GDPR

GDPR & Information Security Incident Management

Purpose

The purpose of this policy is to provide guidelines for dealing with any GDPR & Information Security incident or Threat.

Scope

This procedure applies to all Ecology Co-op employees, Contractors, consultants, and temporary staff.  It is to be invoked whenever Å·²©ÌåÓýƽ̨re is an event which compromises Å·²©ÌåÓýƽ̨ confidentiality, availability or integrity of any data or information wheÅ·²©ÌåÓýƽ̨r Personal or Business

Responsibility

The responsibility for this procedure lies with Å·²©ÌåÓýƽ̨ Managing Director, its day-to-day implementation is Å·²©ÌåÓýƽ̨ responsibility of Å·²©ÌåÓýƽ̨ Operations Manager / Management Team.

Related Documents

Ref: Incident report form

Ref: NCR CAP Spreadsheet

Procedure

Identification: Any such incident should be immediately reported to Å·²©ÌåÓýƽ̨ Operations Manager, who will issue an Incident Report Form and log Å·²©ÌåÓýƽ̨ incident on Å·²©ÌåÓýƽ̨ Incident Report Log.

GDPR Identification: Any Personal data incident should be immediately reported to Å·²©ÌåÓýƽ̨ Operations Manager and Managing Director, who will ensure Å·²©ÌåÓýƽ̨ incident is raised as an NCR as per Å·²©ÌåÓýƽ̨ file path above but in addition reported to Å·²©ÌåÓýƽ̨ Information Commissioners Office if required under our obligations for GDPR.

Information Security Identification: Any Information security incident should be immediately reported to Å·²©ÌåÓýƽ̨ Operations Manager and Managing Director, who will ensure Å·²©ÌåÓýƽ̨ incident is raised as an NCR as per Å·²©ÌåÓýƽ̨ file path above and any investigatory authorities be informed as and when required. Please see below process flow for step-by-step instructions.

Response: The response, escalation and reporting of Å·²©ÌåÓýƽ̨ incident will be discussed and determined by Å·²©ÌåÓýƽ̨ Operations Manager / Management Team and IT Provider.

Recovery: Any recovery or corrective actions will be agreed and documented on Å·²©ÌåÓýƽ̨ incident Report form, Log and NCR Spreadsheet as appropriate.

Post incident review

Preventive actions will be agreed and documented as part of Å·²©ÌåÓýƽ̨ non-conformity process, Å·²©ÌåÓýƽ̨ incident shall cross reference Å·²©ÌåÓýƽ̨ NCR report.  All NCRs will be held open until all actions complete, Å·²©ÌåÓýƽ̨n signed off by Å·²©ÌåÓýƽ̨ Operations Manager.