How to answer
How quickly will you notify us of a data breach?
The one answer that must match your contract word for word, because the contract is what a court reads.
We notify affected customers without undue delay and within [72] hours of confirming a personal data breach, as set out in our Data Processing Agreement. Notification includes what we know at the time, what we are doing, and what the customer may need to do.
Square brackets are yours to fill in. FillTrust grades an answer like this confirmed in your documents when your documents support it.
- Answered from
- Your Data Processing Agreement, and your incident response plan.
- Evidence to attach
- The notification clause of your DPA. Reviewers frequently quote it back and ask you to confirm.
- Where it is asked
- CAIQ v4.0 · SEF-07SIG LiteISO 27001 Annex A · A.5.26
This is a contractual question wearing a security question's clothes, and it is the clearest case on any questionnaire where the answer should be copied from a document rather than composed.
Your DPA has already answered it. Article 33 of the GDPR requires a processor to notify the controller without undue delay; most DPAs then commit to a specific window, and 72 hours is the common one because it mirrors the controller's own obligation to a supervisory authority. Whatever your DPA says is the answer. If the questionnaire response and the DPA disagree, the DPA governs and the questionnaire has created an inconsistency that a diligent reviewer will notice.
Do not improve on it under pressure. A buyer occasionally pushes for 24 hours. That is a contract negotiation, not a questionnaire answer, and agreeing to it in a spreadsheet cell commits you to something your incident process may not support at 3am on a Sunday. Point at the DPA and let the legal teams talk.
Be precise about the trigger. "Aware of" and "confirmed" differ by however long triage takes, which can be most of a day. Read which one your DPA uses and answer with that phrase exactly.
Say what the notification contains. The stronger answers describe the content: the nature of the incident, the categories of data involved, the likely consequences, the measures taken, and a contact point. This is precisely the list the GDPR sets out, and reflecting it shows the process exists.
Non-personal data. Plenty of what you hold is customer content that is not personal data, and many contracts require notification for incidents affecting it too. If your DPA covers only personal data, and your terms cover the rest, say so in one sentence: reviewers are asking a practical question about being told, not a legal question about categories.
Answer this once, from the contract, and approve it. It is asked on every questionnaire, it never changes between them, and it is the answer where improvisation costs the most.
How this one goes wrong
Specific to this question, not general advice.
- Promising a shorter window than your DPA. Whatever the contract says is what you are held to, and an answer that undercuts it creates a second, tighter obligation.
- Starting the clock at the wrong point. "Within 72 hours of becoming aware" and "within 72 hours of confirming" are different commitments, and your DPA has already chosen one.
- Answering only for personal data. Many contracts also require notification of security incidents affecting customer content that is not personal data.
Asked in the same breath
Do you have a documented incident response plan, and what is your breach notification window?
Incident response
Are background checks performed on employees with access to customer data?
People
Are backups tested by performing restores?
Resilience
Are user access rights reviewed periodically?
Access control