Incident and Breach Response Policy
Last updated: · Effective date:
This Incident and Breach Response Policy explains how Dutiva Canada Inc. ("Dutiva," "we," "us," or "our") identifies, escalates, contains, assesses, documents, communicates, and learns from security incidents, privacy breaches, confidentiality incidents, and related provider incidents involving Dutiva systems or personal information.
This Policy should be read with Dutiva's Privacy Policy, Data Processing Agreement, Data Retention and Deletion Policy, Terms of Service, AI Usage Disclosure, AI & Technology Policy, and any applicable subscription or order terms.
1. Scope and Definitions
This Policy applies to suspected or confirmed incidents involving Dutiva systems, production infrastructure, authentication systems, provider credentials, customer data, personal information, generated documents, Advisor processing, AI model-provider requests, electronic-signature workflows, payment-related integrations, support systems, subprocessors, or related operational records.
For this Policy, a security incident means an event that may compromise the confidentiality, integrity, availability, or resilience of Dutiva systems, data, accounts, credentials, workflows, or infrastructure. A privacy breach means loss of, unauthorized access to, unauthorized disclosure of, or unauthorized use of personal information. Under PIPEDA, this may be described as a breach of security safeguards. For Quebec personal information, this may be described as a confidentiality incident.
Not every security event is a reportable privacy breach. Dutiva assesses each incident based on the information involved, likelihood of misuse, affected individuals or customers, legal thresholds, contractual obligations, and the steps needed to reduce harm and prevent recurrence.
2. Response Roles
Dutiva assigns response responsibilities based on the incident type, severity, affected systems, and personal-information impact. The following roles may be involved:
- Incident Lead: coordinates triage, containment, investigation, status updates, decision logging, and post-incident review.
- Privacy Officer: assesses personal-information impact, notification duties, privacy-risk thresholds, breach records, confidentiality-incident registers, and regulator communications.
- Engineering Owner: investigates technical cause, reviews logs, rotates credentials, patches code, validates fixes, and verifies remediation.
- Customer Communications Owner: prepares customer-facing updates, support guidance, affected-user notices, and follow-up messaging where required.
- Legal Counsel: reviews high-risk notifications, regulator filings, contractual duties, evidence preservation, privilege considerations, and litigation or tribunal exposure.
- Executive Sponsor, where needed: supports priority decisions, customer-impact decisions, resource allocation, and external communications for material incidents.
3. Response Phases
Dutiva's incident response process generally follows these phases. Some phases may run in parallel where urgency requires immediate containment or notification support:
- Detect: receive and review signals from monitoring, logs, provider alerts, users, support tickets, security researchers, internal review, or unusual service behaviour.
- Triage: classify severity, systems affected, data categories, customer impact, individual impact, active exploitation risk, provider involvement, and whether personal information may be involved.
- Contain: revoke or rotate credentials, isolate systems, disable affected features, block abusive traffic, suspend risky processing, apply emergency fixes, or preserve affected workflows while preventing further harm.
- Investigate: preserve relevant evidence, identify root cause, determine affected records, estimate affected individuals or customers, reconstruct the timeline, and confirm whether a provider or subprocessor was involved.
- Assess: determine legal, privacy, contractual, customer, operational, security, and reputational implications, including whether notification thresholds are met.
- Notify: provide notices to customers, regulators, affected individuals, providers, insurers, law enforcement, or other parties where required or appropriate.
- Recover: restore service, validate fixes, monitor for recurrence, update safeguards, and move the incident to post-incident review once operationally stable.
- Improve: track corrective actions, policy updates, technical changes, training needs, and product or process changes separately from the incident record.
4. Timing Standards
Dutiva treats potential security incidents and privacy incidents as urgent. Where feasible, Dutiva targets initial triage within 24 hours of discovery and an initial privacy or legal notification assessment within 72 hours after confirming that personal information may be involved.
These timing standards are internal escalation targets. They do not replace legal or contractual requirements, and they may vary depending on incident complexity, evidence availability, provider involvement, law-enforcement restrictions, or the need to prevent additional harm.
Under PIPEDA, reportable breaches must be reported to the Office of the Privacy Commissioner of Canada and affected individuals must be notified as soon as feasible after Dutiva determines that the breach creates a real risk of significant harm. Quebec confidentiality incidents that present a risk of serious injury must be reported to the Commission d'accès à l'information du Québec and affected persons with diligence, subject to applicable investigation limits.
5. PIPEDA Breach Assessment
For personal information under Dutiva's control, Dutiva assesses whether a breach of security safeguards creates a real risk of significant harm by considering the sensitivity of the personal information involved and the probability that the information has been, is being, or will be misused. Dutiva may also consider the circumstances of the breach, exposure duration, threat actor indicators, mitigation already taken, likelihood of identity theft, financial loss, humiliation, reputational harm, employment harm, or other reasonably foreseeable harms.
Where Dutiva determines that the real-risk-of-significant-harm threshold is met, Dutiva will:
- report the breach to the Office of the Privacy Commissioner of Canada as soon as feasible;
- notify affected individuals as soon as feasible unless prohibited by law;
- notify other organizations or government institutions where appropriate and where doing so may reduce or mitigate harm;
- provide notice content required by applicable law and information reasonably useful for affected individuals to reduce risk;
- keep records of every breach of security safeguards for at least 24 months after the day Dutiva determines that the breach occurred, unless a longer period is required or reasonably necessary.
