For the data protection lead of a UK or EU company who just heard "I think I sent that file to the wrong person." The notice to the ICO or your EU authority is due 72 hours after you became aware, and the weekend counts.
18 notes, 2 Bases, 1 canvas: 7 rule notes, 4 templates, 6 filled examples, the Start note. Core plugins only — no community plugins. You check your own breach here for free first; the vault is one payment, not a subscription.
00 Start here.mdBreach board.baseBreach board.canvasBreach register.baseBreaches/2026-09-18 Payroll file sent to wrong client.mdBreaches/2026-09-22 Lost laptop with CRM export.mdBreaches/2026-09-23 Encrypted USB stick lost.mdBreaches/2026-09-24 Mailing vendor ransomware.mdNotices/2026-09-18 Message to affected staff - payroll file.mdNotices/2026-09-22 ICO notice - lost laptop.mdRules/Article 33 - the 72-hour clock.mdRules/Article 33(3) - what the notice must contain.mdRules/Article 33(5) - the breach register.mdRules/Article 34 - telling the people affected.mdRules/Other clocks - NIS2 and telecoms.mdRules/Risk triage - none, risk, high.mdRules/Which authority - UK and EU.mdTemplates/Authority notice draft.mdTemplates/Breach card.mdTemplates/Message to affected people.mdTemplates/Post-incident review.md# Start here - GDPR breach board This vault is a kanban board for personal-data breaches under GDPR (EU) and UK GDPR. Every incident becomes one card. The card moves through five columns until it is closed, and every card stays in the breach register that Article 33(5) asks you to keep. ## The five columns 1. **1 Detected** - someone reported something. Write down the minute you became aware. 2. **2 Assessing** - decide the risk: none, risk, or high risk. See [[Risk triage - none, risk, high]]. 3. **3 Notify authority** - risk or high risk: the notice to the ICO or your EU authority is due 72 hours after you became aware. See [[Article 33 - the 72-hour clock]]. 4. **4 Tell people** - high risk: tell the people affected without undue delay. See [[Article 34 - telling the people affected]]. 5. **5 Closed** - lessons written, register row complete. The column is the `stage` property on each card. Change it and the card jumps to the next column in **Breach board.base**. The canvas **Breach board.canvas** is a wall view of the same cards: drag a card there, then set `stage` to match. ## Your first 5 minutes 1. Open **Breach board.base** and click through the views: 1 Detected, 2 Assessing, 3 Notify authority, 4 Tell people, 5 Closed, Clock. 2. Open the filled example [[2026-09-22 Lost laptop with CRM export]]. It is in column 3 with its notice due on Fri 25 Sep 2026 at 09:15. 3. New incident: create a note in `Breaches/`, then run **Insert template** and pick **Breach card**. Fill `aware` first. 4. Read [[Which authority - UK and EU]] once, and write your authority on the card. ## What is in here - 7 rule notes: [[Article 33 - the 72-hour clock]] · [[Article 33(3) - what the notice must contain]] · [[Article 34 - telling the people affected]] · [[Article 33(5) - the breach register]] · [[Which authority - UK and EU]] · [[Other clocks - NIS2 and telecoms]] · [[Risk triage - none, risk, high]] - 4 templates in `Templates/`: Breach card · Authority notice draft · Message to affected people · Post-incident review - 2 Bases: **Breach board.base** (the kanban) and **Breach register.base** (the Article 33(5) register) - 1 canvas: **Breach board.canvas** - 6 filled examples: [[2026-09-18 Payroll file sent to wrong client]] · [[2026-09-22 Lost laptop with CRM export]] · [[2026-09-23 Encrypted USB stick lost]] · [[2026-09-24 Mailing vendor ransomware]] · [[2026-09-22 ICO notice - lost laptop]] · [[2026-09-18 Message to affected staff - payroll file]] ## Install 1. Unzip the file. 2. In Obsidian choose **Open folder as vault** and pick the unzipped folder. (Menu names can differ slightly by Obsidian version and UI language.) 3. To add it to an existing vault instead, copy the whole folder into that vault. No community plugins are needed. It uses only core plugins: Templates, Bases and Canvas. Bases needs Obsidian 1.9 or newer. This vault is a working tool, not legal advice. Check the current guidance of your own authority before you file.
A working tool, not legal advice. Check your authority's current guidance before you file.