← Policies & data protection
Incident response plan
What we do if something goes wrong, a suspected breach, an account takeover, a safeguarding disclosure through the platform, or a service outage that affects people's data.
Owner: Be Free Campaign. This document is maintained by the organisation and should be reviewed at least annually.
Who does what
| Role | Held by | Responsible for |
|---|---|---|
| Incident lead | Dr Shantanu Kundu MBChB MSc FRSPH FRSA | Owns the incident end to end and makes the call on severity |
| Data protection contact | info@befreecampaign.org | Regulator and individual notification decisions |
| Technical responder | [named person / supplier] | Containment, investigation and fix |
| Safeguarding lead | [named person] | Any incident involving a young person's welfare |
| Communications | [named person] | Messages to young people, organisations and funders |
How to report an incident
- Anyone, staff, young person, partner organisation or security researcher, can report to info@befreecampaign.org.
- In-app: use Report a bug, which reaches the team immediately.
- Report suspicions, not just certainties. A false alarm is always acceptable.
- We aim to acknowledge a report within [1 working day].
Severity levels
| Level | Example | Response time |
|---|---|---|
| Critical | Personal data of young people exposed or accessed without authorisation; account takeover; live safeguarding risk | Immediate, incident lead engaged within [1 hour] |
| High | A vulnerability that could expose data but no evidence of access; payment system compromise | Same working day |
| Medium | Service outage, failed email delivery, data quality error | [2 working days] |
| Low | Isolated bug with no data impact | Normal support queue |
The four steps
- 1. Contain, cut off access first: revoke sessions and keys, disable the affected feature or account, take the route offline if needed. Preserve logs before changing anything.
- 2. Assess, what data, whose data, how many people, how it happened, whether it is still happening. Record timings as we go; the log is written during the incident, not afterwards.
- 3. Notify, see below. Decisions and reasons are recorded even when we decide not to notify.
- 4. Recover and learn, deploy the fix, verify it, then hold a blame-free review within [10 working days] and record the actions taken.
Who we tell, and when
- The Information Commissioner's Office within 72 hours of becoming aware, where a personal data breach is likely to result in a risk to people's rights and freedoms.
- Affected individuals without undue delay where there is a high risk to them, in plain language, saying what happened, what it means for them and what to do.
- For a young person under 16, we also inform the parent or carer where we hold that contact, and the supporting organisation where there is one.
- Partner organisations whose cohort data is involved, as their data processing agreement requires.
- The local authority safeguarding team where a safeguarding threshold is met, following Be Free Campaign's safeguarding procedure.
- Our payment provider where card or subscription data is implicated.
Preventive controls already in place
- Passwordless email one-time codes, there is no password database to steal.
- Access rules enforced in the database itself, so they cannot be bypassed by calling the backend directly.
- Signed and verified payment webhooks.
- Automated security and dependency scanning, with findings tracked to closure.
- Audit logging of administrator actions.
Testing and review
We run a tabletop exercise against this plan at least once a year and review it after every Critical or High incident. Last reviewed: August 2026. Next review due: August 2027.
Draft for review
Anything shown in [square brackets] needs confirming by Be Free Campaign before this is shared with funders, commissioners or an auditor.