How are customers notified in the event of security incidents?
amaise follows internationally recognized reporting obligations and the legal requirements of the respective jurisdiction in the event of security incidents:
GDPR Art. 33/34 (EU): Report to the competent supervisory authority within 72 hours. Notify affected individuals if there is a high risk.
Swiss nDSG Art. 24: Report to the FDPIC and notify affected individuals as soon as possible in case of high-risk data breaches.
US regulations: Compliance with applicable State Breach Notification Laws and industry-specific requirements.
HIPAA (US health data): amaise processes protected health information (PHI) under signed Business Associate Agreements (BAAs). Affected individuals and HHS are notified within 60 days; applicable State Breach Notification Laws may impose shorter deadlines of 30-45 days. The systems that process PHI fall within the scope of amaise's SOC 2 Type II report, as documented in its scope section.
Professional secrecy: Assess implications for data subject to special confidentiality obligations (e.g., attorney-client privilege, medical confidentiality).
Communication channels:
Direct customer communication for affected clients
Status page for public updates
Incident details include: what happened, scope, impact, and measures taken
S1 and S2 incidents follow documented response SLAs for acknowledgement and initial communication.
Customer notification as the client:
amaise notifies the customer as the client (controller) within 24 hours after identifying a security incident affecting their data. This enables the customer to meet their own regulatory reporting obligations on time.
