← Policies & data protection

Incident response plan

What we do if something goes wrong, a suspected breach, an account takeover, a safeguarding disclosure through the platform, or a service outage that affects people's data.

Owner: Be Free Campaign. This document is maintained by the organisation and should be reviewed at least annually.

Who does what

RoleHeld byResponsible for
Incident leadDr Shantanu Kundu MBChB MSc FRSPH FRSAOwns the incident end to end and makes the call on severity
Data protection contactinfo@befreecampaign.orgRegulator and individual notification decisions
Technical responder[named person / supplier]Containment, investigation and fix
Safeguarding lead[named person]Any incident involving a young person's welfare
Communications[named person]Messages to young people, organisations and funders

How to report an incident

  • Anyone, staff, young person, partner organisation or security researcher, can report to info@befreecampaign.org.
  • In-app: use Report a bug, which reaches the team immediately.
  • Report suspicions, not just certainties. A false alarm is always acceptable.
  • We aim to acknowledge a report within [1 working day].

Severity levels

LevelExampleResponse time
CriticalPersonal data of young people exposed or accessed without authorisation; account takeover; live safeguarding riskImmediate, incident lead engaged within [1 hour]
HighA vulnerability that could expose data but no evidence of access; payment system compromiseSame working day
MediumService outage, failed email delivery, data quality error[2 working days]
LowIsolated bug with no data impactNormal support queue

The four steps

  • 1. Contain, cut off access first: revoke sessions and keys, disable the affected feature or account, take the route offline if needed. Preserve logs before changing anything.
  • 2. Assess, what data, whose data, how many people, how it happened, whether it is still happening. Record timings as we go; the log is written during the incident, not afterwards.
  • 3. Notify, see below. Decisions and reasons are recorded even when we decide not to notify.
  • 4. Recover and learn, deploy the fix, verify it, then hold a blame-free review within [10 working days] and record the actions taken.

Who we tell, and when

  • The Information Commissioner's Office within 72 hours of becoming aware, where a personal data breach is likely to result in a risk to people's rights and freedoms.
  • Affected individuals without undue delay where there is a high risk to them, in plain language, saying what happened, what it means for them and what to do.
  • For a young person under 16, we also inform the parent or carer where we hold that contact, and the supporting organisation where there is one.
  • Partner organisations whose cohort data is involved, as their data processing agreement requires.
  • The local authority safeguarding team where a safeguarding threshold is met, following Be Free Campaign's safeguarding procedure.
  • Our payment provider where card or subscription data is implicated.

Preventive controls already in place

  • Passwordless email one-time codes, there is no password database to steal.
  • Access rules enforced in the database itself, so they cannot be bypassed by calling the backend directly.
  • Signed and verified payment webhooks.
  • Automated security and dependency scanning, with findings tracked to closure.
  • Audit logging of administrator actions.

Testing and review

We run a tabletop exercise against this plan at least once a year and review it after every Critical or High incident. Last reviewed: August 2026. Next review due: August 2027.

Draft for review

Anything shown in [square brackets] needs confirming by Be Free Campaign before this is shared with funders, commissioners or an auditor.