Security
Incident response
Last updated · October 7, 2026
As controller you have 72 hours to notify your supervisory authority. Lutril commits to 48.
Incident response
| Step | Commitment |
|---|---|
| Initial notification | Without undue delay, and within 48 hours of qualifying a confirmed security incident affecting your data. |
| Channel | Email to the security contact you designate in the data processing agreement, plus a phone call for a critical incident. |
| Content | Nature of the incident, categories and approximate volume of data and people concerned, likely consequences, containment and remediation measures taken or proposed, and a named contact. |
| Follow-up | Further information as the investigation progresses, without waiting for a complete picture. |
| Post-incident report | Root cause analysis and corrective plan within 7 working days of closure. |
| Assistance | Support for your own notification to the supervisory authority and, where required, to the people concerned. |
- The internal procedure is written and the roles are assigned in advance: detection, severity qualification, containment, eradication, notification, then a documented review.