Data Breach Procedure
Last Updated: September 2026
How Evergreen responds to suspected or confirmed personal-data security incidents.
1. Response Stages
- Identify: record and assess the suspected incident.
- Contain: take proportionate steps to stop or limit unauthorised access, disclosure, alteration or loss.
- Investigate: establish what happened, which systems and information were involved, and the likely consequences.
- Risk assess: assess the risk to affected individuals and document the decision-making.
- Notify where required: where required, Evergreen will notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of a personal-data breach. Where a breach is likely to result in a high risk to individuals, Evergreen will inform them without undue delay, subject to applicable legal exceptions.
- Remediate: address the cause, preserve relevant evidence and implement corrective measures.
- Review: record lessons learnt and update controls, policies or training where necessary.
2. Reporting an Incident
Report suspected incidents promptly using the Data Protection Contact page, including documents shared with the wrong professional, unauthorised access, inappropriate uploads of patient information or a compromised account. Do not circulate exposed documents unnecessarily when reporting the incident.