Skip to content
Kivuz
All services

Data Breach Response & Notification

In a data breach, every hour matters. From detection and containment to timely notification of the Board and informing data subjects, we manage the whole process with our expert team — in a documentable way.

Scope

Breach detection, containment and impact/risk assessment
Notification to the Personal Data Protection Board within 72 hours
Informing the data subjects affected by the breach
Documentation, evidence collection and breach register
Post-incident root-cause analysis and remediation recommendations

Deliverables

Breach response plan
Board and data-subject notification drafts
Breach register and closure report
Process

How we work

1

Detect & contain

Identifying the source of the breach and stopping its spread.

2

Assess

Analyzing affected data categories, number of people/records and likely consequences.

3

Notify

Notifying the Board within 72 hours and data subjects where required.

4

Record & improve

Documenting the process and planning measures to prevent recurrence.

Frequently asked questions

How soon must the Board be notified?

The data controller notifies the Board as soon as possible and in any case within 72 hours of becoming aware of the breach.

Must data subjects also be notified?

If the affected individuals can be identified, they are also informed as soon as possible by an appropriate method.

Is preparation in advance essential?

Yes; a response plan, record-keeping discipline and technical-administrative measures enable correct, fast action during a breach.

Hand your compliance burden to our experts

From needs analysis to implementation, our team is by your side.