6. Quebec Confidentiality Incidents
For Quebec personal information, Dutiva assesses whether a confidentiality incident presents a risk of serious injury. The assessment considers, among other factors, the sensitivity of the personal information, the anticipated consequences of its use, and the likelihood that the information will be used for injurious purposes. Dutiva consults the Privacy Officer as part of this assessment where required or appropriate.
Where Dutiva determines that the risk-of-serious-injury threshold is met, Dutiva will:
- notify the Commission d'accès à l'information du Québec with diligence;
- notify affected persons with diligence unless doing so could hamper an investigation carried out under law to prevent, detect, or repress crime or offences under law;
- take reasonable measures to reduce the risk of injury and prevent new incidents of the same nature;
- provide supplementary information to the Commission d'accès à l'information du Québec with diligence if Dutiva becomes aware of additional required information after the initial notice;
- record the incident in Dutiva's confidentiality-incident register; and
- retain Quebec confidentiality-incident register entries for at least five years after the date or period on which Dutiva became aware of the incident.
7. Customer and Processor Notifications
Where Dutiva processes Customer Personal Information on behalf of a customer, Dutiva will notify the affected customer without undue delay after Dutiva confirms an incident involving Customer Personal Information that requires customer action, notification support, or contractual escalation.
Customer notices will include information reasonably available to Dutiva, which may include the nature of the incident, known or estimated timing, affected systems, affected data categories, containment and remediation steps taken, recommended customer actions, whether regulator or individual notification may be required, and the Dutiva contact point for follow-up.
Where the customer is responsible for the underlying personal information, the customer remains responsible for assessing and meeting its own notification, recordkeeping, employee, regulator, contractual, and workplace obligations. Dutiva will provide reasonable cooperation through available product, support, legal, and technical channels.
8. Provider and Subprocessor Incidents
Some incidents may originate from or involve a service provider, subprocessor, model provider, payment provider, hosting provider, security provider, analytics provider where enabled, or other third-party system used to provide Dutiva.
When Dutiva receives notice of a provider incident, Dutiva will assess the incident in the context of Dutiva's service, determine whether Dutiva systems, Customer Data, or personal information may be affected, request information reasonably needed for Dutiva's assessment, and coordinate customer or regulator communications where required.
A provider outage, vulnerability, or security event does not automatically mean that Dutiva personal information was affected. Dutiva will assess the available facts before communicating confirmed personal-information impact, while providing timely operational updates where appropriate.
9. Communications and Notice Content
Incident communications should be accurate, proportionate, timely, and based on known facts. Dutiva avoids speculation, overstatement, under-disclosure, and unnecessary disclosure of sensitive technical details that could increase security risk.
Depending on the incident and legal requirements, notices may include a description of the incident, the date or period when it occurred, when Dutiva became aware of it, affected data categories, affected individuals or customers, mitigation steps taken, steps individuals or customers can take to reduce risk, whether public notice is used, contact information, and any required regulator filing details.
Dutiva may update incident communications as additional facts are confirmed. Supplemental notices may be provided where required by law, contractual commitments, regulator expectations, or customer-support needs.
10. Incident Records and Retention
Dutiva maintains incident records appropriate to the incident type, severity, legal requirements, and operational need. Incident records may include:
- date discovered, estimated date or period of occurrence, internal timeline, and date Dutiva became aware of the incident;
- systems, providers, subprocessors, customers, individuals, accounts, records, and data categories involved;
- containment, eradication, recovery, monitoring, and mitigation steps taken or planned;
- risk assessment, privacy threshold analysis, notification analysis, notices sent, and regulator filings;
- customer communications, affected-individual communications, public notices, and support guidance where applicable;
- root cause, corrective actions, responsible owners, deadlines, verification evidence, and closure decision.
Incident and breach records are retained according to Dutiva's Data Retention and Deletion Policy and applicable legal requirements, including statutory breach-record and confidentiality-incident register periods.
11. Post-Incident Review and Improvement
After material incidents, Dutiva will conduct a post-incident review to identify root cause, missed signals, delayed decisions, control gaps, vendor issues, training needs, product changes, policy updates, and follow-up owners.
Security fixes and policy updates are tracked separately from the incident so remediation does not depend on memory or informal notes. Dutiva may update safeguards, monitoring, escalation paths, user messaging, provider controls, documentation, or training based on incident learnings.
12. Official References and Related Policies
Reference points include guidance from the Office of the Privacy Commissioner of Canada on mandatory PIPEDA breach reporting and guidance from the Commission d'accès à l'information du Québec on confidentiality incidents for private enterprises.
Related Dutiva policies include the Privacy Policy, Data Processing Agreement, Data Retention and Deletion Policy, Terms of Service, Legal Disclaimer, Cookie Policy, AI Usage Disclosure, and AI & Technology Policy.
13. Contact
Questions about this Policy or privacy-related incident handling can be sent to the Dutiva Privacy Officer at privacy@dutiva.ca.
Security concerns or suspected misuse of Dutiva can also be reported through support channels at support@dutiva.ca with the subject line "Security Incident".
