Add-on service

ICO-ready breach response pack

Under UK GDPR you have 72 hours from becoming aware of a personal data breach to notify the ICO where it is reportable. AI tools create a new class of incident — data pasted into a public model, an inaccurate AI decision about a person, a vendor disclosing a model-side breach — and most small businesses have no plan for any of them.

£249one-off, or included with Compliance Concierge

Best for: Businesses using AI tools that touch personal data, especially where staff use them without central oversight.

What's included

  • Written AI incident response plan, mapped to UK GDPR Articles 33 and 34
  • Severity triage matrix covering AI-specific incident types
  • Pre-drafted ICO notification template with the required Article 33(3) content
  • Data subject notification letter templates for high-risk breaches
  • Breach register template that satisfies the Article 33(5) record-keeping duty
  • Decision tree for deciding whether an incident is reportable, and to whom
  • A one-hour walkthrough with your named incident owner

Why AI breaks the standard breach playbook

Most incident plans assume a lost laptop or a mis-sent email. AI incidents are different: an employee pastes a client list into a consumer chatbot, a transcription tool retains a recording it should have deleted, a recruitment screening model rejects candidates on a protected characteristic, or a vendor discloses that prompts were exposed. Each has a different reporting path, and the clock starts when the business becomes aware — not when someone gets round to escalating it.

What the pack contains

The pack is a working set of documents, not a policy PDF. You get the plan, the triage matrix, the templates and a filled example so your team can see what good looks like.

  • Roles and escalation: who assesses, who decides, who signs off notification
  • The 72-hour timeline broken into hour-by-hour actions
  • Containment steps specific to AI tools — revoking access, requesting vendor deletion, disabling training on inputs
  • Notification thresholds for the ICO, affected individuals and your own clients
  • Evidence and record-keeping so the decision not to report is defensible

Where it sits alongside your register

Your Trestano register already lists which tools handle personal data and how they are classified. The response pack uses that as its starting point, so when an incident involves a specific tool your team can see the data types, the vendor, the processing basis and the contact route without reconstructing it under pressure.

Beyond the ICO

Where the incident involves an AI system in scope of the EU AI Act, serious incident reporting obligations may also apply, and sector regulators such as the FCA or the SRA have their own expectations. The pack flags which of these apply to your business so you are not discovering a second deadline halfway through the first.

Common questions

Is this legal advice?

No. It is a prepared operational workflow and a set of templates based on published ICO guidance. If an incident is serious you should still take legal advice, and the pack is designed to make that conversation faster and cheaper.

Do you handle the incident for us?

Not as part of the pack. Compliance Concierge clients get same-week support on live incidents; otherwise the pack is what your own team runs.

How long does it take to receive?

Around five working days from your register being complete, plus the walkthrough call at a time that suits your incident owner.

Not sure which you need?

Run the free AI register first — it takes about ten minutes and usually makes the answer obvious. Or tell us what you're dealing with and we'll point you at the right thing.

Not legal advice. Trestano provides governance tooling, documentation and practical guidance. It isn't a substitute for advice from a qualified solicitor or your own compliance team.