{"product_id":"personuppgiftsincident-gdpr-mallpaket-2026","title":"GDPR Personal Data Breach Template Package 2026 – Word\/PDF\/Excel","description":"\n\u003ch2\u003ePersonal Data Breach GDPR Template Package 2026 – incident report, IMY notification \u0026amp; 72-hour tool\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eA complete template package for companies and organizations that need to detect, assess, document, and manage personal data breaches according to the GDPR.\u003c\/strong\u003e The package contains professional Word\/PDF templates as well as an Excel tool for incident registers, 72-hour deadlines, risk assessments, IMY (Swedish Authority for Privacy Protection) notifications, information to data subjects, processor reporting, and post-incident analysis.\u003c\/p\u003e\n\n\u003cp\u003eThe GDPR requires that \u003cstrong\u003eall personal data breaches be documented\u003c\/strong\u003e. A breach must be reported to the supervisory authority unless it is unlikely that it will result in a risk to the rights and freedoms of natural persons. If a notification is required, it must be made without undue delay and, where feasible, within \u003cstrong\u003e72 hours\u003c\/strong\u003e of the controller becoming aware of the breach.\u003c\/p\u003e\n\n\u003ch3\u003eIncluded – 9 files\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003ePersonal Data Breach – Incident Report \u0026amp; 72-hour assessment, Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eNotification to IMY – preparation documentation, Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eInformation to data subjects according to Article 34 GDPR, Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eProcedure for personal data breaches \/ Incident Response Playbook, Word + PDF\u003c\/li\u003e\n\n\u003cli\u003eExcel tool with incident register, 72h status, risk classification, IMY log, data subjects, processor notices, measures, and post-incident analysis\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eIncident report with complete decision-making process\u003c\/h3\u003e\n\u003cp\u003eThe main template helps the organization document the entire incident from initial detection to closure:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003etime of incident, detection, and organization awareness\u003c\/li\u003e\n\n\u003cli\u003eautomatic\/clear 72-hour deadline\u003c\/li\u003e\n\n\u003cli\u003eclassification as a confidentiality, integrity, or availability breach\u003c\/li\u003e\n\n\u003cli\u003eaffected data subjects and personal data\u003c\/li\u003e\n\n\u003cli\u003esensitive data, Article 10 data, protected personal data, and children\/vulnerable individuals\u003c\/li\u003e\n\n\u003cli\u003eimmediate containment and recovery measures\u003c\/li\u003e\n\n\u003cli\u003erisk assessment for the rights and freedoms of data subjects\u003c\/li\u003e\n\n\u003cli\u003edecision regarding IMY notification\u003c\/li\u003e\n\n\u003cli\u003edecision regarding information to data subjects\u003c\/li\u003e\n\n\u003cli\u003eroot cause, corrective measures, and lessons learned\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eWhen should the breach be reported?\u003c\/h3\u003e\n\u003cp\u003eAs a data controller, you must report the breach if it is \u003cstrong\u003enot unlikely\u003c\/strong\u003e that it will result in a risk to the rights and freedoms of natural persons. If all information is not available within 72 hours, the information may be provided in phases without undue further delay. In the event of a late notification, the reasons for the delay must be documented.\u003c\/p\u003e\n\n\u003cp\u003eThe package therefore contains a separate \u003cstrong\u003eIMY preparation template\u003c\/strong\u003e with the central information that needs to be collected before or during the reporting. The actual notification is made via IMY's current e-service or other channel designated by the authority.\u003c\/p\u003e\n\n\u003ch3\u003eHigh risk – information to data subjects\u003c\/h3\u003e\n\u003cp\u003eIf the personal data breach is likely to result in a \u003cstrong\u003ehigh risk\u003c\/strong\u003e, the data subjects must, as a general rule, be informed without undue delay. The package contains a ready-to-use and editable communication template with:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eclear description of what has happened\u003c\/li\u003e\n\n\u003cli\u003ewhat personal data is affected\u003c\/li\u003e\n\n\u003cli\u003elikely consequences\u003c\/li\u003e\n\n\u003cli\u003eimplemented and planned measures\u003c\/li\u003e\n\n\u003cli\u003epractical advice to the data subjects\u003c\/li\u003e\n\n\u003cli\u003econtact details for the Data Protection Officer or other point of contact\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eThe template also includes a check against Article 34 exceptions, for example, if the data was effectively encrypted, if subsequent measures eliminated the high risk, or if individual notification involves disproportionate effort.