Breach notification
If a security breach affecting personal data were to occur, we act in
accordance with the obligations of the GDPR and what's agreed in the
Data Processing Agreement.
Our commitment as processor
As data processor, in the event of a breach affecting your data:
- We notify you without undue delay once we become aware of it.
- We provide you with the necessary information so that you, as
controller, can meet your own notification obligations (to the
supervisory authority and, where applicable, to data subjects).
- We cooperate with you in the investigation and mitigation measures.
To the extent we have it, we pass on to you:
- The nature of the breach and the categories of data affected.
- The likely consequences.
- The measures taken or proposed to mitigate the impact.
- A point of contact to coordinate.
Timeframes
The GDPR sets the controller a reference deadline of 72 hours to
notify the supervisory authority when required. Our goal is to inform you
quickly enough for you to meet that deadline.
Contractual detail
The exact procedure, points of contact, and internal notification
timeframes are specified in your DPA. We provide it on request.