3.2 Breach, Complaint, DSR & Retention Plans

Key Takeaways

  • Four governance-level plans anchor II.A: a data breach management plan, a complaint procedure plan, a data subject rights (DSR) process plan, and a data retention and disposal plan — each must exist as a documented, approved artifact before an incident occurs
  • A breach management PLAN is a governance blueprint (who declares, who decides notification, what thresholds trigger action); incident RESPONSE execution is the operational carry-out covered in Domain III and Domain VI — the exam tests the distinction
  • A DSR plan must define intake channels, identity verification, the statutory clock per jurisdiction, refusal and escalation criteria, and logging — not just the mechanics of fulfilling one request
  • Retention and disposal are paired: a retention schedule without enforceable disposal procedures is a legal-liability amplifier, not a compliance control
  • Each plan has a named owner accountable to the privacy leader; plans interconnect because a single incident (e.g., a breach during a DSR fulfillment error) can trigger three plans at once
Last updated: August 2026

The Four Plans at a Governance Level

The CIPM Body of Knowledge groups four plan-creation duties under II.A. At the governance level, your job is not to write the runbook that an engineer follows during an incident — it is to ensure a documented, approved plan exists that defines authority, thresholds, ownership, and reporting before the event. Operational execution (Domain III) and breach response logistics (Domain VI) build on these governance artifacts.

Plan 1: Data Breach Management Plan

A breach management plan is the governance blueprint for what the organization will do when personal data is — or may be — compromised. At a minimum it must contain:

  • Definition of a reportable breach in the organization's own terms, mapped to each applicable jurisdiction's legal threshold (e.g., GDPR Article 33's 'risk to rights and freedoms,' U.S. state-law definitions of breach of personal information).
  • Severity tiers with the escalation each tier triggers (e.g., Tier 1 — internal-only; Tier 2 — regulator-notifiable within 72 hours; Tier 3 — regulator + data subject notification).
  • Authority to declare a breach — named role, not named person, so the plan survives turnover.
  • Decision authority for notification — who decides whether to notify regulators, data subjects, law enforcement, and cyber-insurers.
  • Internal reporting clock — how fast a suspected breach must reach the privacy office once discovered (often 'immediately' or within 1 hour of detection).
  • External counsel and forensic vendor relationships pre-negotiated, so procurement does not delay response.
  • Post-incident review requirement, including a lessons-learned report to the board or privacy steering committee.

Plan 2: Complaint Procedure Plan

A complaint procedure gives data subjects and employees a documented, accessible channel to raise privacy concerns and defines how the organization will investigate and respond. Key governance components:

  • Intake channels — web form, email, postal address, phone, and (for employees) an anonymous hotline.
  • Acknowledgment and response timelines — typically acknowledge within a defined window (e.g., 5 business days) and resolve or update within a defined longer window (e.g., 30 days), unless a jurisdiction-specific law sets a different deadline.
  • Triage and severity criteria — which complaints escalate to the privacy leader, to Legal, or to the board.
  • Documentation and trend reporting — every complaint logged, trends reported to the privacy steering committee, and patterns fed back into training and controls.
  • Regulator-channel awareness — the plan must tell complainants they can also complain to the supervisory authority (a GDPR transparency requirement and a best practice elsewhere).

Plan 3: Data Subject Rights (DSR) Process Plan

A DSR plan governs how the organization fulfills access, deletion, correction, portability, objection, and restriction requests. At the governance level it must define:

  • Intake channels and the obligation to accept requests by any reasonable means under GDPR (no 'web form only' shortcut that blocks other channels).
  • Identity verification standard — proportionate to the sensitivity of the data and the risk of unauthorized disclosure.
  • Statutory clock per jurisdiction — GDPR's one-month (extendable by two months for complex cases), CCPA's 45-day window, and any other applicable law.
  • Refusal criteria and documentation — when the organization will lawfully refuse (e.g., legitimate grounds for refusal, unfounded or excessive requests) and how the refusal is communicated.
  • Internal routing matrix — which systems and data owners are involved for each request type.
  • Logging and metrics — volumes, turnaround times, refusal rates, and aging reported to the privacy steering committee.

Plan 4: Data Retention and Disposal Plan

A retention and disposal plan pairs a retention schedule (how long each data category is kept, and the legal or business basis for that period) with disposal procedures (how data is destroyed when the period ends). Governance components:

  • Retention schedule by data category and jurisdiction, with the legal basis or business need for each period.
  • Legal-hold mechanism — a process that suspends deletion when litigation, investigation, or regulatory inquiry is anticipated.
  • Disposal standard — NIST 800-88 'Clear, Purge, Destroy' guidance or an equivalent certified method; certificates of destruction for physical media.
  • Automated vs. manual deletion — preference for automated triggers tied to the system of record, with manual deletion as a controlled exception.
  • Audit trail — evidence that disposal occurred and who certified it.

Plan Comparison Table

PlanPurposeKey ComponentsOwner
Breach ManagementGovern detection, escalation, and notification of personal-data breachesSeverity tiers; notification thresholds; declaration authority; pre-negotiated forensic counsel; post-incident reviewPrivacy Leader (CPO/DPO)
Complaint ProcedureProvide an accessible channel for privacy complaints with defined response timesIntake channels; acknowledgment and resolution timelines; triage criteria; trend reporting; regulator-channel noticePrivacy Office Operations Lead
DSR ProcessFulfill data subject rights within statutory clocks across jurisdictionsIntake; identity verification; per-jurisdiction clock; refusal criteria; routing matrix; logging and metricsPrivacy Office Operations Lead
Retention & DisposalLimit personal-data lifespan and ensure certified destruction at end of lifeRetention schedule by category; legal-hold mechanism; disposal standard; audit trailPrivacy Leader + Records Manager

Breach Plan vs. Incident Response Execution — The Exam Distinction

This is a frequent exam trap. The breach management plan is a governance artifact owned by the privacy leader; it answers who decides and what thresholds apply. Incident response (IR) execution is the operational carry-out — the IT security team isolating systems, the forensic vendor imaging disks, the comms team drafting customer notices. IR execution lives in Domain VI ( Incident Response) and overlaps with Domain III (operational controls). If a question asks 'who owns the breach notification decision to the regulator,' the answer is the privacy leader (or the executive they escalate to) — not the IT responder running the forensic scan.

Worked Scenario: A DSR That Becomes a Breach

A bank receives a deletion request from a former customer. The DSR operations lead verifies identity and routes the request to the retail-banking data owner. The data owner, under time pressure, emails a spreadsheet of the customer's transaction history to a colleague in a different business unit to 'help with the deletion.' The colleague opens it on a personal device that is later lost.

Three plans triggered at once:

  1. DSR plan — the request is now at risk of missing its statutory clock because the routing went off-process.
  2. Breach management plan — personal data left an approved system and was stored on an unmanaged device; this is a potential reportable breach requiring assessment against the jurisdiction's threshold.
  3. Retention and disposal plan — the original deletion goal is now complicated by the fact that a copy exists outside the system of record and must itself be located and destroyed.

The governance lesson is that the plans are interconnected by design, and the privacy leader's job is to ensure the plan owners rehearse the seams between plans, not just their own silo.

Test Your Knowledge

A question asks whether the privacy manager or the IT security lead 'owns' the decision to notify the supervisory authority within 72 hours of a confirmed GDPR-breachable incident. Which answer aligns with the IAPP governance model?

A
B
C
D
Test Your Knowledge

Which of the following is NOT a required governance component of a data subject rights (DSR) process plan under the IAPP BoK?

A
B
C
D