PanicStation.org
uk Work & employment crises

What to do if…
you are blamed for or investigated over a workplace data breach

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy UK guide

Short answer

Report any continuing risk immediately through your employer’s authorised incident route and follow the security team’s containment instructions. Do not delete, alter or privately copy records, and prepare a factual chronology of what you directly know.

Do not do these things

  • Do not delete, edit, wipe, reset or conceal relevant messages, files, logs, accounts or devices unless an authorised incident responder instructs you to do so.
  • Do not forward workplace data or possible evidence to a personal email account, cloud service or device.
  • Do not continue accessing an affected system after being told to stop.
  • Do not contact affected people, customers, the media or outside organisations on behalf of your employer unless you are authorised to do so.
  • Do not speculate about what happened or accuse colleagues without evidence.
  • Do not coordinate accounts or suggested answers with other people involved.
  • Do not accept blame, guess at answers or confirm a statement you believe is inaccurate simply to end the discussion.
  • Do not resign or make another irreversible employment decision in the first rush of panic.

What to do now

  1. Report any continuing exposure immediately. Use the organisation’s stated route, such as its IT security team, data protection contact, incident desk or manager. Say clearly if data may still be accessible, an email is still being delivered, a device is missing or an account may be compromised.

  2. Follow authorised containment instructions. Use only the organisation’s approved security controls or compromised-account process. Record what you did and when, but do not independently wipe devices, remove files or change records that may be needed to establish what happened.

  3. Give the incident team precise facts. State what happened, when you noticed it, which system or device was involved, what information may be affected, who may have received or accessed it and what action you have already taken. Separate facts from assumptions.

  4. Create a dated chronology in an approved location. Record relevant times, instructions, alerts, conversations and actions while they are fresh. Do not reproduce personal data, confidential files, passwords or security information unnecessarily.

  5. Preserve the original records. Keep relevant emails, alerts, meeting invitations and written instructions in their existing workplace locations. Tell the investigator where system records or relevant witnesses may exist rather than collecting restricted material yourself.

  6. Ask what process is being followed. Request written confirmation of whether a proposed meeting is an incident-response discussion, an investigatory meeting or a formal disciplinary hearing. Ask for the issue being examined, the meeting’s purpose, the relevant policies and what will happen next.

  7. Prepare a factual account. Check your chronology against the information supplied. Say when you do not know or cannot remember something. Mention relevant matters such as shared accounts, unclear instructions, system faults, access by other authorised users or missing training only where they genuinely apply.

  8. Check the meeting record. Take permitted notes and ask for a copy of any meeting notes or statement. Read it carefully and request corrections before confirming that it accurately records what you said.

  9. Ask about accompaniment. For an investigatory meeting, ask whether the employer’s policy allows a companion. At a formal disciplinary hearing that may lead to formal action, request an eligible work colleague or trade union representative and give the employer reasonable notice.

  10. Get independent support if the matter becomes formal. Contact your trade union or an official employment-advice service if dismissal, a formal warning, police involvement or pressure for an immediate admission is being discussed. Acas covers England, Scotland and Wales; the Labour Relations Agency covers Northern Ireland.

What can wait

You do not need to decide now whether to resign, raise a grievance, bring an employment claim or make an external report unless doing so is part of your role or you have received independent advice. You also do not need to provide a complete technical explanation before relevant records have been secured and the allegation has been clarified.

Important reassurance

Being investigated does not mean that misconduct has been established. A workplace investigation should gather relevant information from all sides and determine whether there is a case to answer, rather than begin by assuming guilt.

Scope note

This guide covers immediate incident reporting and the first stages of a workplace investigation. Later decisions involving disciplinary action, appeals, regulatory reporting, criminal allegations or employment claims may require specialist advice.

Important note

This is general information, not legal, employment, data protection, cybersecurity or professional advice. Procedures and rights can differ between Great Britain and Northern Ireland, and your employment status, contract, workplace policies and circumstances may affect what applies.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us