Breach Response Plan
EnkiLabs's formal procedure for detecting, containing, and notifying users and regulators of a personal data breach — in compliance with Quebec Law 25, GDPR, and PIPEDA.
Last updated: May 2026 · EnkiLabs Technologies
This plan defines how EnkiLabs Technologies responds to a personal data breach. It satisfies the notification requirements of Quebec Law 25 (72-hour rule), GDPR Article 33–34, and PIPEDA breach-of-security safeguards regulations. All EnkiLabs staff and contractors with access to personal data are required to follow this plan.
1. What Constitutes a Breach
A personal data breach is any security incident that leads to the accidental or unlawful:
- Destruction, loss, or alteration of personal data
- Unauthorised disclosure or access to personal data
This includes: server intrusion, ransomware, misconfigured cloud storage, lost devices with unencrypted data, insider threat, or third-party processor breach involving Enki App user data.
2. Incident Response Timeline
Detection & Containment — Hour 0
Any team member who identifies a potential breach immediately notifies the Privacy Officer and CTO via the designated secure channel. The affected system is isolated. No public statement is made at this stage.
Assessment — Hours 0–12
The Privacy Officer and CTO assess: what data was affected, how many users are impacted, whether vault contents were exposed (if decryption keys were not compromised, vault contents remain safe). Severity is classified as Low / Medium / High / Critical.
Regulatory Notification — Within 72 Hours
For any breach posing real risk of significant harm:
- Quebec: Commission d'accès à l'information (CAI) — cai.gouv.qc.ca
- EU users: Relevant Lead Supervisory Authority under GDPR
- Canada (federal): Office of the Privacy Commissioner — priv.gc.ca
The notification includes: nature of the breach, categories and approximate number of individuals affected, likely consequences, and measures taken or proposed.
User Notification — Within 72 Hours (if high risk)
Affected users are notified by email in plain language. The message covers: what happened, what data was involved, what we are doing, and what users can do to protect themselves (e.g., change password, revoke emergency contacts).
Remediation & Post-Incident Review — Week 1–4
Root cause is documented. Security controls are updated. A written post-mortem is produced and stored in the breach register. Third-party security audit may be commissioned.
3. Roles & Responsibilities
| Role | Responsibility |
|---|---|
| Privacy Officer | Overall incident coordination, regulatory notifications, user communications, breach register maintenance |
| CTO / Engineering Lead | Technical containment, forensic investigation, system remediation, log preservation |
| All Staff | Immediate reporting of any suspected breach; no independent disclosure to media or third parties |
4. Encryption & Breach Impact Mitigation
EnkiLabs uses AES-256 encryption for all data at rest and TLS 1.3 for all data in transit. Master PINs are hashed using PBKDF2 with a per-user salt and are never stored in recoverable form. Digital Legacy Vault contents are encrypted client-side with a key derived from the user's Master PIN — meaning even a full database breach does not expose vault contents without the PIN.
These measures significantly reduce the severity of any breach. However, breaches involving unencrypted contact metadata (names, email, phone) are still treated with the same urgency and notification obligations.
5. Report a Security Vulnerability
If you discover a vulnerability in Enki App, please report it responsibly. We commit to acknowledging your report within 48 hours and resolving confirmed issues within 30 days.
Email: security@enkilabstech.com
Please do not disclose the vulnerability publicly until we have had a chance to address it.