Read the notice as a risk map
Look for the date of the breach, the affected service, the categories of data involved and the organisation’s recommended actions. A leaked email address creates a different risk from an exposed password, identity document or bank detail. Do not use links or phone numbers in an unexpected message until you verify it independently.
Secure the route an attacker would use
- If a password was exposed, change it anywhere it was reused. Start with email and financial accounts.
- Turn on multi-factor authentication and save recovery codes securely.
- If payment data was involved, contact the provider using its official number and monitor transactions.
- If identity documents were exposed, keep the breach notice and watch for convincing impersonation attempts.
- Update devices and run a security scan if you downloaded or opened something suspicious.
Know the organisation’s duties
Under GDPR, organisations assess the risk to people after a personal-data breach. The Data Protection Commission says a controller must notify the regulator within 72 hours where the breach presents a risk, and inform affected people without undue delay where high risk is likely.
Sources and review record
- Data Protection Commission: Personal data breaches · accessed 11 July 2026.
- NCSC: Online account security guidance · accessed 11 July 2026.
This guide provides general information for the Republic of Ireland. Check the linked official guidance for your circumstances and current rules.