Data Breach Response Plan
This plan explains how SchoolBudi responds if personal data is ever lost, accessed without permission, or otherwise compromised — and how schools and families would be kept informed.
1. Purpose and scope
This plan sets out how SchoolBudi responds to a personal data breach: any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
It applies to all personal data we process on behalf of schools, including pupil check-in data and staff account information, as well as data on our own website and systems.
Schools remain the controller of their pupils' data; SchoolBudi acts as processor and will assist schools in meeting their own breach-notification obligations.
2. What counts as a breach
Examples include: unauthorised access to pupil or staff accounts, data being sent to the wrong recipient, a system outage that makes data unavailable, malware or ransomware affecting our systems, or data being lost or altered without authorisation.
Not every incident is a reportable breach, but every suspected incident is taken seriously and assessed.
3. Detection and reporting
We monitor our systems for unusual activity, review security alerts from our infrastructure providers, and log administrative access.
Anyone can report a suspected breach — including school staff, parents, or children via a trusted adult — by emailing hello@schoolbudi.co.uk.
We aim to acknowledge breach reports immediately and begin our response within 24 hours of being made aware.
4. Our response process
Contain: we act quickly to stop the breach getting worse — revoking access, resetting credentials, isolating affected systems, or taking a service temporarily offline if needed.
Assess: we establish what data was involved, whose data it was, the risk to those people, and the likely cause.
Notify: where a breach is likely to result in a risk to individuals, we notify the Information Commissioner's Office (ICO) without undue delay and, where required, within 72 hours of becoming aware of it.
Resolve: we fix the underlying cause and restore normal service, verifying the fix before reopening access.
5. Notifying schools and individuals
If a breach affects a school's data, we inform the school's nominated contact as soon as we have assessed the incident, providing the information schools need to meet their own duties.
Where a breach is likely to result in a high risk to individuals, affected people (or, for children, their parents or guardians via the school) will be informed without undue delay, in clear and plain language.
Notifications will describe what happened, what data was involved, what we are doing about it, and what steps individuals can take.
6. Records of breaches
We keep an internal record of every personal data breach, whether or not it is reported to the ICO.
Each record includes the facts of the breach, its effects, and the remedial action taken, so we can demonstrate compliance and learn from incidents.
7. Review and prevention
After every breach we review what happened and update our systems, procedures, or training to reduce the chance of it happening again.
We review this plan regularly and after any significant incident to make sure it stays effective.
8. Contact
To report a suspected data breach or ask about this plan, email hello@schoolbudi.co.uk.
You can also contact the ICO directly at ico.org.uk if you are concerned about how your data has been handled.
Last updated: 24/09/2026.