Search all 478 artefacts by title, document ID or content.
Disclosure | Family 14, Jurisdiction Variant Sets
This statement varies the global commitment DIS-GL-016 for an EEA hospital. It does not change the severity model, the incident response process, the rehearsal cadence or the escalation contacts. Those are in DIS-GL-016 and POL-GL-112 and are not restated. What is forked here is the clock map: which statutory clocks…
DIS-EU-016 v1.0.0, Last Modified On 01 August 2026, Tier: Public
| DM-1 Dedicated | DM-2 Shared | DM-3 Customer Cloud | DM-4 On-Premise |
|---|---|---|---|
| Yes | Yes | Yes | (for components Pensieve Labs can observe; see Section 7) |
This statement varies the global commitment DIS-GL-016 for an EEA hospital. It does not change the
severity model, the incident response process, the rehearsal cadence or the escalation contacts. Those
are in DIS-GL-016 and POL-GL-112 and are not restated. What is forked here is the clock map: which
statutory clocks an EEA hospital is running, who reports to whom, and how Pensieve Labs's commitment
is positioned inside them.
The contractual expression is DPA-EU-001 clause 9 and MSA-EU-001 clause 5.2.
| Commitment | Value |
|---|---|
| Notify the hospital of a personal data breach or reportable security incident | Within 4 hours of Pensieve Labs becoming aware |
| Supply notification content sufficient for the hospital's own Article 33 filing without a second request | With the first notification |
| Intermediate report | Within 48 hours of the first notification |
| Progress reporting while the incident is open | Weekly, and on request |
| Written post-incident review | Within 10 Business Days of containment, or a dated interim review stating why |
| Final report suitable for the hospital's NIS2 final report | Within 20 Business Days of containment |
| Draft of the Article 34 communication and the list of affected data subjects, on request | With the intermediate report |
| Evidence and log preservation | Not less than the period in DIS-GL-034 |
"Aware" means the point at which any Pensieve Labs person or system holds information indicating an
incident may have occurred. It does not mean confirmed, triaged, scoped or understood. A clock that
starts at certainty can be started whenever it is convenient.
An incident at a European hospital starts up to four clocks in parallel, and they do not have the same start point. This is the single most common source of confusion in a European security review, and getting it wrong in a contract costs the hospital its own deadline.
flowchart LR
T0["T0: Pensieve Labs becomes aware"] --> P["≤ 4 hours<br/>Pensieve Labs notifies the hospital<br/>with reportable content"]
P --> A["≤ 24 hours from the hospital's awareness<br/>Hospital files NIS2 early warning<br/>with the national CSIRT"]
P --> B["≤ 72 hours from the hospital's awareness<br/>Hospital notifies the supervisory authority<br/>under GDPR Art. 33"]
P --> C["≤ 72 hours from the hospital's awareness<br/>Hospital files the NIS2 incident notification"]
P --> D["Without undue delay<br/>Hospital communicates to data subjects<br/>under GDPR Art. 34, where the risk is high"]
C --> E["≤ 1 month<br/>Hospital files the NIS2 final report"]
Text description. At time zero Pensieve Labs becomes aware of an incident. Within four hours it
notifies the hospital with content sufficient for the hospital's own filings. That notification feeds four
hospital obligations running in parallel: a NIS2 early warning to the national computer security incident
response team within 24 hours; a GDPR Article 33 notification to the supervisory authority within 72 hours;
a NIS2 incident notification within 72 hours; and, where the risk to individuals is high, an Article 34
communication to affected data subjects without undue delay. A NIS2 final report follows within one month.
