← Governance framework
Platform Operations

Incident Response and Breach Notification Policy

How ImpactMiles detects, classifies, contains and reports security and privacy incidents.

Version
v1.0
Effective
2026-07-19
Last reviewed
2026-07-19
Next review
2027-07-19
Owner
Head of Security
Approver
Board of Trustees
Anchored by content hashissued 2026-07-29
Payload hash
5cacb1aa633bad1c612076e47cd733e890c8545acf71183d814fcddcbf571791
SHA-256 digest of the receipt content
Issuer AID
EP1_FGkcwfHAuih6VUzv9kgAVBvvSoaswSUao61lkxhE
Party that issued this receipt
ImpactMiles handle
audit:governance:5cacb1aa633bad1c

This receipt is anchored by content hash. A resolvable credential SAID is not available for this record.

Applies to

  • All systems and data

Jurisdictions

  • Hong Kong (PDPO, IRD s.88)
  • United Kingdom (UK GDPR, DPA 2018)
  • European Union (GDPR)
  • Singapore (PDPA)
  • Australia (Privacy Act 1988)
  • Japan (APPI)
  • Wider APAC per country taxonomy

How this is applied in-product

  • On-call rotation and paging
  • Incident register and post-mortem template
  • Regulator notification workflow within statutory deadlines

1. Classification

  • SEV1 - confirmed breach of personal data or funds; regulator notification likely.
  • SEV2 - service outage affecting core flows for >30 minutes.
  • SEV3 - degraded experience with workaround.

2. Notification

  • GDPR / UK GDPR: regulator within 72 hours; data subjects without undue delay when high risk.
  • PDPO: PCPD notified as soon as practicable for material breaches.
  • PDPA (SG): PDPC notified within 3 calendar days for notifiable data breaches.

3. Post-mortem

Blameless post-mortem within 10 business days. Actions tracked to closure. Summary published where public interest justifies.

Questions or concerns about this policy? Contact the DPO.

Related policies