Lifecycle
Detect → contain → classify → investigate → protect people/data → determine notification duties → remediate → review.
Personal-data breach trigger
Where unauthorized access/acquisition creates a real risk of harm, the controller assesses statutory notification obligations. Kenya’s Act provides a 72-hour controller notification timeline from awareness and a processor-to-controller notification expectation without delay and, where reasonably practicable, within 48 hours.
Communications
Notices describe the nature, protective measures and contact point as required. Notifications are not delayed to protect reputation.
Evidence
Incident facts, effects and remedial action are recorded; logs/evidence are access-limited and preserved for investigation.
Exercises
Incident-response exercises and backup/recovery validation are required assurance activities and are not claimed completed unless actually executed.
Questions or requests
Use the Certifiedge contact, complaints or data-rights route appropriate to the issue. Internal policies do not remove rights or remedies available under applicable law.