Data Breach Notification Procedure

How we respond to security incidents and protect your data.

Updated May 20, 2026 Version 1.0

The Spencer Website takes data security seriously. This document outlines our comprehensive procedure for detecting, responding to, and notifying stakeholders about data breaches in compliance with GDPR, CCPA, and other applicable regulations.

Security Incident Reporting: If you believe you have discovered a security vulnerability or data breach, please report it immediately to security@thespencerwebsite.com.

1. Overview

A data breach is any incident that compromises the confidentiality, integrity, or availability of personal data. This includes:

  • Unauthorized access — Hackers gain access to user data
  • Data theft — Personal information is copied or extracted
  • Ransomware — Data is encrypted and held hostage
  • Accidental disclosure — Data is mistakenly exposed to unauthorized parties
  • Loss of devices — Equipment containing user data is lost or stolen

2. Incident Response Process

2.1 Detection and Identification

Security incidents may be detected through:

  • Automated security monitoring systems
  • User reports of suspicious activity
  • Security researcher disclosures (via our bug bounty program)
  • Internal security audits
  • Third-party security services

2.2 Immediate Containment (0-2 Hours)

Upon detection of a potential breach:

  • Activate the Incident Response Team (IRT)
  • Isolate affected systems to prevent further data loss
  • Preserve forensic evidence (logs, system images, network traffic)
  • Change all administrative credentials
  • Document all actions taken

2.3 Investigation and Analysis (2-24 Hours)

During the investigation phase:

  • Determine the scope and nature of the breach
  • Identify what data was accessed or stolen
  • Determine the timeline of the incident
  • Identify affected users and data subjects
  • Assess the root cause and vulnerability exploited

2.4 Eradication and Recovery (24-72 Hours)

Once the breach is understood:

  • Remove the threat and close security vulnerabilities
  • Restore systems from clean backups if necessary
  • Implement additional security measures to prevent recurrence
  • Validate that systems are secure before restoring service

3. Risk Assessment

Before notifying users or regulators, we conduct a risk assessment to determine if the breach poses a risk to individuals' rights and freedoms. Factors considered:

Risk Factor High Risk Indicators Low Risk Indicators
Data Type Financial info, SSN, passwords, health data Usernames, preferences, non-sensitive data
Data Sensitivity Unencrypted, plain text data Encrypted, hashed, or tokenized data
Volume Large-scale breach (1000+ users) Limited scope (few users affected)
Accessibility Data publicly posted or sold Data accessed but not disclosed
Potential Harm Identity theft, financial fraud, harassment Minimal impact on individuals

GDPR Notification Threshold: We must notify supervisory authorities within 72 hours if the breach poses a risk to individuals' rights and freedoms.

4. Notification Timeline

4.1 Regulatory Notification (Within 72 Hours)

If the breach poses a risk to individuals:

  • Notify relevant data protection authorities within 72 hours of becoming aware of the breach
  • Provide detailed information about the nature of the breach, affected data, and mitigation measures
  • Document the reasoning if notification cannot be made within 72 hours

4.2 User Notification (Without Undue Delay)

If the breach poses a high risk to individuals' rights and freedoms:

  • Notify affected users without undue delay
  • Provide clear, plain-language information about the breach
  • Describe the likely consequences and recommended protective measures
  • Contact information for follow-up questions

4.3 Low-Risk Breaches

If the breach poses no risk to individuals (e.g., encrypted data with strong keys, no evidence of access):

  • Document the incident internally
  • Implement preventive measures
  • No user or regulatory notification required

5. User Notification

When user notification is required, we will:

5.1 Notification Methods

  • Email — Primary notification method for all affected users
  • Website banner — Prominent notice on thespencerwebsite.com
  • In-app notification — For logged-in users
  • Press release — For large-scale breaches (media outreach)

5.2 Notification Content

User notifications will include:

  • Description of what happened
  • What data was involved
  • What we are doing to fix it
  • What users should do to protect themselves
  • Contact information for questions and concerns

5.3 Recommended User Actions

Depending on the breach type, we may recommend:

  • Password changes for all accounts
  • Enabling two-factor authentication (if available)
  • Monitoring financial statements for fraudulent activity
  • Placing fraud alerts with credit bureaus
  • Being cautious of phishing attempts using breach data

6. Regulatory Notification

6.1 Authorities Notified

Depending on the breach scope and user locations, we may notify:

  • GDPR Supervisory Authorities — For EU data subjects
  • State Attorneys General — For US state breach law compliance
  • Federal Trade Commission (FTC) — For US federal compliance
  • Information Commissioner's Office (ICO) — UK data protection authority
  • Other relevant authorities — Based on user locations

6.2 Notification Content

Regulatory notifications include:

  • Nature of the breach
  • Categories and approximate number of data subjects concerned
  • Categories and approximate number of personal data records concerned
  • Likely consequences of the breach
  • Measures taken to address the breach and mitigate adverse effects
  • Measures proposed to address the breach

7. Post-Incident Review

7.1 Post-Mortem Analysis

Within 30 days of resolving a significant breach:

  • Conduct a thorough post-mortem analysis
  • Document lessons learned and improvement opportunities
  • Update security policies and procedures based on findings
  • Provide additional training to staff if needed

7.2 Security Enhancements

Based on incident findings, we will:

  • Implement additional security controls
  • Enhance monitoring and detection capabilities
  • Update incident response procedures
  • Conduct additional security testing

7.3 Transparency Report

For significant breaches, we may publish a transparency report describing:

  • What happened and when
  • How we responded
  • What we learned
  • What we're doing to prevent future incidents

8. Contact

For questions about this Data Breach Notification Procedure or to report a security incident:

  • Email: security@thespencerwebsite.com
  • Subject line: "Security Incident" or "Breach Procedure Inquiry"
  • Response time: We acknowledge all security reports within 24 hours.