1. Contain and preserve evidence
We first limit ongoing exposure, preserve relevant logs and evidence, identify affected systems and prevent unnecessary further processing. Credentials, sessions or integrations may be revoked where appropriate.
2. Assess the facts and risk
We record what happened, when we became aware, the data and people potentially affected, likely consequences, containment actions and the likelihood and severity of harm to individuals.
3. Decide whether notification is required
If a personal data breach is likely to result in a risk to people's rights and freedoms, the operator will notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware. If the risk is likely to be high, affected individuals will also be informed without undue delay.
4. Record the decision
Every confirmed personal data breach must be documented, including incidents that do not meet the threshold for ICO notification. The record includes the facts, effects, remedial action and the reason for the reporting decision.
5. Recover and learn
We restore normal service safely, validate corrective actions, review whether controls should change and record lessons learned. Provider or processor incidents are handled alongside the relevant contractual notification obligations.
Report a security concern
Security concerns should be reported privately to admin@buildpilotai.co.uk. Please provide enough information for investigation but do not send passwords, payment-card security codes or unnecessary sensitive information.