On the day of the breach nobody has time to decide who decides. And yet that is the first decision, the one that sets the pace of all the others: whether or not to notify the Spanish Data Protection Agency (AEPD), whether or not to tell those affected, and with exactly what content.
The 72-Hour Standby is an annual retainer that fills that gap before anything happens. When it does happen, you make one call and the protocol is triggered: someone decides, someone drafts, and everything that is done is documented and dated while it is being done, not afterwards.
Who it is for
- Companies holding data on a significant number of people that know an incident is a question of when, not of whether.
- Chief executives who do not want to discover on the day itself that the most sensitive decision is left to whoever happens to be available that morning.
- Anyone who has already been through an incident and remembers exactly what improvising cost.
- Organisations without an in-house legal team able to hold three fronts at once with a clock running on each of them.
What it includes, exactly
- A written, signed protocol, before the incident. Who decides on notification, who drafts it, who speaks to those affected and within what deadline each of them acts.
- An activation line throughout the year. A single point of contact to set the protocol in motion, without hunting for anyone or explaining the case from scratch.
- Decision on notifying the AEPD. Analysis of the case and a reasoned decision in writing, whether or not notification is given. A decision not to notify must also be capable of being justified.
- Communication to those affected. Drafting of the text sent to them, measured word by word: it is the document the other side will use later.
- Evidence secured from the first hour. A dated record of what was known, when it was known, what was decided and who decided it.
- Annual dry run. One dry activation a year to check that the protocol works with the people who hold the posts today.
Which rule it addresses
Rule C — Fault is presumed. To be exonerated you will have to prove the appropriate diligence measures, including those aimed at preventing identity impersonation, under SAP Madrid 273/2024 (Article 82.3 GDPR). Every improvised hour is an hour without a documentary trail, and what leaves no trail cannot be argued.
Rule D — Accountability. The burden of demonstrating diligence falls on you, and half the evidence in the future case is created in those first hours:
And, under Article 5.2 GDPR, “the controller shall be responsible for compliance with the provisions of paragraph 1 and be able to demonstrate it (accountability)”. [translation]
Deliverables
- Written response protocol, signed and distributed to those who must carry it out.
- Decision table with names, deputies and deadlines.
- Templates for notification to the AEPD and for communication to those affected, ready to adapt within hours.
- Chronological incident log template, to document while it happens.
- Closing report for each activation, which is then added to your evidence file.
- Minutes of the annual dry run.
Indicative timescale
The protocol is operational within two or three weeks of engagement. From then on, the standby is live for the twelve months of the retainer and activation is immediate.
This service covers the response. The evidence that will support that response is built beforehand: see the Demonstrable Diligence File, measure your current position with the Breach Management Test and understand the judicial approach in what a court really looks at after a breach.
72-Hour Standby
If the incident has already happened, write to us and say so in the subject line. If it has not, this is the best moment to settle who decides.
Talk to ILP Abogados