Privacy incident management

Document, assess, and notify privacy incidents within the deadlines required by Law 25 and the GDPR.

2 min read

What is a privacy incident?

A privacy incident is any event involving unauthorized access, unauthorized use, unauthorized disclosure, or loss of personal information. Common examples: an email sent to the wrong recipient, a lost USB drive containing client data, unauthorized access to your CRM, or a ransomware attack. Law 25 requires all incidents to be logged in a register, even those that do not present a serious risk.

Recording an incident

From Operate > Incidents, click New Incident and enter the basic information: date of discovery, description of the event, types of data affected, number of people involved (estimated if necessary). Conformaze guides you through the qualification steps: severity, probability of serious harm, and notification obligation. You can associate the affected assets and processing activities for full traceability.

Risk assessment and notification obligation

Law 25 requires notifying the CAI and the affected individuals when an incident presents a risk of serious harm. Conformaze structures this assessment by jurisdiction. For each incident, you assess the sensitivity of the data, the context of the incident, and the mitigation measures in place. Conformaze calculates the risk level and tells you whether notification is required.

Response actions and templates

Each incident can be associated with structured response actions: internal investigation, notification to affected individuals, notification to the CAI, corrective measures, internal communication. Conformaze offers pre-configured response templates that you can adapt. Automatic routing rules assign actions to the right people based on the incident type.

Incident register and audit trail

The incident register keeps the complete history of each event: timeline, assessments, notifications sent, actions taken, and closing date. This register is your proof of diligence in the event of an investigation. Notification deadlines (72 hours for the CAI under Law 25) are automatically calculated with preventive alerts.

    Privacy incident management — Conformaze Help Center | Conformaze