Notify affected customers when their data or systems were exposed
Customers are notified of any incident involving unauthorized access to their identity documents, account details, or transaction records, or a compromise of their systems through the Company. The Compliance Officer decides the need and timing with outside counsel; notice goes out as soon as practical after containment and root cause analysis, typically within five to ten business days of confirmation, coordinated with regulatory notices and the sponsor bank. The notice states what happened, when, what the Company did, what the customer should do, and whom to contact, in language counsel has approved.
Event-driven
Each incident exposing customer data, typically within 5 to 10 business days of confirmation
Record the notification decision and its basis, draft the notice with the required content, obtain counsel’s approval, align timing with the bank and any regulatory notice, send it, and keep the evidence.
- Notification decision
Required or not, basis, counsel consulted, date
- Customer notice
Approved text, recipients, and send date
Compliance Officer
Leela can prepare the artifact and hand it to a person for review.
Leela can draft the customer notice from the incident record with the required content and route it to counsel and the Compliance Officer for approval.
Tell Leela about your company to see whether this applies.
Tell Leela how you handle it today, or hand it over: see what’s next.