Information and Data Protection Office

  • Home
  • About
  • Information
    • For individuals
    • For organisations
    • For public authorities
  • Contact us
Make a complaint or report
Information and Data Protection Office > Information > Data security and breaches

Data security and breaches

This page explains your security and breach response duties under the Freedom of Information and Data Protection Act 2026.


Security obligations

  • You must take appropriate technical and organisational measures to protect personal data
  • Your security measures must be proportionate to the level of risk
  • You must protect personal data against unauthorised access, loss, damage and misuse

What counts as a data breach

A data breach is any incident that results in the loss, unauthorised access, disclosure or destruction of personal data.

Notifying the IDPO

If a data breach could risk harm to individuals, you must notify the Information and Data Protection Office without undue delay.

Informing affected individuals

If a breach presents a high risk to individuals, you must inform those individuals without undue delay.

After a breach

You must follow any binding directions issued by the Information and Data Protection Office.

You must take steps to reduce the risk of further harm and prevent future breaches.

Information

Information for individuals

Information for organisations

Information for public authorities

Resources

About the IDPO

News and publications

Site terms and privacy policy

The Information and Data Protection Office of the Hokorian State

The Information Data Protection Office is an independent regulator for information and data in the Hokorian State, as established under the Freedom of Information and Data Protection Act, 2026.

All public organisations in the Hokorian State use a ‘hokoriagov.net’ or ‘hokoria.net’ domain.