> ## Documentation Index
> Fetch the complete documentation index at: https://internal.softcrum.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Runbook — Personal Data Breach (72 h) — BLOCKING before commercial launch

> Roles: Incident Lead (DPO — Daniel, provisional) · Tech Lead · Comms. Clock starts at DETECTION (log timestamp).

Refs: DEC-J4, Ley 21.719 (notification to APDP without undue delay; 72 h target; affected data subjects if high risk)

0. **Detect & triage (T+0–2 h):** confirm personal data involved; open incident channel; freeze evidence (BetterStack export, audit\_log extract by correlation\_id); classify scope (tenants, contacts, fields — was national\_id exposed?).
1. **Contain (T+2–12 h):** revoke exposed keys/tokens; rotate secrets; patch vector; if exfiltration via webhook/integration, disable endpoint; snapshot DB state.
2. **Assess (T+12–36 h):** count affected data subjects per tenant; risk level (sensitive fields ⇒ high); document in incident record (template in Comply).
3. **Notify controllers (tenants) (T+≤48 h):** per DPA obligation "without undue delay": affected counts, fields, measures, recommendations. Template: 70-legal annex.
4. **Notify APDP (T+≤72 h):** via Agency channel; DPO signs. If high risk: plan data-subject notification WITH the affected tenants (they are controllers; we assist).
5. **Remediate & verify (T+≤7 d):** fix root cause; add regression test; verify no recurrence in logs.
6. **Post-mortem (T+≤14 d):** blameless doc; update RAT/DPIA if processing changed; file evidence pack (the APDP audits operational evidence).
   Quarterly: tabletop drill; keep contact sheet current (APDP, lawyer, hosting DPO contacts).
