Data Breach / Incident Response Policy
Last updated 28 September 2026
On this page6 sections
If personal data is breached, we contain it, report it to CERT-In within 6 hours where required, inform the Data Protection Board and affected users without delay, and file a detailed report with the Board within 72 hours.
1. What counts as an incident
Any unauthorised access, disclosure, alteration, loss or destruction of personal data, or any cyber incident affecting our systems — for example a hacked account, a lost laptop or phone with student data, data sent to the wrong person, ransomware, or a vendor breach.
2. Response team
Incidents are handled by a designated partner as incident lead, our technical lead, and our Grievance Officer (Ankur Patel) for communications. Any staff member who suspects an incident must report it immediately to the incident lead and to careercomradehelpdesk@gmail.com.
3. Steps and timelines
Contain — isolate affected systems, reset credentials, revoke access (immediately).
Assess — what data, how many people, likely harm.
CERT-In — report reportable cyber incidents within 6 hours of noticing them (CERT-In Directions, 2022).
Data Protection Board — intimate without delay, and send a detailed report on facts, cause, mitigation and notified users within 72 hours (DPDP Rules, 2025).
Affected users — inform each affected person without delay, in plain language: what happened, likely consequences, what we are doing, what they should do, and whom to contact.
Fix and review — remove the root cause and record lessons learned within 30 days.
4. Records
Every incident is logged (date, facts, effect, actions, notifications) and kept for at least 3 years.
5. Vendors
Our processors must notify us of any breach affecting our data within 24 hours of discovering it.
6. If you notice something
If you receive a suspicious message claiming to be from Career Comrade, or think your data has been misused, contact careercomradehelpdesk@gmail.com or +91 80416 63641.
