Data Breach Response Plan
Last updated: 27 August 2026
1. Purpose and scope
This plan describes how Clayton Leonard Enterprises Ltd (Unit 19, Seatown Business Campus, Swords, Co. Dublin, K67 Y673, Ireland), operator of www.ivapegreatshop.ie, responds to personal data breaches in line with Articles 33 and 34 of the GDPR and the Data Protection Act 2018. It applies to all personal data we control, whether held on our systems or processed on our behalf by service providers such as our e-commerce platform, payment processors, courier and marketing platforms.
2. What is a personal data breach?
A personal data breach is "a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed". Examples include: unauthorised access to customer accounts or order data; loss or theft of a device containing personal data; misdirected emails containing customer details; a ransomware or other cyber attack; or a breach at one of our processors affecting our customers' data.
3. Responsibilities
- Our designated Data Protection Lead is responsible for coordinating breach response, maintaining the breach register, and liaising with the Data Protection Commission. Contact: [INSERT CONTACT EMAIL], marked "Data Protection".
- All staff and contractors must report any suspected breach to the Data Protection Lead immediately upon discovery, however minor it may appear.
- Our processors are contractually required under Article 28 GDPR to notify us without undue delay after becoming aware of a breach affecting our data.
4. Response procedure
Phase 1 — Identification and containment (immediately)
- Confirm whether a breach has occurred and record the date and time of discovery.
- Contain the breach: isolate affected systems, revoke compromised credentials, recall misdirected communications where possible, and instruct processors as needed.
- Preserve evidence and logs for investigation.
Phase 2 — Risk assessment (within 24–48 hours)
- Establish what data was affected, how many people, and the likely consequences (e.g. fraud, identity theft, loss of confidentiality).
- Assess the risk to the rights and freedoms of affected individuals, considering the nature of the data, the number of people affected, and how easily individuals could be identified.
Phase 3 — Notification
-
To the Data Protection Commission: unless the breach is unlikely to result in a risk to individuals, we will notify the Data Protection Commission (DPC) without undue delay and, where feasible, within 72 hours of becoming aware of the breach, using the DPC's breach-notification process at www.dataprotection.ie. If notification is made after 72 hours, it will be accompanied by reasons for the delay.
-
To affected individuals: where the breach is likely to result in a high risk to individuals, we will inform them without undue delay, in clear plain language, describing the nature of the breach, the likely consequences, the measures we have taken, and the steps they can take to protect themselves, together with a contact point.
-
To others where relevant: An Garda Síochána (for criminal activity), our insurers, payment providers and card schemes (for payment-data incidents).
Phase 4 — Evaluation and prevention
- Record every breach — whether or not notified to the DPC — in our internal breach register, including its effects and the remedial action taken (Article 33(5) GDPR).
- Carry out a post-incident review to identify the root cause and implement measures (technical, organisational or training) to prevent recurrence.
5. Reporting a concern to us
If you believe your personal data held by us has been compromised, contact us immediately at our Contact Us page. You also have the right to complain directly to the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28.
6. Review
This plan is reviewed at least annually, and after any significant incident or change to our systems or processors.