Skip to content

🔥 Privacy Incident and Breach Management Process ​

Purpose ​

This process establishes how Syslifters identifies, reports, assesses, and responds to privacy incidents and data breaches to minimize impact and ensure compliance with applicable privacy and data protection regulations.

Scope ​

This process applies to all employees, contractors, and third parties who handle personal or confidential information on behalf of Syslifters.

1. Identification and Reporting ​

Any employee or third party who becomes aware of a suspected or confirmed privacy incident (e.g., unauthorized access, disclosure, loss, or alteration of personal data) must report it immediately to the directors or Data Protection Officer (DPO) via the Signal messenger.

All reports must include known details such as the date/time, nature of the incident, affected systems or data, and individuals involved.

2. Containment and Assessment ​

  • The director/DPO will promptly initiate containment measures to prevent further data loss or exposure.
  • A preliminary assessment will be conducted to determine:
    • The type and sensitivity of the data affected
    • The number of individuals impacted
    • The root cause and potential harm
    • Whether the event constitutes a notifiable breach under relevant privacy laws.

3. Notification and Escalation ​

  • If a breach meets the threshold for notification, Syslifters will notify the appropriate regulatory authority and impacted individuals and companies within required legal timeframes (e.g., within 72 hours under GDPR).
  • If a breach involves software products under the CRA, the required steps must be taken.
  • Notifications will describe the nature of the breach, data involved, potential consequences, and actions taken or recommended mitigating risks.

4. Remediation and Recovery ​

  • Corrective actions will be implemented to resolve identified vulnerabilities and prevent recurrence.
  • Systems will be restored to normal operation following security verification.

Last reviewed: 13/04/2026