Data Breach Response Policy

Effective date: 1 May 2026 · Version 1.0 · Aligned with the Jamaica Data Protection Act 2020 (DPA)
A "personal data breach" is a security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This policy applies to every breach we become aware of, however small.

1. Scope

This policy applies to all personal data we hold or process — customer accounts, shipment records, KYC documents, broker letters, signed PDFs, vendor records, and staff records.

2. Response stages

We follow a six-stage NIST-aligned process: Detect → Contain → Assess → Notify → Remediate → Review.

3. Detection

4. Containment

On confirmed or suspected breach the Incident Commander (DPO or delegate) immediately:

5. Risk assessment

Within 24 hours the team assesses:

6. Notify the Information Commissioner

Where the breach is likely to result in a risk to the rights and freedoms of data subjects we notify the Office of the Information Commissioner of Jamaica without undue delay and within 72 hours of becoming aware. Where the 72-hour window cannot be met we notify with reasons for the delay and supplement promptly thereafter.

The notification includes the nature of the breach, categories and approximate numbers of data subjects, the likely consequences, the measures taken or proposed to be taken to address the breach, and the contact details of the DPO.

7. Notify affected individuals

Where the breach is likely to result in a high risk to data subjects we notify them without undue delay in plain language, by email and (where serious) by SMS. The notification describes:

Where direct notification would involve disproportionate effort we use a public communication of comparable effectiveness, such as a banner on this site and a press release.

8. Remediation

9. Post-incident review

Within 30 days of containment we publish an internal post-mortem covering root cause, contributing factors, timeline, and corrective actions, and incorporate lessons into staff training and engineering practice.

10. Breach register

We maintain an internal register of all breaches (including those not requiring external notification) for a minimum of 5 years. The Information Commissioner may inspect the register on request.

Reportable breaches in the last 24 monthsCount
Reportable breaches0
Notifications to Information Commissioner0
Updated annually. Material incidents will be communicated promptly here and to affected individuals as required.

11. How to report a breach to us

If you believe your account, data, or any MGR system has been compromised, please report immediately:

We commit not to take legal action against good-faith researchers who follow our responsible-disclosure guidelines.