Data Breach Response Policy

Purpose

This policy defines Redequip’s process for identifying, responding to, and communicating data breaches involving diagnostic, coaching, or organisational data.

Definition of a Data Breach

A data breach includes:

  • unauthorised access

  • unauthorised disclosure

  • loss of data

  • accidental exposure

  • compromise of authentication credentials

  • system intrusion affecting stored data

Detection and Identification

Redequip monitors systems for:

  • anomalous access patterns

  • authentication irregularities

  • unexpected data movements

  • system‑level alerts

  • integrity failures

Any suspected breach is escalated immediately.

Response Process

  1. Containment

    • Isolate affected systems

    • Disable compromised accounts

    • Prevent further unauthorised access

  2. Assessment

    • Determine the nature and scope of the breach

    • Identify affected data and users

    • Assess potential impact

  3. Notification

    • Notify affected client organisations promptly

    • Provide details of the breach, impact, and remediation steps

    • Notify regulatory bodies if required by law

  4. Remediation

    • Restore secure operation

    • Patch vulnerabilities

    • Reset credentials

    • Strengthen controls

  5. Review

    • Analyse root causes

    • Update policies and controls

    • Document lessons learned

Commitment

Redequip is committed to transparent communication and rapid remediation in the event of any breach.