Data Breach Response Policy
Introduction
This policy outlines revzper SAS's response to personal data breaches, ensuring compliance with applicable data protection regulations and minimizing risks to individuals.
Data Breach Response Obligations
1. Breach Assessment
In the event of a personal data breach, revzper SAS will assess the nature, scope, and potential impact within 24 hours of detection.
2. Supervisory Authority Notification
If the breach is likely to result in a risk to the rights and freedoms of individuals, revzper SAS will notify the relevant supervisory authority within 72 hours of detection.
Ref: GDPR Art. 33
3. Data Subject Notification
If the breach is likely to result in a high risk to the rights and freedoms of natural persons, revzper SAS will notify affected data subjects without undue delay. Such risks include discrimination, identity theft, financial loss, or other significant economic or social disadvantages.
Ref: GDPR Art. 34, GDPR Recital 85
4. Breach Documentation
revzper SAS will document all breaches, including causes, effects, and remedial actions taken.
Ref: GDPR Art. 33(5), GDPR Art. 30(1)(g)
5. Preventive Measures
revzper SAS will implement measures to prevent recurrence of personal data breaches.
Supervisory Authority Notification Process
1. Notification Authority
In the event of a personal data breach requiring notification to the relevant supervisory authority within 72 hours, revzper SAS will submit the breach notification to the French Data Protection Authority (CNIL).
2. Notification Portal
The notification will be submitted through the CNIL's official online portal.
3. Notification Package Contents
The notification package will include:
- A description of the nature of the personal data breach, including the categories and approximate number of data subjects and personal data records concerned;
- The name and contact details of the data protection officer (DPO) or other contact point where more information can be obtained;
- A description of the likely consequences of the personal data breach;
- A description of the measures taken or proposed to be taken by revzper SAS to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
4. Notification Timeline
The notification will be prepared and submitted by the DPO or designated incident response team within the 72-hour deadline.
5. Notification Documentation
All breach notifications will be documented in the internal breach documentation template.
Ref: GDPR Art. 33(5)
Internal Breach Documentation Template
1. Purpose of Documentation
All personal data breaches will be documented using a standardized template to ensure consistency, traceability, and compliance with applicable regulations.
2. Breach Documentation Fields
The breach documentation template includes the following fields:
- Breach ID: Unique identifier for the breach.
- Detection Date/Time: Date and time when the breach was detected.
- Product: The product(s) affected by the breach.
- Hosting Environment: The hosting environment where the breach occurred.
- Data Location: The geographic location of the affected data.
- Breach Description: A detailed description of the nature and scope of the breach.
- Categories of Data Affected: The categories of personal data involved.
- Approximate Number of Data Subjects: The approximate number of individuals affected by the breach.
- Assessment Date/Time: Date and time when the breach was assessed.
- Risk Assessment: The assessed risk level (low, medium, high) and justification.
- Supervisory Authority Notification: Date and time of notification to the supervisory authority, if applicable.
- Data Subject Notification: Date and time of notification to affected data subjects, if applicable.
- Remedial Actions Taken: A description of the measures taken to address the breach and prevent recurrence.
- Root Cause Analysis: The root cause of the breach and any systemic issues identified.
- Preventive Measures: Additional measures implemented to prevent recurrence.
- DPO Review Date: Date when the DPO reviewed and approved the breach documentation.
3. Documentation Process
Ref: GDPR Art. 30(1)(g)
The breach documentation process includes the following steps:
- Initial Documentation: The incident response team will complete the template within 24 hours of breach detection.
- Assessment Update: The risk assessment and remedial actions will be updated as the investigation progresses.
- Final Review: The DPO will review and approve the final documentation within 72 hours of breach detection.
- Retention: The completed template will be retained for a minimum of 3 years in accordance with applicable regulations.
4. Documentation Storage and Sharing
All breach documentation will be stored securely and shared with relevant stakeholders, including the supervisory authority and affected data subjects, as required by applicable regulations.