Data Breach Procedure
1. Objective
The purpose of this document is to establish an authoritative, time-critical operational protocol for identifying, triaging, containing, and reporting personal data breaches. This procedure ensures that anDREa B.V. (hereafter "anDREa") minimizes organizational blast radius, mitigates risk to data subjects, and fulfills its strict statutory notification obligations under the General Data Protection Regulation (GDPR) and the European Union NIS 2 Directive.
2. Scope
This procedure applies universally to all internal personnel, executive directors, external partners, contractors, software tenants, and system users handling data within the anDREa ISMS perimeter. It operates as an extension of the core Data Protection Policy and covers all categories of processed user and research datasets.
3. Availability and Access
This document is:
- Required reading for all anDREa employees and contractors.
- Available to all authorized interested parties and platform users via our public ISMS repository.
4. Definitional Boundary
- Personal Data Breach: Any verified or suspected security anomaly leading to the accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure of, or administrative access to personal or special category data transmitted, stored, or otherwise processed within the platform cloud fabric.
5. Sequential Data Breach Lifecycle Management
[Phase 1: Identification & Taxonomy Routing]
│
▼
[Phase 2: DPO Investigation (Within 48 Hours)]
│
▼
[Phase 3: Impact Assessment & Response Activation]
│
▼
[Phase 4 & 5: Recovery & Statutory Notification (Within 72 Hours)]
│
▼
[Phase 6: Post-Incident Evaluation & Review]
Phase 1: Identification, Taxonomy, and Immediate Reporting
Every observed or suspected security anomaly—regardless of apparent scale, impact, or immediate harm—must be identified and reported immediately.
Upon discovery, the reporter must immediately classify the event into one of three specific operational tracks and execute the corresponding communication route:
-
Category 1: anDREa Identity/User Data Compromise (e.g., compromised
@mydre.orgcorporate or platform user accounts). -
Action: Escalate directly to the anDREa Director immediately.
-
Category 2: Tenant Workspace Infiltration (e.g., data accessed or accessible by unauthorized individuals or services within a specific
myDREWorkspace boundary). -
Action: Escalate directly to the anDREa Director immediately.
-
Category 3: External Institutional Dataset Exposure (e.g., study or clinical data accessed outside of a defined workspace perimeter).
-
Action: Route immediately to the designated security contact of the responsible Tenant organization or the data owner. If contact cannot be established, escalate immediately to the anDREa Director.
Reporting Execution Mechanisms
For Categories 1 and 2, internal or external personnel must immediately file a report through one of the following official intake channels:
- Submit an emergency entry via the designated internal Google Form.
- Generate an authenticated priority ticket through the support ecosystem (Issues and Risk Logging).
Note on Voluntarily Assigned Governance Roles: While anDREa is not legally mandated to maintain a dedicated Data Protection Officer (DPO) under baseline corporate sizing rules, the organization has voluntarily assigned full DPO responsibilities to the anDREa Director to align with industry best practices.
Phase 2: Accelerated Forensic Investigation
- Operational Constraint: Upon receipt of a breach ticket, the Director (acting as DPO) will immediately initiate a formal forensic investigation.
- Timeline Threshold: The technical investigation must conclude within 48 hours of initial intake. This internal limit provides a vital buffer to safely satisfy the statutory 72-hour regulatory reporting deadline for serious security incidents.
- Policy Enforcement: Bypassing, delaying, or failing to report a suspected or verified data breach to the Director will trigger immediate investigation under the Workplace Behavior & Disciplinary Action Policy, up to and including immediate termination of contract or employment.
Phase 3: Risk Assessment and Response Team Activation
- Log Enforcement: If the initial 48-hour investigation confirms that a personal data breach has occurred, the Director will formally log the event within the master Data Breach Register.
- Severity Classification: The Director executes a comprehensive risk assessment to determine the threat level, evaluating potential harm to data subject rights and freedoms, exposure of special category medical data, and technical scope.
- Response Team Assembly: Based on the severity matrix, the Director will notify executive leadership and activate a cross-functional Cyber Incident Response Team (CIRT). This team draws dedicated personnel from HR, Technical Support, and Platform Development to isolate system perimeters.
- Reputational Triage: For high-severity breaches, the Director and executive management will activate corporate trust-preservation protocols to manage institutional reputation and client transparency.
Phase 4: Formulating a Technical Recovery Plan
The Director and the active CIRT will formulate a customized technical recovery plan to isolate the incident's blast radius and safeguard surviving infrastructure. This plan includes:
- Executing emergency configuration locks, token revocations, or network quarantines as outlined in the Contingency Plans.
- Conducting formal investigative interviews with key personnel involved in the lifecycle of the anomaly to identify root causes and track data exposure lines.
Phase 5: Regulatory and Statutory Notifications (72-Hour AP Limit)
- Regulatory Authority Notification: Unless the data breach is demonstrably unlikely to result in a risk to the rights and freedoms of natural persons, the Director holds sole, exclusive authority to draft and submit the formal notification to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens - AP). This submission must occur within 72 hours of anDREa becoming aware of the breach.
- Data Subject Notification: If the breach is assessed as introducing a high risk to individual privacy or safety, anDREa will notify the affected data subjects immediately, utilizing clear, plain, and transparent language.
- Corporate Updates: The Director will continuously monitor the forensic loop and provide incremental update reports to the AP, the internal Board of Directors, and organizational shareholders as new telemetry emerges.
Phase 6. Post-Incident Evaluation & Preventive Engineering
To ensure continuous compliance under ISO/IEC 27001:2023 Control A.08.28 (Learning from information security incidents), every breach cycle requires a formal post-mortem review:
- The Director and the Senior Leadership Team will execute an objective critique to evaluate the speed, accuracy, and containment effectiveness of the corporate response.
- All findings, structural root causes, and remediation milestones must be appended to the master Data Breach Register.
- Any identified architectural flaws, code vulnerabilities, or process deficiencies will trigger mandatory updates to platform policies, system configuration baselines, or employee training modules to prevent future recurrence.