Skip to content
Policy · Last updated 2025

Data Breach Policy

This policy summarises how we respond to suspected or confirmed personal-data breaches, including how we contain, investigate, notify and learn from them.

Definition

A personal-data breach is a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

Detection & reporting

All staff and vendors must report suspected breaches immediately to the Data Protection Officer at dpo@kedaricapital.com. Reports must include what happened, when, the data and individuals affected, and any actions already taken.

Containment & investigation

Our incident-response team contains the incident, preserves evidence and assesses the risk to affected data subjects.

Notification

Where required we notify the regulator within the statutory deadline (typically within 72 hours of becoming aware of a notifiable breach) and inform affected individuals where the breach is likely to result in high risk to their rights and freedoms.

Records & lessons learned

We keep a register of all breaches and conduct a post-incident review to update controls and training.

Need the full policy document?

Request the complete signed PDF from our compliance team.