Personal-data breach procedure
This procedure applies to any event that may lead to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data held on InnoQualis systems — the hub, the website, the tools host, backups, or a sub-processor. It sits alongside the incident response guide (availability incidents) and is contractual through the DPA §8. Owner: the on-call founder. Last reviewed: 13 September 2026.
The clocks
Section titled “The clocks”| Clock | Starts | Deadline |
|---|---|---|
| Customer notice (DPA §8) | The moment we become aware — a credible report, an alert, a log entry we cannot explain | Without undue delay, no later than 48 hours |
| Supervisory authority (UK GDPR Art. 33) | The moment we become aware, as controller | 72 hours, unless the breach is unlikely to result in a risk to individuals — and the reasoning is recorded either way |
| Data subjects (Art. 34) | Assessment concludes the risk is high | Without undue delay |
| Write-up | Resolution | 72 hours (Trust Centre commitment) |
“Aware” is when a reasonable degree of certainty exists that a breach occurred — not when the investigation is finished. Start the clock, then investigate.
Step 1 — Record and contain (first hour)
Section titled “Step 1 — Record and contain (first hour)”- Open a ticket
KAN-…titledBreach: <one line>with the timestamp of awareness in UTC. Everything below goes on the ticket. - Preserve evidence before changing anything: copy journald, auth logs, Docker logs and
/dev/shmoff the box (scripts/backup/has the encryption recipe); note running processes and listening ports. Do not reboot or kill first — evidence goes with it. - Contain: rotate the credential involved, block the source at the firewall or in CrowdSec, suspend the affected user or workspace from the control panel if a workspace account is the vector. If a sub-processor is the source, open their incident channel and record the reference.
- Decide who is affected: which workspaces (
tenant_id), which data categories, how many people, whether backups are involved.
Step 2 — Assess (by hour 24)
Section titled “Step 2 — Assess (by hour 24)”Answer on the ticket, in writing:
- What happened, when it started, when it was detected, and how.
- Data categories and approximate numbers of records and individuals.
- Likely consequences for the people concerned (identity, financial, reputational, physical — quality records can contain health information in complaints).
- Whether the data was encrypted, pseudonymised or otherwise unreadable to the recipient.
- Risk rating: none / low / high — and why.
Step 3 — Notify customers (by hour 48)
Section titled “Step 3 — Notify customers (by hour 48)”For every affected workspace, email the workspace administrators from dpo@innoqualis.com using the template below, even if the assessment is not complete — say what is known, what is not, and when the next update comes. Log the send time on the ticket.
Subject: Personal-data breach notice — InnoQualis workspace <workspace name>
We are writing under section 8 of our Data Processing Agreement.
What happened: <plain-language description>When: detected <date time UTC>; started (as far as we know) <date time UTC>What data is involved: <categories, approximate volume, which records>Who is affected: <categories of individuals, approximate number>What we have done: <containment steps and their times>What we recommend you do: <e.g. rotate the affected user's sign-in email password, notify individuals if your assessment requires it>Likely consequences: <our assessment; or "not yet assessed — next update by <time>">Contact: dpo@innoqualis.com — reference <KAN-…>We will send the next update by <date time UTC>.Step 4 — Notify the ICO (by hour 72) where we are controller
Section titled “Step 4 — Notify the ICO (by hour 72) where we are controller”Where the breach concerns data InnoQualis controls (accounts, billing, website, staff) and is likely to result in a risk, notify the Information Commissioner’s Office through its report-a-breach form (ico.org.uk/for-organisations/report-a-breach/) within 72 hours; where InnoQualis is processor, the customer is the controller and decides — we supply the facts they need. If you cannot notify within 72 hours, notify in phases and record the reason for the delay. Record the ICO reference on the ticket. Where EU residents are affected and the EU GDPR applies, InnoQualis has no EU establishment and therefore no lead supervisory authority under the one-stop-shop: each concerned EU supervisory authority is notified directly (legal review KAN-820 confirms the route and whether an Article 27 representative is required).
ICO notification — working notesOrganisation: InnoQualis LTD, company number 17066029, <ICO registration number>Contact: dpo@innoqualis.comNature of the breach: <categories and approximate numbers of data subjects and records>Likely consequences: <…>Measures taken or proposed: <…>Why late (if late): <…>Step 5 — Individuals (if high risk)
Section titled “Step 5 — Individuals (if high risk)”If the assessment is high, tell the individuals directly, in plain language, with the same content as the customer notice and concrete steps they can take. Where they are in a customer’s workspace, agree the message with the customer first — they are the controller.
Step 6 — Close
Section titled “Step 6 — Close”- Root cause and the fix, with the PR and ticket links.
- Write-up on status.innoqualis.com within 72 hours of resolution if availability or customer data was affected.
- Update this procedure and the Records of processing if anything changed.
- Keep the ticket: Art. 33(5) requires a record of every breach, including those not notified, with the reasoning.