DashStack sp. z o.o.

Wersja polska

Personal Data Breach Notification Procedure

How DashStack sp. z o.o. identifies, assesses, escalates, documents and communicates suspected or confirmed personal data breaches — including notification of customers, sellers, platform partners, supervisory authorities and affected individuals.

Document version
1.1
Effective date
1 September 2026
Document owner
Management Board / Privacy Responsible Person
Classification
Internal / Controlled Document
Review frequency
At least annually, or following a material legal, organizational, technological or security-related change

1. Purpose

The purpose of this Personal Data Breach Notification Procedure is to define the process used by DashStack sp. z o.o. to identify, assess, escalate, document and communicate suspected or confirmed personal data breaches.

This Procedure is intended to ensure that personal data breaches are handled promptly and that customers, sellers, platform partners, supervisory authorities and affected individuals are notified where required by applicable law or contractual obligations.

2. Scope

This Procedure applies to:

  • employees of DashStack sp. z o.o.;
  • contractors and subcontractors;
  • systems and applications operated or maintained by DashStack;
  • personal data processed by DashStack as a controller, processor or sub-processor;
  • customer, seller and platform data processed through DashStack systems;
  • third-party services used by DashStack where they process personal data on behalf of DashStack or its customers.

3. Definition of a Personal Data Breach

A personal data breach means a security incident leading to the accidental or unlawful:

  • destruction;
  • loss;
  • alteration;
  • unauthorized disclosure of;
  • unauthorized access to

personal data transmitted, stored or otherwise processed.

Examples may include:

  • unauthorized access to an application, database or administrative account;
  • accidental disclosure of personal data to an unauthorized recipient;
  • loss or theft of a device containing personal data;
  • compromise of authentication credentials;
  • malware or ransomware affecting systems containing personal data;
  • unauthorized extraction or export of personal data;
  • accidental deletion or corruption of personal data where availability is affected;
  • improper access caused by a software or configuration error.

4. Roles and Responsibilities

The Privacy Responsible Person and/or Information Security Responsible Person is responsible for coordinating the response to suspected or confirmed personal data breaches.

Responsibilities include:

  • receiving and assessing incident reports;
  • coordinating technical investigation;
  • determining whether personal data has been affected;
  • assessing the nature, scope and potential impact of the breach;
  • coordinating containment and remediation;
  • determining customer or partner notification requirements;
  • supporting regulatory notification where applicable;
  • maintaining incident documentation;
  • coordinating corrective and preventive actions.

All employees and contractors are required to promptly report suspected security incidents or personal data breaches.

5. Internal Incident Reporting

Any employee or contractor who becomes aware of a suspected or confirmed personal data breach shall report it immediately to the Privacy Responsible Person or Information Security Responsible Person.

Reports may be submitted through designated internal communication channels, including:

  • the designated privacy or security contact;
  • internal company communication systems;
  • incident management or support systems;
  • another communication channel designated by management.

The reporter should provide all available information, including where known:

  • date and time the incident was identified;
  • systems or services affected;
  • type of personal data involved;
  • suspected cause;
  • known or estimated number of affected individuals;
  • actions already taken;
  • any evidence or logs available.

6. Initial Assessment

Following receipt of an incident report, DashStack shall assess the incident without undue delay.

The assessment shall consider:

  • whether personal data is involved;
  • categories of personal data affected;
  • sensitivity of the affected data;
  • approximate volume of records;
  • approximate number of affected individuals;
  • whether the data was encrypted or otherwise protected;
  • whether unauthorized access or disclosure occurred;
  • likely consequences for affected individuals;
  • potential impact on customers, sellers or platform partners;
  • legal and contractual notification requirements.

The assessment may be updated as additional information becomes available.

7. Containment and Remediation

DashStack shall take appropriate steps to contain and remediate the incident.

Such actions may include:

  • disabling compromised accounts;
  • revoking credentials or access tokens;
  • resetting passwords;
  • isolating affected systems;
  • blocking unauthorized access;
  • applying security patches;
  • correcting application or infrastructure configuration;
  • restoring affected systems from backups;
  • removing malicious software;
  • restricting access to affected data;
  • preserving relevant logs and evidence.

Corrective actions shall be proportionate to the severity and nature of the incident.

8. Notification of Customers, Sellers and Platform Partners

Where DashStack acts as a processor or sub-processor and becomes aware of a personal data breach affecting data processed on behalf of a customer, seller, TikTok Shop or another controller, DashStack shall notify the affected controller without undue delay.

Notification shall be provided through the designated customer privacy or security contact, contractual communication channel or another communication method agreed with the affected party.

Where information is not yet complete, DashStack may provide an initial notification followed by additional information as the investigation progresses.

