Breach Management Test · Personal data breaches
If you suffered a breach tomorrow, could you prove you acted diligently?
Twelve questions, one per screen. We do not assess your systems: we assess whether you could demonstrate to a court what you already do. At the end you will obtain your Defensibility Index.
What a court looks at
What a Spanish court really looks at after a personal data breach
The breach does not condemn you; the absence of proof of your diligence does. What Spanish Provincial Courts of Appeal weigh when the claims arrive.
What a court looks atBreach Management Test
Twelve questions, one per screen. We do not assess your systems: we assess whether you could demonstrate to a court what you already do. At the end you will obtain your Defensibility Index.
Take the Breach Management Test72-Hour Standby
A protocol you can activate from the first hour: the notification decision, communication to those affected and evidential protection while the clock runs.
See the serviceServices
Demonstrable Diligence File
We build the file that wins the claims: a dated inventory of measures, written protocols, records of decisions and documented training.
See the serviceContractual Liability Allocation
Review and drafting of your data processing agreements, to set out in writing who answers for what in each system.
See the service72-Hour Standby
A protocol you can activate from the first hour: the notification decision, communication to those affected and evidential protection while the clock runs.
See the servicePost-Breach Claims Defence
A single, coordinated defence strategy against serial claims, with costs kept under control.
See the serviceThe case law
Rule A · Article 32 GDPR
The modest measure you can prove is worth more than the investment you cannot evidence.
Courts do not require infallibility, they require demonstrable diligenceRules D and E · Article 5 GDPR
Accountability does not ask you for one more principle: it asks you for proof of all the previous ones.
Complying without being able to prove it is, before a judge, not complyingRule C · Article 82.3 GDPR
The controller's fault is presumed. The only thing that disables it is proof of your diligence, and that proof is not manufactured afterwards.
You start out convicted: the case is won before the breach happensRule B · Articles 28 and 32 GDPR
Before arguing about what measures were in place, a court decides whose duty it was to have them.
The data processing agreement decides who stands in the dockRule F · Article 17 GDPR
Every request handled badly opens a new claim. And every request the claimant cannot evidence is a defence for you.
After the breach come the serial erasure requestsDo you report unpaid debts to credit blacklists? See also the ASNEF Exposure Test