What happens if there's a data breach? (United Kingdom)
For UK organisations, breach notification is a contractual term — without undue delay and within 72 hours of becoming aware, to the practice-owner email and by in-product notice.
Every supplier assessment asks this, so here is the United Kingdom commitment in plain terms. It is a contractual term in the UK Data Processing Schedule and is restated in the UK privacy notice — it applies to organisations on the UK Sovereign region.
If Akoua becomes aware of a personal data breach affecting your clinical data, we notify your practice without undue delay and in any event within 72 hours of becoming aware.
The notice carries the information Article 33(3) requires so far as it is known at the time, and it is supplemented as more becomes available. We would rather send an incomplete notice inside 72 hours than a tidy one late.
How you’ll hear: the registered practice-owner email address, and an in-product notice.
Your practice remains the controller, so the decision to notify the ICO or affected patients is the practice’s — our job is to give you what you need to make it, quickly.
What sits behind it
Every access to a record is written to an append-only audit log, enforced at the database level. On the UK Sovereign region, every external processing hop is also recorded immutably and is disclosable to your practice in-product. That is what makes a specific notice possible rather than a vague one.
By contrast, if your organisation is in Australia or New Zealand, the terms that apply to you are in the privacy policy and the terms of use; talk to us at privacy@akoua.ai if you need the detail in writing for an assessment.
Still stuck?
Email support@akoua.ai — or see the contact page. Service status lives at status.akoua.ai.