DashStack shall not delay an initial notification solely because all details of the incident are not yet available.

9. Information Included in a Breach Notification

Where reasonably available, a notification shall include:

  • a description of the nature of the incident;
  • date and time of detection;
  • date or estimated period of occurrence, where known;
  • systems or services affected;
  • categories of personal data involved;
  • approximate number of affected individuals;
  • approximate number of affected records;
  • potential consequences of the breach;
  • containment measures already taken;
  • remediation measures implemented or planned;
  • recommended actions for the affected customer or partner, where applicable;
  • contact details for further communication.

Information may be provided in stages if the investigation is ongoing.

10. TikTok Shop and Seller Data

Where a suspected or confirmed personal data breach affects data processed on behalf of TikTok Shop or a TikTok Shop seller, DashStack shall:

  1. promptly assess whether TikTok Shop or seller data is affected;
  2. notify the relevant party without undue delay;
  3. provide available information regarding the nature and scope of the incident;
  4. provide information regarding affected personal data;
  5. describe containment and remediation actions;
  6. provide reasonable assistance required to assess notification obligations;
  7. provide relevant updates as material new information becomes available.

DashStack shall cooperate with TikTok Shop and/or the relevant seller in relation to incident investigation and response, subject to applicable contractual and legal requirements.

11. Regulatory Notification

Where DashStack acts as a controller, it shall assess whether a personal data breach requires notification to the competent supervisory authority under applicable data protection law.

Where notification is required under the GDPR, DashStack shall notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach.

Where DashStack acts solely as a processor or sub-processor, DashStack shall support the relevant controller in assessing and fulfilling its regulatory notification obligations.

12. Notification of Affected Individuals

Where required by applicable law, affected individuals shall be informed of a personal data breach where the breach is likely to result in a high risk to their rights and freedoms.

Where DashStack acts as a processor or sub-processor, communication with affected individuals shall normally be performed by the relevant controller unless otherwise instructed or legally required.

13. Communication and Cooperation

DashStack shall maintain reasonable cooperation with affected customers, sellers and platform partners throughout the incident response process.

Communication may include:

  • initial incident notification;
  • investigation updates;
  • technical findings;
  • remediation status;
  • confirmation of containment;
  • corrective actions;
  • final incident summary.

Sensitive security information shall only be disclosed to authorized recipients and only to the extent reasonably necessary.

14. Incident Documentation

DashStack shall maintain appropriate records of personal data breaches.

Records may include:

  • date and time of detection;
  • incident description;
  • affected systems;
  • affected data;
  • investigation findings;
  • risk assessment;
  • containment actions;
  • remediation actions;
  • notifications made;
  • notification dates;
  • parties notified;
  • final outcome;
  • lessons learned;
  • corrective actions.

Incident records shall be retained in accordance with applicable legal, contractual and internal retention requirements.

15. Post-Incident Review

Following a material incident, DashStack shall perform an appropriate post-incident review.

The review may consider:

  • root cause;
  • effectiveness of detection;
  • effectiveness of containment;
  • effectiveness of communication;
  • security control weaknesses;
  • required technical improvements;
  • required organizational improvements;
  • required policy or procedure changes.

Corrective actions shall be documented and implemented within a timeframe proportionate to the associated risk.

16. Confidentiality

Information relating to security incidents and personal data breaches shall be treated as Confidential or Restricted information.

Access shall be limited to persons who require the information for investigation, remediation, legal, contractual or regulatory purposes.

17. Third-Party Incidents

Where a third-party provider or sub-processor notifies DashStack of a personal data breach affecting data processed for DashStack or its customers, the incident shall be handled under this Procedure.

DashStack shall assess whether customers, sellers, platform partners or supervisory authorities must be notified and shall coordinate further actions with the relevant third party.

18. Testing and Review

DashStack may periodically review or test its incident response and breach notification process.

This Procedure shall be reviewed:

  • at least once every 12 months;
  • following a material personal data breach;
  • following significant changes to applicable law;
  • following significant changes to infrastructure or processing activities;
  • following changes to material customer or platform requirements.

Material updates shall be approved by the Management Board or an authorized representative of DashStack sp. z o.o.

19. Related Documents

This Procedure should be read together with:

  • DashStack Information Security Policy;
  • DashStack Privacy and Personal Data Protection Policy;
  • applicable customer agreements;
  • applicable Data Processing Agreements;
  • applicable internal security procedures.

20. Approval

Company: DashStack sp. z o.o. Document: Personal Data Breach Notification Procedure, version 1.1.

Approved by: Management Board / Authorized Representative.

DashStack sp. z o.o. — Personal Data Breach Notification Procedure v1.1

Back to top