Data Breach Response Policy
Effective date: 1 May 2026 · Version 1.0 · Aligned with the Jamaica Data Protection Act 2020 (DPA)
A "personal data breach" is a security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This policy applies to every breach we become aware of, however small.
1. Scope
This policy applies to all personal data we hold or process — customer accounts, shipment records, KYC documents, broker letters, signed PDFs, vendor records, and staff records.
2. Response stages
We follow a six-stage NIST-aligned process: Detect → Contain → Assess → Notify → Remediate → Review.
3. Detection
- Continuous audit-log monitoring of all account access and data exports.
- Automated alerts on unusual login patterns, unauthorised admin actions, mass data downloads, and failed-login spikes.
- Reports from staff, customers, partners, and external researchers (see §11).
4. Containment
On confirmed or suspected breach the Incident Commander (DPO or delegate) immediately:
- Isolates the affected systems (revoke tokens, rotate credentials, block IPs, suspend accounts).
- Preserves forensic evidence (logs, snapshots, memory captures).
- Activates the incident-response team — DPO, Head of Engineering, Legal Counsel, and (where serious) external counsel and forensic specialists.
5. Risk assessment
Within 24 hours the team assesses:
- What categories and volumes of personal data are affected;
- Number and identity of affected data subjects;
- Likely consequences — identity theft, fraud, financial loss, reputational harm, regulatory exposure;
- Whether sensitive data (KYC IDs, passport, biometric, health, criminal-record clearances) is involved.
6. Notify the Information Commissioner
Where the breach is likely to result in a risk to the rights and freedoms of data subjects we notify the Office of the Information Commissioner of Jamaica without undue delay and within 72 hours of becoming aware. Where the 72-hour window cannot be met we notify with reasons for the delay and supplement promptly thereafter.
The notification includes the nature of the breach, categories and approximate numbers of data subjects, the likely consequences, the measures taken or proposed to be taken to address the breach, and the contact details of the DPO.
7. Notify affected individuals
Where the breach is likely to result in a high risk to data subjects we notify them without undue delay in plain language, by email and (where serious) by SMS. The notification describes:
- What happened and when;
- What data is affected;
- What we have done about it;
- What you can do to protect yourself (e.g. change password, enable 2FA, monitor accounts);
- How to contact our DPO.
Where direct notification would involve disproportionate effort we use a public communication of comparable effectiveness, such as a banner on this site and a press release.
- Patch the underlying vulnerability or process gap.
- Rotate any compromised secrets, certificates, or credentials.
- Where appropriate, offer affected individuals identity-monitoring services.
- Update access controls and detection rules.
9. Post-incident review
Within 30 days of containment we publish an internal post-mortem covering root cause, contributing factors, timeline, and corrective actions, and incorporate lessons into staff training and engineering practice.
10. Breach register
We maintain an internal register of all breaches (including those not requiring external notification) for a minimum of 5 years. The Information Commissioner may inspect the register on request.
| Reportable breaches in the last 24 months | Count |
| Reportable breaches | 0 |
| Notifications to Information Commissioner | 0 |
Updated annually. Material incidents will be communicated promptly here and to affected individuals as required.
11. How to report a breach to us
If you believe your account, data, or any MGR system has been compromised, please report immediately:
We commit not to take legal action against good-faith researchers who follow our responsible-disclosure guidelines.