DNZ Consulting LLC · Effective August 27, 2026 · Next review August 27, 2027
This policy states what DNZ Consulting LLC does when a security incident or a personal data breach happens.
1. Scope and ownership
This policy applies to every system, device, and person that DNZ Consulting LLC uses to do business. DNZ Consulting LLC is a small company. The Managing Member owns this policy. The Managing Member also acts as the Security Officer and the Data Protection Officer.
The Managing Member reviews this policy one time each year. The Managing Member also reviews it after any security incident.
2. What counts as an incident
Somebody reaches a system or data without authority.
Personal data goes to the wrong person, or becomes public.
A device that holds company data is lost or stolen.
Malware runs on an endpoint or a server.
A credential, key, or token leaks.
A supplier tells us that they had a breach that touches our data.
3. Roles
Role
Who
Responsibility
Incident Manager
Managing Member
Declares the incident. Runs the response. Makes every decision.
Security Officer
Managing Member
Contains and investigates the incident. Collects evidence.
Data Protection Officer
Managing Member
Decides on regulator and customer notification. Answers data subjects.
Communications
Managing Member
Writes and sends every external message.
The company is small, so one person holds these roles. The company appoints a
second responder in writing if it grows.
Report within 1 hour of discovery. Report a suspicion. Do not wait for proof.
Anyone may report: a worker, a merchant, a platform, a supplier, or a member of the public.
5. Response steps
Record. Write down the time, the reporter, and what they saw.
Assess. Decide the severity within 4 hours. Decide whether personal data is involved.
Contain. Isolate the system. Revoke the credential. Rotate the key. Block the account.
Investigate. Find the cause and the scope. Identify every record that the incident touched.
Notify. Follow section 6.
Recover. Restore the service from a clean state. Confirm that the attacker is out.
Review. Hold a review within 10 working days. Write the lessons. Change the controls.
6. Notification
We notify the affected platform and the affected merchants without undue delay, and within 24 hours of confirming a breach that touches their data.
We notify a supervisory authority within 72 hours where the law requires it.
We notify affected individuals without undue delay when the breach creates a high risk to them.
Every notification states what happened, what data it touched, what we did, and what the reader should do.
We give a contact point for questions in every notification.
7. Records
We record every incident, including the ones that need no notification. We keep the
record for 5 years. The record holds the facts, the effect, and the action we took.
8. Testing
We walk through this plan one time each year with a test scenario. We record the
result and we fix any gap.
9. Review
The Managing Member reviews this policy one time each year, and after every incident.