Incident Management PolicyMarketing Lama GmbH
Version 1.2
Date: 23 April 2026
1. Objective
The objective of this policy is to ensure a structured, fast and traceable response to security and data protection incidents in order to:limit damagerestore system availabilityprotect affected datameet statutory notification obligationsprevent recurrence2. ScopeThis policy applies to:cloud infrastructureserver and development environmentsend-user devicesthird-party integrationspersonal dataIt forms part of the information security management system (ISMS).3. Definition of a security incidentA security incident exists if at least one of the following occurs:unauthorised access to systems or datasuspected data loss or data manipulationmalware infection on end-user devicescompromise of access credentialsunusual or unauthorised system activityfailure of security-critical systems3.1 Definition of a personal data breachA personal data breach is a breach of security leading to the accidental or unlawful:destructionlossalterationor unauthorised disclosureof personal data.Personal data breaches are a special category of security incident and are subject to additional assessment and notification obligations.4. Roles & responsibilitiesManagement bears overall responsibility for assessment and external communication in security and data protection incidents.The technical lead is responsible for operational analysis, isolation and remediation.In small teams, roles may be combined.The decision on external notification is taken and documented by management.5. Procedure in a security incidentIdentification
Detection or report of a potential incident.Assessment
Classification of criticality and potential damage.
For personal data breaches, an initial risk assessment takes place within 24 hours of becoming aware.Isolation
Immediate isolation of affected systems or credentials to prevent further spread.Analysis
Root cause analysis and determination of the scope of the incident.Remediation
Technical measures to restore security and system stability.Documentation
Traceable documentation of the incident, its cause, the assessment and the measures taken.Preventive measures
Implementation of additional security measures to avoid similar incidents.6. Reporting channelsSecurity incidents are reported internally without delay.Internal reports go directly to management or the technical lead.All incidents are documented, regardless of their severity.6.1 External notification of personal data breachesIn the event of a personal data breach, it is assessed whether a statutory or contractual notification obligation applies.Where required:affected clients or platform partners are informed without delaya notification is made to the competent supervisory authority at the latest within 72 hours of becoming aware of the incident, where a notification obligation existsaffected individuals are informed where legally requiredAll external notifications are made in writing and are documented.7. Communication principlesTransparency towards affected partiesNo premature public statements before analysisDocumented decision-making on external communicationConsistent and coordinated communication by management8. Follow-upOnce an incident is closed, an internal review takes place to:identify structural weaknessesimprove technical controlsadjust processes or policiesassess possible organisational improvements9. ReviewThis policy is reviewed at least once a year and after security-relevant events, and is adjusted where necessary.Changes are documented with version control. This English text is a convenience translation; the German version is the authoritative one.