Breach Notification Process
In the event of a personal data breach, Convo is committed to prompt action and full GDPR compliance:
- Immediate Response: Upon breach identification, we will act swiftly to contain and assess the situation to minimise further risks.
- Notifying Supervisory Authorities: We notify the ICO of personal data breaches without undue delay and, where feasible, within 72 hours of awareness (Article 33).
- Notification to Affected Users: If the breach is likely to result in a high risk to individuals, we notify affected users without undue delay (Article 34) and provide: description, likely consequences, and measures taken.
- Ongoing Communication: We will provide further updates to affected individuals as necessary and offer guidance on protective measures.
- Post-Breach Review: We maintain a breach register, conduct root-cause analysis, and implement corrective actions.
Next: Infrastructure Security
