Regulatory Templates
ICO, FCA, PRA, DSPT, and SRA notification templates.
Regulatory Notification Templates
CrownSync Playbooks provides pre-built notification templates for every major UK regulator that requires incident reporting. These templates are formatted to meet each regulator's specific submission requirements and are automatically personalised with your organisation details. Regulatory templates appear at the appropriate step within your playbooks and are also accessible from the Communications section.
Regulatory Deadlines Are Strict
Many regulatory notifications carry mandatory deadlines. The ICO requires breach notification within 72 hours of becoming aware of a personal data breach. FCA and PRA notifications must be made without undue delay. Missing these deadlines can result in significant fines and enforcement action. CrownSync Playbooks tracks these deadlines during active incidents, but it is your organisation's responsibility to ensure timely submission.
ICO Breach Notification
The ICO breach notification template is designed for reporting personal data breaches under UK GDPR Article 33. The template includes all fields required by the ICO's online reporting tool and is structured to help you provide a complete initial notification even when full details are still emerging.
The template covers the following required information:
- Organisation name, ICO registration number, and DPO contact details
- Date and time the breach was discovered
- Nature of the breach (confidentiality, integrity, or availability)
- Categories and approximate number of data subjects affected
- Categories of personal data involved
- Likely consequences of the breach
- Measures taken or proposed to address the breach
- Measures taken to mitigate possible adverse effects
72-Hour Deadline
You must notify the ICO within 72 hours of becoming aware of a reportable personal data breach. If you cannot provide all required information within this window, submit the initial notification with what you know and provide supplementary details as they become available. The template supports phased reporting for this purpose.
FCA Incident Report
Firms regulated by the Financial Conduct Authority must report material cyber incidents that could affect the firm's ability to provide adequate services to consumers, the integrity of the UK financial system, or the firm's own safety and soundness.
The FCA template includes:
- Firm reference number and regulated activities affected
- Nature and scope of the incident
- Impact on customers, markets, and firm operations
- Containment and remediation steps taken
- Communication plan for affected customers
- Estimated timeline for resolution
This template is shown only to organisations whose sector profile includes financial services regulation.
PRA Notification
Dual-regulated firms supervised by the Prudential Regulation Authority must notify the PRA of material operational incidents separately from any FCA notification. The PRA template focuses on the prudential impact of the incident, including effects on capital adequacy, liquidity, and operational resilience.
Key fields in the PRA template include:
- Firm name and PRA firm reference number
- Description of the operational disruption
- Impact on important business services
- Customer impact assessment
- Recovery timeline and actions taken
NHS DSPT Notification
NHS organisations and their suppliers who process health data must report data security incidents through the Data Security and Protection Toolkit. The DSPT template covers the specific fields required by NHS Digital, including clinical safety impact, service disruption details, and whether patient care has been affected.
The template includes:
- ODS code and organisation details
- Incident severity grading (as per DSPT criteria)
- Whether patient care or safety has been compromised
- Systems and services affected
- Number of patient records involved
- Actions taken and lessons identified
SRA Notification
Law firms regulated by the Solicitors Regulation Authority have obligations to report serious cyber incidents, particularly those involving client funds or confidential legal information. The SRA template is structured around the reporting requirements set out in the SRA Standards and Regulations.
Key fields include:
- SRA number and firm details
- Whether client money or the client account has been affected
- Whether confidential client information has been compromised
- Steps taken to protect client interests
- Details of any notifications to affected clients
Using Regulatory Templates
Regulatory templates appear automatically within your playbooks at the phase where notification is required. They can also be accessed from the Communications section. Each template is pre-populated with your organisation details from your profile. Review the content, fill in the incident-specific fields, and copy the completed notification for submission to the relevant regulator.
For guidance on editing and saving customised versions of these templates, see Customising Templates.
Was this page helpful?