Data Leak Procedure
Data Breach Notification Procedure – Atlas NextWave
Atlas NextWave is committed to protecting personal data and ensuring compliance with applicable data protection laws, including the UK GDPR, EU GDPR, and the UK Data (Use and Access) Act 2025 (“DUAA”).
A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
- Immediate Internal Reporting (Mandatory)
All employees, contractors, professionals, suppliers, and partners must immediately report any actual or suspected personal data breach.
Notifications must be made without delay via:
• Email: privacyofficer@atlasnextwave.com
• Telephone: +44 7375 559494
Failure to report promptly may expose Atlas NextWave to regulatory risk and will be treated as a compliance matter. - Minimum Information Required
The initial report should include, where available:
• Description of the incident (what happened)
• Date and time of discovery (and, if known, occurrence)
• Nature and cause of the breach (e.g. cyber incident, loss, unauthorised access)
• Categories and approximate volume of personal data affected
• Categories and number of affected individuals
• Immediate containment measures taken
• Initial assessment of potential impact/risk
• Contact details of the reporter
Incomplete information should not delay reporting updates can follow.
- Assessment and Escalation
Upon notification, the Global Privacy Officer will:
1. Log the incident in the central breach register (mandatory for all incidents, including non-notifiable ones, in line with DUAA accountability requirements)
2. Initiate an investigation with relevant stakeholders (IT, HR, Legal, Operations, Marketing as applicable)
3. Assess risk level, considering:
• Nature and sensitivity of data
• Volume and identifiability
• Ease of identification of individuals
• Severity of potential harm (financial, reputational, legal, safety)
• Whether data is encrypted or otherwise protected - Regulatory Notification
Where a breach is likely to result in a risk to the rights and freedoms of individuals, Atlas NextWave will:
• Notify the relevant supervisory authority, including the Information Commissioner’s Office and/or Dutch Data Protection Authority
• Do so without undue delay and, where required, within 72 hours of becoming aware of the breach
Where notification is delayed, reasons must be documented. - Notification to Data Subjects
Where a breach is likely to result in a high risk to individuals, Atlas NextWave will notify affected individuals without undue delay.
Such notification will include:
• A clear description of the breach
• Likely consequences
• Measures taken or proposed to address the breach
• Steps individuals can take to mitigate harm
• Contact details for further information
Notification may be made via direct communication (e.g. email/letter) and/or public communication (e.g. website notice), depending on the circumstances.
Notification is not required where:
• Data is effectively encrypted or rendered unintelligible; and
• The risk to individuals is demonstrably low
This must be assessed and documented on a case-by-case basis.
- Containment, Mitigation and Remediation
Atlas NextWave will take all necessary steps to:
• Contain the breach and prevent further unauthorised access
• Recover data where possible
• Mitigate risks to affected individuals
• Implement corrective actions to prevent recurrence
This may include system changes, access restrictions, policy updates, and training.
- Record-Keeping and Accountability
In line with GDPR and DUAA requirements:
• All data breaches (including near misses) must be documented
• Records must include facts, effects, decisions, and remedial actions
• The breach register will be maintained by the Global Privacy Officer
• Records must be sufficient to demonstrate regulatory compliance and audit readiness
- Third Parties and Contractual Obligations
All suppliers and partners processing personal data on behalf of Atlas NextWave must:
• Notify Atlas NextWave immediately upon becoming aware of a breach
• Cooperate fully in investigations and remediation
• Comply with contractual data protection obligations
All relevant agreements must include reference to this procedure and clear breach notification obligations. - Governance and Oversight
• The Global Privacy Officer will report material breaches to senior management
• Significant incidents may be escalated to Board level where appropriate
• Periodic reporting will support ongoing compliance monitoring and risk management
- Further Information
Further details are available in the Atlas NextWave Data Breach Notification Protocol and Privacy Statement, accessible via:
www.atlasnextwave.com.