Skip to content

Personal-data breach procedure

This procedure applies to any event that may lead to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data held on InnoQualis systems — the hub, the website, the tools host, backups, or a sub-processor. It sits alongside the incident response guide (availability incidents) and is contractual through the DPA §8. Owner: the on-call founder. Last reviewed: 13 September 2026.

ClockStartsDeadline
Customer notice (DPA §8)The moment we become aware — a credible report, an alert, a log entry we cannot explainWithout undue delay, no later than 48 hours
Supervisory authority (UK GDPR Art. 33)The moment we become aware, as controller72 hours, unless the breach is unlikely to result in a risk to individuals — and the reasoning is recorded either way
Data subjects (Art. 34)Assessment concludes the risk is highWithout undue delay
Write-upResolution72 hours (Trust Centre commitment)

“Aware” is when a reasonable degree of certainty exists that a breach occurred — not when the investigation is finished. Start the clock, then investigate.

Step 1 — Record and contain (first hour)

Section titled “Step 1 — Record and contain (first hour)”
  1. Open a ticket KAN-… titled Breach: <one line> with the timestamp of awareness in UTC. Everything below goes on the ticket.
  2. Preserve evidence before changing anything: copy journald, auth logs, Docker logs and /dev/shm off the box (scripts/backup/ has the encryption recipe); note running processes and listening ports. Do not reboot or kill first — evidence goes with it.
  3. Contain: rotate the credential involved, block the source at the firewall or in CrowdSec, suspend the affected user or workspace from the control panel if a workspace account is the vector. If a sub-processor is the source, open their incident channel and record the reference.
  4. Decide who is affected: which workspaces (tenant_id), which data categories, how many people, whether backups are involved.

Answer on the ticket, in writing:

  • What happened, when it started, when it was detected, and how.
  • Data categories and approximate numbers of records and individuals.
  • Likely consequences for the people concerned (identity, financial, reputational, physical — quality records can contain health information in complaints).
  • Whether the data was encrypted, pseudonymised or otherwise unreadable to the recipient.
  • Risk rating: none / low / high — and why.

For every affected workspace, email the workspace administrators from dpo@innoqualis.com using the template below, even if the assessment is not complete — say what is known, what is not, and when the next update comes. Log the send time on the ticket.

Subject: Personal-data breach notice — InnoQualis workspace <workspace name>
We are writing under section 8 of our Data Processing Agreement.
What happened: <plain-language description>
When: detected <date time UTC>; started (as far as we know) <date time UTC>
What data is involved: <categories, approximate volume, which records>
Who is affected: <categories of individuals, approximate number>
What we have done: <containment steps and their times>
What we recommend you do: <e.g. rotate the affected user's sign-in email password, notify individuals if your assessment requires it>
Likely consequences: <our assessment; or "not yet assessed — next update by <time>">
Contact: dpo@innoqualis.com — reference <KAN-…>
We will send the next update by <date time UTC>.

Step 4 — Notify the ICO (by hour 72) where we are controller

Section titled “Step 4 — Notify the ICO (by hour 72) where we are controller”

Where the breach concerns data InnoQualis controls (accounts, billing, website, staff) and is likely to result in a risk, notify the Information Commissioner’s Office through its report-a-breach form (ico.org.uk/for-organisations/report-a-breach/) within 72 hours; where InnoQualis is processor, the customer is the controller and decides — we supply the facts they need. If you cannot notify within 72 hours, notify in phases and record the reason for the delay. Record the ICO reference on the ticket. Where EU residents are affected and the EU GDPR applies, InnoQualis has no EU establishment and therefore no lead supervisory authority under the one-stop-shop: each concerned EU supervisory authority is notified directly (legal review KAN-820 confirms the route and whether an Article 27 representative is required).

ICO notification — working notes
Organisation: InnoQualis LTD, company number 17066029, <ICO registration number>
Contact: dpo@innoqualis.com
Nature of the breach: <categories and approximate numbers of data subjects and records>
Likely consequences: <…>
Measures taken or proposed: <…>
Why late (if late): <…>

If the assessment is high, tell the individuals directly, in plain language, with the same content as the customer notice and concrete steps they can take. Where they are in a customer’s workspace, agree the message with the customer first — they are the controller.

  • Root cause and the fix, with the PR and ticket links.
  • Write-up on status.innoqualis.com within 72 hours of resolution if availability or customer data was affected.
  • Update this procedure and the Records of processing if anything changed.
  • Keep the ticket: Art. 33(5) requires a record of every breach, including those not notified, with the reasoning.