earlier, and what we will change. Changes are tracked through to completion and revisited at the next annual policy review.
Report a breach.
If you believe you have evidence of a personal data breach involving ORBIT, please tell us as soon as you can:
- Email security@orbit-rri.org with as much detail as you can share safely.
- If the matter is urgent and you cannot reach us by email, you may also write to the registered office at De Montfort University, Leicester, LE1 9BH.
- Responsible disclosure of security issues is welcomed; we do not pursue legal action against good-faith researchers who report problems privately and give us reasonable time to fix them.