\u003c\/p\u003e\n\n\u003ch3\u003eObligations of the processor\u003c\/h3\u003e\n\u003cp\u003eA processor must report a personal data breach to the controller \u003cstrong\u003ewithout undue delay\u003c\/strong\u003e. The processor does not need to determine whether the incident entails such a risk that it must be reported to IMY – the primary responsibility for the risk and notification assessment lies with the controller.\u003c\/p\u003e\n\n\u003cp\u003eThe Excel tool therefore contains a separate register for processor notices with awareness time, initial report, time difference, missing information, and next update.\u003c\/p\u003e\n\n\u003ch3\u003eExcel – incident register with 72-hour check\u003c\/h3\u003e\n\u003cp\u003eThe Excel file serves as a practical incident management tool and contains:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003edashboard with key performance indicators\u003c\/li\u003e\n\n\u003cli\u003eincident register\u003c\/li\u003e\n\n\u003cli\u003e72-hour deadline and status \u003cem\u003eOn time \/ Urgent \/ Overdue\u003c\/em\u003e\n\n\u003c\/li\u003e\n\n\u003cli\u003erisk classification based on probability and impact\u003c\/li\u003e\n\n\u003cli\u003eIMY notification register\u003c\/li\u003e\n\n\u003cli\u003ecommunication to data subjects\u003c\/li\u003e\n\n\u003cli\u003eprocessor reporting\u003c\/li\u003e\n\n\u003cli\u003emeasures register\u003c\/li\u003e\n\n\u003cli\u003ePost-Incident Review \/ root cause analysis\u003c\/li\u003e\n\n\u003cli\u003esources and legal references\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eAll breaches must be documented\u003c\/h3\u003e\n\u003cp\u003eEven breaches that do not need to be reported to IMY must be documented. The documentation should, among other things, make it possible to verify that the organization has followed the GDPR and should also include the reasons for the decision not to notify or not to inform data subjects.\u003c\/p\u003e\n\n\u003ch3\u003eCommon incidents for which the package can be used\u003c\/h3\u003e\n\u003cul\u003e\n\n\u003cli\u003emisdirected emails or documents\u003c\/li\u003e\n\n\u003cli\u003ephishing and compromised accounts\u003c\/li\u003e\n\n\u003cli\u003eransomware and data breaches\u003c\/li\u003e\n\n\u003cli\u003eincorrect access rights\u003c\/li\u003e\n\n\u003cli\u003elost computer, phone, or storage media\u003c\/li\u003e\n\n\u003cli\u003eaccidental publication\u003c\/li\u003e\n\n\u003cli\u003eincorrect sharing via cloud service or link\u003c\/li\u003e\n\n\u003cli\u003edeletion or loss of personal data\u003c\/li\u003e\n\n\u003cli\u003eincident at a processor or subcontractor\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003ch3\u003eLegal basis\u003c\/h3\u003e\n\u003cp\u003eThe template package has been legally reviewed as of \u003cstrong\u003eOctober 3, 2026\u003c\/strong\u003e, based on:\u003c\/p\u003e\n\u003cul\u003e\n\n\u003cli\u003eGDPR Article 4(12)\u003c\/li\u003e\n\n\u003cli\u003eGDPR Article 33 – notification to the supervisory authority and documentation\u003c\/li\u003e\n\n\u003cli\u003eGDPR Article 34 – information to data subjects\u003c\/li\u003e\n\n\u003cli\u003eIMY's current guidance on personal data breaches and e-service\u003c\/li\u003e\n\n\u003cli\u003eEDPB Guidelines 01\/2021 on Examples regarding Personal Data Breach Notification\u003c\/li\u003e\n\n\n\u003c\/ul\u003e\n\n\u003cp\u003eDuring 2026, the EDPB also published a proposal for a common European breach-notification-template for public consultation. The legal accuracy of this package is not based on a consultation document that has not yet been fully implemented, but on current GDPR, IMY's current guidance, and adopted EDPB guidelines.\u003c\/p\u003e\n\n\u003ch3\u003ePlease note\u003c\/h3\u003e\n\u003cp\u003eThe package is a general compliance and documentation framework. An actual incident may simultaneously be covered by other reporting regulations, such as sector-specific requirements in finance, cybersecurity, healthcare, or public operations. Therefore, always check whether additional authorities, contracting parties, insurers, or other actors need to be informed.\u003c\/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eFormat:\u003c\/strong\u003e Word (DOCX) + PDF + Excel (XLSX)\u003cbr\u003e\n\u003cstrong\u003eLanguage:\u003c\/strong\u003e Swedish\u003cbr\u003e\n\u003cstrong\u003eJurisdiction:\u003c\/strong\u003e Sweden \/ EU\u003cbr\u003e\n\u003cstrong\u003eNumber of files:\u003c\/strong\u003e 9\u003cbr\u003e\n\u003cstrong\u003eVersion:\u003c\/strong\u003e 1.0 – 2026-10-03\u003c\/p\u003e\n","brand":"Svenska Dokumentmallar","offers":[{"title":"Default Title","offer_id":55590536610134,"sku":"GDPR-INCIDENT-2026","price":249.0,"currency_code":"SEK","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0827\/2373\/3846\/files\/personuppgiftsincident-gdpr-mallpaket-2026.png?v=1791040791","url":"https:\/\/mallbutiken.se\/en\/products\/personuppgiftsincident-gdpr-mallpaket-2026","provider":"Mallbutiken","version":"1.0","type":"link"}