Leela
Incident Response
IR-05

Notify affected customers when their data or systems were exposed

Policy reference

Incident Response policy, §6

Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice, 12 CFR Part 364, Appendix B, Supplement A
Requirement

Customers are notified of any incident involving unauthorized access to their identity documents, account details, or transaction records, or a compromise of their systems through the Company. The Compliance Officer decides the need and timing with outside counsel; notice goes out as soon as practical after containment and root cause analysis, typically within five to ten business days of confirmation, coordinated with regulatory notices and the sponsor bank. The notice states what happened, when, what the Company did, what the customer should do, and whom to contact, in language counsel has approved.

Trigger

Event-driven

Each incident exposing customer data, typically within 5 to 10 business days of confirmation

Action

Record the notification decision and its basis, draft the notice with the required content, obtain counsel’s approval, align timing with the bank and any regulatory notice, send it, and keep the evidence.

Evidence
  • Notification decision

    Required or not, basis, counsel consulted, date

  • Customer notice

    Approved text, recipients, and send date

Owner

Compliance Officer

Leela can
Prepare for review

Leela can prepare the artifact and hand it to a person for review.

Leela can draft the customer notice from the incident record with the required content and route it to counsel and the Compliance Officer for approval.

Applies

Tell Leela about your company to see whether this applies.

Status
Setup needed

Tell Leela how you handle it today, or hand it over: see what’s next.

What’s next?