Cybersecurity & Data Protection

Data Breach Support

When a personal-data breach is suspected, we help privacy, legal and incident teams establish which systems, records and people may be affected, and we document the evidence, the assumptions and what is still unknown.

AploIQ supports the technical scoping of a potential personal-data breach, the analysis of potentially affected systems, people and data, and the evidence record for the decision-makers. Notification, controller, DPO and legal decisions remain with the responsible functions.

  • We prepare the technical and affected-data evidence. Whether to notify, and every decision that belongs to the controller, the DPO or legal counsel, stays with them.

When breach facts are incomplete

  • The affected systems, accounts or repositories have not yet been identified and narrowed.
  • Which people, records and personal-data categories are affected is unclear.
  • Technical findings, response actions and privacy questions sit in separate records with no shared chronology.
  • The decision-makers need a traceable evidence basis, and the timetable is short.

What we do

Technical incident boundary

Map the systems, accounts, time windows and access paths with the incident team, and the evidence that exists for each.

Affected-data review

Identify the candidate data stores, set the review criteria, and analyse the people, records and data categories potentially affected.

Incident evidence record

Keep a chronology of the technical findings, the assumptions, the open questions and the evidence references.

Decision support pack

Organise the technical and data findings for the controller, the DPO and legal counsel.

What you receive

  • Affected-system and account matrix
  • Matrix of potentially affected people, records and data categories
  • Incident chronology, evidence log and open-question register
  • Decision-support pack with stated limitations

How we work

  1. Define the technical scope

    Agree what is known, which systems may be involved, and which records can test the current view.

  2. Review potentially affected data

    Narrow the population by agreed criteria, and document uncertainty instead of presenting estimates as facts.

  3. Maintain the decision record

    Keep a current record of findings, changes, evidence gaps and open questions against the response deadlines.

How to start

Send a brief, non-sensitive note with the event date, the systems potentially affected, the current incident owner and the decision timetable. Do not attach logs, personal data or draft notifications.

Discuss a potential breach

Technical support and breach decisions

  • Does AploIQ decide whether notification is required?

    No. We establish the technical and affected-data facts. The controller, the DPO and legal counsel make the notification and regulatory decisions.