Skip to main content

Breach Management Test · Personal data breaches

If you suffered a breach tomorrow, could you prove you acted diligently?

Twelve questions, one per screen. We do not assess your systems: we assess whether you could demonstrate to a court what you already do. At the end you will obtain your Defensibility Index.

Take the Breach Management Test

What a court looks at

What a Spanish court really looks at after a personal data breach

The breach does not condemn you; the absence of proof of your diligence does. What Spanish Provincial Courts of Appeal weigh when the claims arrive.

What a court looks at

Breach Management Test

Twelve questions, one per screen. We do not assess your systems: we assess whether you could demonstrate to a court what you already do. At the end you will obtain your Defensibility Index.

Take the Breach Management Test

72-Hour Standby

A protocol you can activate from the first hour: the notification decision, communication to those affected and evidential protection while the clock runs.

See the service

Services

Demonstrable Diligence File

We build the file that wins the claims: a dated inventory of measures, written protocols, records of decisions and documented training.

See the service

Contractual Liability Allocation

Review and drafting of your data processing agreements, to set out in writing who answers for what in each system.

See the service

72-Hour Standby

A protocol you can activate from the first hour: the notification decision, communication to those affected and evidential protection while the clock runs.

See the service

Post-Breach Claims Defence

A single, coordinated defence strategy against serial claims, with costs kept under control.

See the service

The case law

Rule A · Article 32 GDPR

The modest measure you can prove is worth more than the investment you cannot evidence.

Courts do not require infallibility, they require demonstrable diligence

Rules D and E · Article 5 GDPR

Accountability does not ask you for one more principle: it asks you for proof of all the previous ones.

Complying without being able to prove it is, before a judge, not complying

Rule C · Article 82.3 GDPR

The controller's fault is presumed. The only thing that disables it is proof of your diligence, and that proof is not manufactured afterwards.

You start out convicted: the case is won before the breach happens

Rule B · Articles 28 and 32 GDPR

Before arguing about what measures were in place, a court decides whose duty it was to have them.

The data processing agreement decides who stands in the dock

Rule F · Article 17 GDPR

Every request handled badly opens a new claim. And every request the claimant cannot evidence is a defence for you.

After the breach come the serial erasure requests

Do you report unpaid debts to credit blacklists? See also the ASNEF Exposure Test