| # | Clock | Window | Who files | Basis |
|---|---|---|---|---|
| 0 | Pensieve Labs → hospital |
≤ 4 hours from Pensieve Labs's awareness |
Edsol Edtech Pvt. Ltd. |
DPA-EU-001 clause 9.1: contractual, tighter than the statutory "without undue delay" |
| 1 | Hospital → national CSIRT, early warning | 24 hours from the hospital's awareness | Hospital | National transposition of Directive (EU) 2022/2555, Article 23 |
| 2 | Hospital → supervisory authority | 72 hours from the hospital's awareness | Hospital | GDPR Article 33(1) |
| 3 | Hospital → national CSIRT, incident notification | 72 hours from the hospital's awareness | Hospital | National transposition, Article 23 |
| 4 | Hospital → affected data subjects | Without undue delay, where high risk | Hospital | GDPR Article 34 |
| 5 | Hospital → national CSIRT, final report | 1 month | Hospital | National transposition, Article 23 |
Note the asymmetry. Clocks 1 to 5 run from the hospital's awareness, not Pensieve Labs's. The
four-hour commitment exists to make the hospital's awareness follow Pensieve Labs's as closely as
possible, so that the hospital is not spending its own 24-hour window waiting for a vendor.
Clocks 1, 3 and 5 apply only where the hospital is a covered entity under its national transposition. Hospitals are ordinarily essential entities in the health sector. Where the transposition is not yet in force in the hospital's State, clocks 1, 3 and 5 do not run; clocks 0, 2 and 4 always do. The country delta packs record the position.
The hospital reports. Pensieve Labs does not.
In all four deployment models the hospital is the controller and holds the Article 33 obligation.
Edsol Edtech Pvt. Ltd. is the processor: its statutory duty is Article 33(2), to notify the controller
without undue delay, and it discharges that duty at four hours. It supplies content, technical analysis
and evidence.
Edsol Edtech Pvt. Ltd. does not notify a supervisory authority or a data subject on the hospital's
behalf, does not represent that it can, and will not agree a contract term that says it will. A processor
that files on a controller's behalf creates a record the controller cannot stand behind.
Edsol Edtech Pvt. Ltd. is not itself a covered entity under any national transposition of Directive
(EU) 2022/2555 and holds no registration under one. Its obligations under this statement are contractual.
STM-EU-002 states the position in full.
Written so the hospital's data protection officer can lift it into the supervisory authority's own form.
| Field | Mapped to |
|---|---|
| Nature of the breach | Article 33(3)(a) |
| Categories and approximate number of data subjects concerned | Article 33(3)(a) |
| Categories and approximate number of personal data records concerned | Article 33(3)(a) |
Name and contact details of Pensieve Labs's data protection contact |
Article 33(3)(b) |
| Likely consequences | Article 33(3)(c) |
| Measures taken or proposed, including mitigation | Article 33(3)(d) |
| Whether special-category data is affected, and which categories | Article 9; drives the Article 34 assessment |
| Whether data was accessed, exfiltrated, altered or made unavailable, and the basis for that conclusion | Article 34 risk assessment |
| Time of the incident, of detection and of containment | NIS2 early warning content |
| Whether the incident is suspected to be caused by unlawful or malicious acts, and whether it may have cross-border impact | NIS2 early warning content |
| Whether the incident originated with a sub-processor, and which | Article 28(4) |
| Whether other controllers are affected | NIS2 significant-incident assessment |
Where a field is unknown, the notification says so and states when it will be supplied. It does not omit the field, because an omitted field looks like a nil return.
