What if CertNudge ever suffers a data breach?

Security, Privacy & Data Protection

CertNudge will investigate, contain and assess any suspected personal-data breach or security incident.

The actions taken, notifications required and timing will depend on the circumstances, the risks involved and the applicable legal requirements.

Not every security incident is a reportable breach

CertNudge must first investigate what happened, which information may be affected and the likely risk to the people involved.

How would CertNudge respond?

1

Investigate the incident

CertNudge would review the available information to understand what happened and which systems, accounts or records may be affected.

2

Contain the issue

Appropriate steps would be taken to limit further access, loss or misuse while the investigation continues.

3

Assess the risk

CertNudge would assess the type of information involved, the possible consequences and the level of risk to affected people.

4

Take required follow-up action

This may include remediation, notifications and additional account or security measures where appropriate.

Would the ICO be notified?

CertNudge will notify the Information Commissioner's Office when notification is required by applicable data-protection law.

The applicable deadline and information provided will depend on the incident and its legal assessment.

Not every security event or suspected incident requires an ICO notification.

Would affected users be contacted?

CertNudge will contact affected people when this is required by law or is otherwise appropriate to help them understand and reduce a meaningful risk.

The response will depend on the incident

CertNudge does not promise that every incident will result in notification to every user, a public report or a mandatory password reset. Those actions will be considered where relevant to the circumstances.

Report suspected unauthorised access promptly

Email support@certnudge.co.uk with your organisation name and a description of the concern. Do not send passwords, recovery codes, full card details or unnecessary tenant personal data.

Was this helpful?
Share this FAQ