GDPR procedure: Data Breach Response and Notification Procedure
In case we suffer a data breach, we will enact the following procedure, and you will be notified within a week of the result of the assessment.
Measures to follow:
Lockdown of service: possible downtime for the web app(s)
Assessment of how the breach happened by analysis on the servers
We will detail whether the breach happened as result of an attack, or of bugs in the code
Assessment of which private data was involved in the incident
Assessment of the remediation
Alerting of the end users, within a week, about the accidents (point 3) and remediation (point 4)
Write-up in the data breach register and the alerting of the authorities
Templates for the alerting of ponits 5 and 6 can be found on the DPC shared drive (accessible only to the Data Privacy Commission)