Legal

    Data Breach Response Policy Policy.

    What we do if personal data is exposed, who we tell, and how quickly.

    Last updated: 3 August 2026

    What counts as a breach

    A personal data breach is any security incident leading to personal data being lost, altered, disclosed or accessed without authorisation — accidentally or deliberately. It is broader than "hacked": sending a document to the wrong recipient, returning one customer's data to another, or losing access to records are all breaches.

    We also record near misses — where something could have gone wrong but a control caught it. These are not legally required, but they are the clearest evidence that our controls work, and they tell us where to strengthen things before a real breach.

    What we do when one happens

    1. Contain — stop the exposure. That may mean disabling a feature, revoking a link or taking a control offline while we work.
    2. Assess — establish what data was involved, how many people are affected, and what the actual risk to them is.
    3. Record — log it in our internal breach and near-miss register with the facts, the fix, when it was fixed, and the number of people affected. Article 33(5) UK GDPR requires every breach to be documented, whether or not it is reported.
    4. Notify the ICO where the breach is likely to result in a risk to people's rights and freedoms — within 72 hours of becoming aware.
    5. Tell the people affected, without undue delay, where the risk to them is high — in plain language, with what happened and what they can do.
    6. Fix the cause, not just the symptom, and record the remedial action.

    The 72-hour clock

    The 72 hours runs from the moment we become aware of the breach — not from when it happened, and not from when it was fully understood. Our register records the moment of discovery separately from the moment of reporting, so that timeliness can be evidenced rather than estimated.

    If you are an agency customer

    Where we process personal data on your behalf and a breach affects that data, we will inform you without undue delay and give you the information you need to meet your own obligations as a controller — including the nature of the breach, the categories and approximate number of records involved, the likely consequences and the measures taken.

    Reporting something to us

    If you think personal data held by PropertyGoose has been exposed, lost or sent to the wrong person, tell us immediately at info@propertygoose.co.uk. Include what happened, when you noticed, and any reference numbers — but please do not attach the exposed data itself.

    Security vulnerabilities are handled through our security page.

    Your right to complain

    You can complain to us at any time, and you have the right to complain directly to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. You do not need to raise it with us first, though it often gets resolved faster if you do. PropertyGoose is registered with the ICO under ZC014112.