How to answer
Do you have a documented incident response plan, and what is your breach notification window?
Two questions in one, and the second half, the notification window, is the one with contractual teeth. It comes from your DPA, not from GDPR.
Yes. We maintain a documented incident response plan covering detection, triage, containment, notification and post-incident review. It is reviewed annually and exercised at least once a year; the most recent exercise was [month, year]. Under our DPA we notify affected customers without undue delay and within [72] hours of confirming a breach.
Square brackets are yours to fill in. FillTrust grades an answer like this confirmed in your documents when your documents support it.
- Answered from
- Your incident response plan for the process, and your DPA for the notification window. These are two different documents and the answer needs both.
- Evidence to attach
- Rarely the plan itself. More often the date of the last tabletop exercise.
- Where it is asked
- CAIQ v4.0 · SEF-03SIG LiteISO 27001 Annex A · A.5.24
This arrives as one cell and contains two questions with different sources, and answering only the first is the most common failure.
The plan. A reviewer wants to know that a named person is responsible, that there is a defined path from detection to containment, and that it does not depend on one engineer being awake. If your plan exists and covers detection, triage, containment, notification and a post-incident review, say so in those terms. The vocabulary itself signals a real plan rather than a paragraph written for an audit.
Then say when it was last exercised. "Documented" and "tested" are separate claims, and the second is increasingly what is being asked. A tabletop exercise is an hour in a room; having a date for one is disproportionately convincing relative to its cost.
The notification window is where answers go wrong, and the mistake is a specific and understandable one. Teams write 72 hours because they have read that GDPR requires notification within 72 hours. But Article 33 is the controller's obligation to notify a supervisory authority. As a processor, your obligation is Article 33(2), notify the controller without undue delay, and what you actually owe your customer is whatever your DPA says. Some DPAs say 72 hours, some say 48, some say without undue delay with no number at all.
So read your own DPA and quote it. If it does not contain a window, that is a real gap in the contract rather than a wording problem in the questionnaire, and the answer should not invent one. A number in a questionnaire that your contract does not support is a commitment you have made without noticing.
How this one goes wrong
Specific to this question, not general advice.
- Answering only the first half. The question has two parts and the notification window is the one with contractual teeth.
- Quoting 72 hours because GDPR says so. Article 33 is a controller's obligation to a regulator; what you owe your customer is whatever your DPA says, and those are often different.
- A plan that has never been exercised. "Documented" and "tested" are separate claims and reviewers increasingly ask for the second.