Security

Incident & Personal Data Breach Policy

Detection, containment, assessment, notification and evidence preservation

Certifiedge Internally Approved — Deployment Activation PendingPublic activation is intentionally blocked until verified operator/provider details are configured.

Lifecycle

Detect → contain → classify → investigate → protect people/data → determine notification duties → remediate → review.

Personal-data breach trigger

Where unauthorized access/acquisition creates a real risk of harm, the controller assesses statutory notification obligations. Kenya’s Act provides a 72-hour controller notification timeline from awareness and a processor-to-controller notification expectation without delay and, where reasonably practicable, within 48 hours.

Communications

Notices describe the nature, protective measures and contact point as required. Notifications are not delayed to protect reputation.

Evidence

Incident facts, effects and remedial action are recorded; logs/evidence are access-limited and preserved for investigation.

Exercises

Incident-response exercises and backup/recovery validation are required assurance activities and are not claimed completed unless actually executed.

Questions or requests

Use the Certifiedge contact, complaints or data-rights route appropriate to the issue. Internal policies do not remove rights or remedies available under applicable law.