Incident Notification
Notification of affected clients and authorities in the event of an incident or data breach
In the event of an incident, SSM.ro communicates transparently with affected clients and, where applicable, with the competent authorities.
Client notification
| Stage | Action |
|---|---|
| Upon identification | Affected tenants are notified by email |
| In progress | Periodic status updates are issued until resolution |
| Upon resolution | A final confirmation is sent to affected tenants |
Notifications include the nature of the incident, the estimated impact, the measures taken and, where applicable, the actions recommended to the client.
Notification of authorities — personal data breaches
If the incident involves a security breach of personal data, GDPR obligations apply:
- Notification of ANSPDCP (National Supervisory Authority for Personal Data Processing) within a maximum of 72 hours of becoming aware of it, if the breach poses a risk to the rights and freedoms of individuals (GDPR Art. 33).
- Informing the data subjects without undue delay, when the breach poses a high risk to their rights and freedoms (GDPR Art. 34).
- Involvement of the DPO (Neoprivacy SRL) in assessing and managing the notification.
Detailed procedure: Data Breach Notification.
Roles in the controller–processor relationship
When SSM.ro acts as a processor for a client's data, breaches affecting the client's data are notified to the controller (the client) without delay, so that the controller can fulfill its own notification obligations. The allocation of responsibilities is set out in the Data Processing Agreement (DPA).
Channels
Official communication during incidents is carried out by email to affected tenants and through the Status and History page.