- fremforge - EU-sovereign CI/CD with Git included/
- Legal documents/
- fremverk Controller-side Incident Response/
fremverk Controller-side Incident Response
On this page
Scope #
fremverk maintains a controller-side incident-response runbook governing our response to Personal Data Breaches affecting fremverk-as-Controller processing activities — breaches where fremverk owes the GDPR Art. 33 (72-hour Datatilsynet notification) and Art. 34 (data-subject communication) duties directly, rather than in our role as a Customer-as-Controller’s processor.
For Customer-Controller breaches — a sub-processor compromise affecting Customer Personal Data, or an exposure caused by Customer-tenant misconfiguration — the processor-side flow in DPA §§8.1–8.2 applies instead.
The runbook is in force. It is referenced by DPA §8.5 and by the Audit-Monitoring DPIA.
What it covers #
- Breach-severity classification and the criteria for each class.
- The Art. 33 notification decision and its 72-hour clock, including the assessment of whether a breach is likely to result in a risk to data subjects.
- The Art. 34 data-subject communication decision and threshold.
- Incident roles, and how the dual-role of privacy contact and incident commander is managed to avoid a conflict of interest.
- Containment, evidence-preservation, and post-incident review steps.
- The customer-notification template used for processor-side breaches.
Availability #
The runbook itself is classified internal. It contains operational detail — infrastructure identifiers, internal escalation contacts, and step-by-step recovery procedures — that would weaken our security posture if published, so this page carries the scope and coverage rather than the document.
Customers, prospective customers under evaluation, and auditors can obtain the full runbook under NDA. Email compliance@frem.sh with your organisation name and the purpose of the request.
For the incident-notification commitments that are contractually binding on fremverk, see DPA §8 and SLA §6 — those are public and are the authoritative statement of what we owe you.