Governance & Legal Centre

Personal Data Breach Response Procedure

Last Reviewed: 7 July 2026Version: 1.04 min read

Document Information

Document
Personal Data Breach Response Procedure
Document ID
CLB-BREACH-001
Category
Security
Version
1.0
Status
Approved
Effective Date
7 July 2026
Last Reviewed
7 July 2026
Next Review
7 July 2027
Review Cycle
Annual
Owner
Cluboom

Clubs trust Cluboom with information about their coaches, volunteers, parents and children. This procedure sets out how a suspected personal data breach is identified, contained, assessed and resolved, and how clubs and individuals are kept informed where UK GDPR requires it. It should be read alongside the Security Policy and the Privacy Policy, and is not legal advice.

1. Purpose

Cluboom maintains a structured process for identifying, managing and responding to suspected personal data breaches. Having a defined process matters because the pressure of an incident is the worst possible moment to decide what to do.

The objective is to minimise risk, protect the individuals whose information is involved — very often children and their families — and support compliance with the UK GDPR and the Data Protection Act 2018.

2. Scope

This procedure applies to all personal data processed through Cluboom, regardless of where the incident originates or which part of the platform is involved. That includes information relating to:

  • clubs;
  • club administrators;
  • team administrators;
  • coaches;
  • parents and guardians;
  • players, including children and young people;
  • volunteers and committee members;
  • visitors and users of the Cluboom website.

It covers incidents affecting the Cluboom platform itself and incidents reported to Cluboom that involve a club’s use of the platform.

3. What is a personal data breach?

A personal data breach is a security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. It is not limited to deliberate attacks — most incidents in grassroots sport are ordinary mistakes made by busy people.

A breach may involve:

  • unauthorised access — someone reaching information they are not entitled to see, for example through a shared or compromised account;
  • accidental disclosure — sending a message, document or contact detail to the wrong recipient;
  • loss of personal data — data becoming unavailable or irretrievable;
  • alteration of personal data — records changed without authority, so they can no longer be relied upon;
  • destruction of personal data — records deleted outside the normal, authorised process;
  • unauthorised availability of information — data being exposed more widely than intended, including to other clubs or families.

A suspected breach is treated seriously from the outset. Whether it is ultimately confirmed as a personal data breach is a conclusion reached at the assessment stage, not an assumption made at the start.

4. Incident response process

Every suspected breach follows the same six-stage lifecycle: Identify → Contain → Assess → Notify → Recover → Review. The stages run in order, though containment and assessment often overlap where an incident is still developing.

  1. Stage 1 of 6

    Identify

    A suspected breach is recognised and captured accurately before anything is changed.

    • Recognise a suspected breach, however it is reported.
    • Record the initial information: what was seen, when, and by whom.
    • Preserve evidence such as logs, messages and screenshots.
    • Escalate internally where appropriate so the right people are involved quickly.
  2. Stage 2 of 6

    Contain

    Exposure is stopped before the incident is investigated in depth.

    • Prevent further exposure of the personal data involved.
    • Secure affected systems, accounts and integrations.
    • Restrict access where necessary, including suspending accounts or sessions.
    • Protect affected data so it cannot be altered or lost while work continues.
  3. Stage 3 of 6

    Assess

    The facts are established so that any obligations can be judged on evidence, not assumption.

    • What happened, and how the incident occurred.
    • What data is involved, including whether it relates to children.
    • How many individuals are affected, and which clubs.
    • The potential impact on those individuals.
    • The likelihood of harm arising.
    • Whether the incident meets the UK GDPR definition of a personal data breach.
  4. Stage 4 of 6

    Notify

    Notification is proportionate to the assessed risk and to what UK GDPR actually requires.

    • Relevant clubs are informed where their members’ data is affected.
    • Appropriate regulatory notification is considered against the statutory threshold.
    • Individuals may be informed where there is a high risk to their rights and freedoms.
    • Communications are factual, timely and free of speculation.
  5. Stage 5 of 6

    Recover

    Normal, verified service is restored rather than simply resumed.

    • Restore affected services where appropriate.
    • Verify the integrity of systems and data.
    • Confirm that security measures are functioning correctly.
    • Continue monitoring for related or repeat activity.
  6. Stage 6 of 6

    Review

    Every confirmed breach is treated as something to learn from, not just close.

    • Root cause analysis of how the incident became possible.
    • Lessons learned, recorded honestly.
    • Improvements to procedures and internal escalation.
    • Security enhancements where appropriate.
    • Updates to documentation where the published position has changed.

5. Roles and responsibilities

Responding well to an incident depends on each party doing the part only they can do.

Cluboom operates the platform and leads the response to incidents affecting it. Cluboom is responsible for maintaining this procedure, triaging reports, containing platform-level incidents, assessing risk, informing affected clubs, considering regulatory notification, restoring service and carrying out the post-incident review. Where Cluboom acts as a processor for a club, it supports that club’s own obligations as controller in line with the Data Processing Agreement.

Clubs remain the data controller for their members’ information. Clubs are responsible for managing who holds administrator, coach, team administrator and parent access, removing access promptly when people leave a role, reporting suspected incidents to Cluboom without delay, and making their own controller decisions on notifying individuals or the regulator where the incident arises from their use of the platform.

Authorised users — coaches, volunteers, team administrators and parents — are responsible for keeping their credentials and player PINs secure, signing out of shared devices, using club information only for legitimate club activity, and reporting anything that looks wrong rather than waiting to be certain.

6. Reporting a suspected breach

Suspected security or privacy incidents should be reported to support@cluboom.co.uk as soon as they are noticed.

Please report promptly. Early reports are far more useful than complete ones — the statutory timescales for assessing and notifying a breach are short, and containment is most effective in the first hours. You do not need to be sure that a breach has occurred, and no one is penalised for raising a concern that turns out to be nothing.

Where possible, include what happened, when it was noticed, which club and team are involved, and what information may have been exposed. Do not attach copies of the exposed personal data itself.

Cluboom support is not an emergency or safeguarding-reporting service. If a child or vulnerable adult is at immediate risk, contact the emergency services on 999 and your club’s safeguarding officer.

7. Record keeping

Cluboom maintains appropriate records of security incidents and the actions taken in response, as required by UK GDPR and expected by good security practice. Records are kept for confirmed breaches and for incidents assessed as not meeting the threshold, together with the reasoning behind that decision.

Incident records typically capture the facts of what happened, the categories and approximate volume of data involved, the assessment of risk, any notifications made, the remedial action taken and the outcome of the review. These records are retained in line with the Data Retention Policy and are available to affected clubs and to the regulator where appropriate.

9. Policy review

This procedure is reviewed periodically and following:

  • security incidents, whether or not a breach was confirmed;
  • changes to legislation or regulatory guidance;
  • platform improvements that change how data is stored or accessed;
  • operational reviews and internal testing of the response process.

The version, effective date and review date shown above always reflect the current published position.

10. Feedback

Questions regarding this procedure can be sent to support@cluboom.co.uk.

Cluboom welcomes responsible feedback that helps improve our governance, security and compliance documentation.

Cluboom maintains a single governance register. Every document in the register is published and publicly available. Browse the full library in the Governance Centre.

Questions about this document? Contact us at support@cluboom.co.uk.

Cluboom is a trading name and product of D & D Home Maintenance Solutions Ltd (company number 14929079), 24 Brynaeron, Dunvant, Swansea, United Kingdom, SA2 7UX.

  • Built in the UK
  • Designed with privacy in mind
  • Secure cloud infrastructure
  • Designed for grassroots sport