Data Breach Response Policy Policy.
What we do if personal data is exposed, who we tell, and how quickly.
Last updated: 3 August 2026
What counts as a breach
A personal data breach is any security incident leading to personal data being lost, altered, disclosed or accessed without authorisation — accidentally or deliberately. It is broader than "hacked": sending a document to the wrong recipient, returning one customer's data to another, or losing access to records are all breaches.
We also record near misses — where something could have gone wrong but a control caught it. These are not legally required, but they are the clearest evidence that our controls work, and they tell us where to strengthen things before a real breach.
What we do when one happens
- Contain — stop the exposure. That may mean disabling a feature, revoking a link or taking a control offline while we work.
- Assess — establish what data was involved, how many people are affected, and what the actual risk to them is.
- Record — log it in our internal breach and near-miss register with the facts, the fix, when it was fixed, and the number of people affected. Article 33(5) UK GDPR requires every breach to be documented, whether or not it is reported.
- Notify the ICO where the breach is likely to result in a risk to people's rights and freedoms — within 72 hours of becoming aware.
- Tell the people affected, without undue delay, where the risk to them is high — in plain language, with what happened and what they can do.
- Fix the cause, not just the symptom, and record the remedial action.
The 72-hour clock
If you are an agency customer
Reporting something to us
If you think personal data held by PropertyGoose has been exposed, lost or sent to the wrong person, tell us immediately at info@propertygoose.co.uk. Include what happened, when you noticed, and any reference numbers — but please do not attach the exposed data itself.
Security vulnerabilities are handled through our security page.