Pensieve Labs's outputs to the hospital's filings| Hospital filing | Due | Pensieve Labs output that feeds it |
Delivered by |
|---|---|---|---|
| NIS2 early warning | 24 hours | First notification (Section 5) | 4 hours |
| Article 33 notification | 72 hours | First notification plus the intermediate report | 4 hours + 48 hours |
| NIS2 incident notification | 72 hours | Intermediate report, with the initial severity assessment and indicators of compromise | 48 hours |
| Article 34 communication | Without undue delay | Draft communication plus the affected-subject list, on request | With the intermediate report |
| Phased/progress reporting | On request | Weekly written update while open | Weekly |
| NIS2 final report | 1 month | Final report: root cause, severity and impact, cross-border impact, remediation with owners and dates | 20 Business Days |
| Post-incident review | Contractual | Written review with corrective actions and dates | 10 Business Days |
| Model | What Pensieve Labs detects |
What the hospital detects | Effect on the clock |
|---|---|---|---|
DM-1 |
Everything in the dedicated project: platform, database, storage, access | The hospital's own endpoints, network and users | Full 4-hour commitment |
DM-2 |
Everything in the shared platform, tenant-scoped | Same | Full 4-hour commitment. Where an incident affects more than one tenant, each is notified; no tenant is told another's identity |
DM-3 |
The platform layer inside the hospital's project | The hospital's own cloud account, identity and network layers | Full 4-hour commitment for what Pensieve Labs can observe. The hospital must forward its own account-level alerts for Pensieve Labs to act on them |
DM-4 |
Only what the hospital's telemetry forwarding exposes | The premises, the hardware, the network, the operating system, physical access | The 4-hour clock starts when Pensieve Labs becomes aware. Where the hospital does not forward telemetry, Pensieve Labs may become aware only when told, which is a consequence of the model and is stated in ADD-GL-008 |
DM-4 is the model where a breach commitment is most often over-promised by vendors.
Pensieve Labs will not commit to detecting an incident on hardware it cannot see.
An incident at a sub-processor is an incident for the purposes of this statement, and the four-hour clock
runs from Pensieve Labs's awareness. Edsol Edtech Pvt. Ltd. remains fully liable to the hospital for
its sub-processors' performance under DPA-EU-001 clause 7.7. The sub-processor's identity, role and
country are already published in DIS-GL-009, so the hospital does not learn of a sub-processor's
existence for the first time in a breach notification.
9.1 Four hours is a notification commitment, not a containment commitment. Containment time depends on
the incident. SLA-GL-001 states the response times; nothing here promises a resolution time.
9.2 The first notification will be incomplete. That is deliberate. A vendor that waits for a complete picture before notifying has spent the hospital's 24-hour window on its own comfort.
9.3 Not every incident is a personal data breach. A failed intrusion attempt, a denial-of-service event
with no data impact, or a vulnerability disclosure are security incidents but may not be Article 4(12)
breaches. Pensieve Labs notifies security incidents affecting the hospital's environment under
SLA-GL-001 and applies the four-hour clock where a personal data breach cannot be excluded. Where it
is uncertain, Pensieve Labs notifies.
9.4 The significance test is the hospital's. Whether an incident is "significant" under the hospital's
NIS2 transposition, and whether the Article 34 risk threshold is met, are assessments the hospital makes.
Pensieve Labs supplies the facts and its own view; it does not make the call.
9.5 No admission. A notification is not an admission of fault or liability.
9.6 Language. Notifications are issued in English. Pensieve Labs does not undertake to file in the
hospital's national language, because the hospital files, not Pensieve Labs.
Pensieve Labs about an incident| Channel | Address | Availability |
|---|---|---|
| Security incident reporting | info@pensievelabs.org |
Monitored continuously |
| Privacy and data protection | info@pensievelabs.org |
Business hours, escalating to the security channel |
| Coordinated vulnerability disclosure | POL-GL-059, including the published security.txt |
Continuous |
| Escalation matrix | POL-GL-056 |
Not applicable |
A hospital should test the security channel during evaluation by sending a test message and timing the
acknowledgement. Pensieve Labs expects to be tested.
| ID | Artefact |
|---|---|
DIS-GL-016 |
Incident Response & Breach Notification Commitment (global master) |
DPA-EU-001 |
Data Processing Agreement: EU/EEA, clause 9 |
MSA-EU-001 |
Master Services Agreement (EU/EEA Variant), clause 5 |
STM-EU-002 |
NIS2 Supplier Statement |
POL-GL-112 |
Incident Response Policy |
DIS-GL-034 |
Log Retention & Localisation Disclosure |
SLA-GL-001 |
Service Level Agreement |
ADD-GL-008 |
On-Premise Supplement (DM-4) |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 01 August 2026 |
Security | First issue. EEA fork of DIS-GL-016: the six-clock map, the asymmetry between processor awareness and controller awareness, and the mapping of Pensieve Labs outputs to each hospital filing. |