Breach Management
by Formiti's Global DPO Team
An end-to-end breach lifecycle module covering incident logging, risk assessment, DPA notification tracking, and post-incident remediation — now with embedded Breach Guidance that uses AI-assisted review to help teams assess breach facts faster, highlight missing information, surface notification considerations, and draft internal assessment wording. AI-generated guidance with human review. Your data is used only to generate this review and is not used to train AI models.
Who uses this module?
DPOs, Incident Response Teams, Legal Counsel, Senior Management.
What governance problem does it solve?
The 72-hour GDPR notification window demands rapid, structured response. Breach Management replaces email chains and spreadsheets with a governed workflow that ensures nothing is missed and every action is documented.
What are the key workflows?
- Log incidents with structured classification (confidentiality, integrity, availability)
- Assess severity, affected individuals, and data categories
- Determine DPA reportability with documented rationale
- Track notification to DPA and affected individuals with timestamps
- Document remediation actions and lessons learned
- DPO review and formal breach closure
- Breach Guidance — AI-assisted review highlights missing facts, notification considerations, and suggested remediation steps
Log incidents with structured classification (confidentiality, integrity, availability)
Assess severity, affected individuals, and data categories
Determine DPA reportability with documented rationale
Track notification to DPA and affected individuals with timestamps
Document remediation actions and lessons learned
DPO review and formal breach closure
Breach Guidance — AI-assisted review highlights missing facts, notification considerations, and suggested remediation steps
What evidence and reporting does it produce?
Built-in outputs for accountability and regulatory readiness
Breach register with full incident timeline
DPA notification records with proof of submission
Severity distribution analytics
Remediation action tracking and closure evidence
Post-incident review documentation
How does it connect to other Privacy360 modules?
- Links to ROPA entities to identify affected processing activities
- May trigger DSARs from affected individuals
- Remediation actions can generate Assessment follow-ups
- Feeds into Privacy Training needs analysis
What are some example use cases?
An employee reports a misdirected email containing personal data; the DPO logs the incident, assesses it as non-reportable, documents the rationale, and closes the record within 24 hours.
A significant breach affecting 5,000 data subjects triggers DPA notification; the platform tracks the 72-hour deadline, records the submission, and manages individual notifications.
Post-breach review identifies a training gap; the DPO links the finding to a targeted Privacy Training campaign.
Related modules
ROPA Records
Maintain records of processing activities with clear ownership, data mapping, review controls and AI Processor disclosure — and let the record automatically open and pre-fill the DPIA, LIA, transfer and AI assessments it triggers.
DSAR Requests
Manage data subject requests with workflow tracking, ownership, deadlines and response evidence.
Privacy & AI Training LMS
A full SCORM-compliant LMS built into Privacy360 — fresh 2026 privacy, security and AI courses out of the box, new content every week, and unlimited custom SCORM uploads at no extra per-user cost.
Privacy Assessments
Run global privacy gap assessments, DPIAs, LIAs, transfer reviews and vendor assessments against 150+ controls — with structured rationale, evidence and AI-assisted review.
Breach Management guides
Practical articles from Formiti's Global DPO team on running this work well.