ssm.ro Docs
Security, Infrastructure & OperationsIncident Management

Incident Notification

Notification of affected clients and authorities in the event of an incident or data breach

In the event of an incident, SSM.ro communicates transparently with affected clients and, where applicable, with the competent authorities.

Client notification

StageAction
Upon identificationAffected tenants are notified by email
In progressPeriodic status updates are issued until resolution
Upon resolutionA final confirmation is sent to affected tenants

Notifications include the nature of the incident, the estimated impact, the measures taken and, where applicable, the actions recommended to the client.

Notification of authorities — personal data breaches

If the incident involves a security breach of personal data, GDPR obligations apply:

  • Notification of ANSPDCP (National Supervisory Authority for Personal Data Processing) within a maximum of 72 hours of becoming aware of it, if the breach poses a risk to the rights and freedoms of individuals (GDPR Art. 33).
  • Informing the data subjects without undue delay, when the breach poses a high risk to their rights and freedoms (GDPR Art. 34).
  • Involvement of the DPO (Neoprivacy SRL) in assessing and managing the notification.

Detailed procedure: Data Breach Notification.

Roles in the controller–processor relationship

When SSM.ro acts as a processor for a client's data, breaches affecting the client's data are notified to the controller (the client) without delay, so that the controller can fulfill its own notification obligations. The allocation of responsibilities is set out in the Data Processing Agreement (DPA).

Channels

Official communication during incidents is carried out by email to affected tenants and through the Status and History page.