← Governance framework
Platform Operations
Incident Response and Breach Notification Policy
How ImpactMiles detects, classifies, contains and reports security and privacy incidents.
- Version
- v1.0
- Effective
- 2026-07-19
- Last reviewed
- 2026-07-19
- Next review
- 2027-07-19
- Owner
- Head of Security
- Approver
- Board of Trustees
Anchored by content hashissued 2026-07-29
Payload hash
5cacb1aa633bad1c612076e47cd733e890c8545acf71183d814fcddcbf571791SHA-256 digest of the receipt content
Issuer AID
EP1_FGkcwfHAuih6VUzv9kgAVBvvSoaswSUao61lkxhEParty that issued this receipt
ImpactMiles handle
audit:governance:5cacb1aa633bad1cThis receipt is anchored by content hash. A resolvable credential SAID is not available for this record.
Applies to
- All systems and data
Jurisdictions
- Hong Kong (PDPO, IRD s.88)
- United Kingdom (UK GDPR, DPA 2018)
- European Union (GDPR)
- Singapore (PDPA)
- Australia (Privacy Act 1988)
- Japan (APPI)
- Wider APAC per country taxonomy
How this is applied in-product
- On-call rotation and paging
- Incident register and post-mortem template
- Regulator notification workflow within statutory deadlines
1. Classification
- SEV1 - confirmed breach of personal data or funds; regulator notification likely.
- SEV2 - service outage affecting core flows for >30 minutes.
- SEV3 - degraded experience with workaround.
2. Notification
- GDPR / UK GDPR: regulator within 72 hours; data subjects without undue delay when high risk.
- PDPO: PCPD notified as soon as practicable for material breaches.
- PDPA (SG): PDPC notified within 3 calendar days for notifiable data breaches.
3. Post-mortem
Blameless post-mortem within 10 business days. Actions tracked to closure. Summary published where public interest justifies.
Questions or concerns about this policy? Contact the DPO.