Every school asks this before it signs, and it deserves a straight answer rather than a paragraph in a contract. These are the commitments Commun makes to every school it holds data for, in the order they happen. They are written into clause 7 of the data processing agreement we sign with you.
Halaman ini diterbitkan dalam Bahasa Inggeris; teks Bahasa Inggeris yang terpakai.
A personal data breach is any loss, misuse, unauthorised or accidental access, disclosure, alteration or destruction of personal data. It does not have to be an attack from outside: a member of staff seeing records they should not, a file sent to the wrong family, or one school’s user reaching another school’s data all count. We treat a suspicion as enough to start — the deadlines in the Act run from the moment we become aware, not from the moment we are certain.
We stop the exposure, preserve the evidence rather than tidying it away, and open an incident record that we keep adding to as facts arrive. A short interruption to the service is a price we will pay to close a breach, and we would rather explain an outage than a leak.
Not 72 — 24. Under the Act your school, as the data controller, has 72 hours to notify the Personal Data Protection Commissioner, and that clock starts when you become aware. If we took the full 72 hours to tell you, we would have spent your deadline for you. So we send what we know within a day, plainly marked as incomplete if it is, rather than waiting for a tidy account.
The notification to the Commissioner is your school’s to make, and so is the notification to affected families where a breach is likely to cause significant harm — that one is due within 7 days of telling the Commissioner. We supply the facts, the timeline and the technical detail, we draft the technical part of any message, and we can send it through the platform on your instruction. What we will not do is decide on your behalf whether to notify. That judgment belongs to the controller, and a vendor leaning on it either way is a vendor overstepping.
We keep a register of personal data incidents for at least two years, with what happened, who was affected, what we did and when. Your school can ask for the entry that concerns it at any time, and we will give it to you — including where the cause was ours.
We will not wait for certainty before telling you. We will not close an incident quietly without telling you what caused it. And we will not describe a breach as a “technical issue” in the hope that it reads better; if your families’ data was exposed, the message will say so.
Our Data Protection Officer, registered with the Personal Data Protection Commissioner on 30 August 2026, is the point of contact for anything on this page: [email protected]. If you believe you have found a security problem in Commun, write to the same address and say so in the subject line — we would rather hear it from you than read about it later.
This page sits alongside our Personal Data Protection Notice, which sets out what personal data we process and the rights you have over it.