1. Purpose
This Incident Response Plan outlines the procedures British Craft Studio ("the Company") will follow to detect, assess, contain, and report data security incidents — including unauthorised access, data breaches, or suspected exposure of personal data — particularly data accessed through the TikTok Shop API integration.
2. Roles & Responsibilities
| Role | Responsibility |
|---|
| Incident Lead | Business owner. Coordinates response, makes decisions on containment and notification. |
| Technical Contact | Identifies scope, revokes access/credentials, implements containment measures. |
| Communications | Notifies affected parties (TikTok Shop, customers, ICO) and manages communications. |
In a small organisation, these roles may be held by the same individual. The Incident Lead is the business owner or a designated senior staff member.
3. Incident Detection & Reporting
- Any suspected security incident must be reported to the Incident Lead immediately upon discovery.
- Indicators of a potential incident include: unauthorised access alerts, unexpected API activity, missing or altered data, compromised credentials, or reports from customers/partners.
- All reports are logged with date, time, description, and reporter details.
4. Response Phases
Phase 1: Identify & Assess (0–4 hours)
- Confirm whether a genuine incident has occurred.
- Determine scope: what data is affected, how many records, which systems.
- Classify severity: Low (no personal data at risk), Medium (limited personal data exposed), High (significant personal data or seller data breached).
Phase 2: Contain (0–24 hours)
- Revoke compromised credentials immediately (API keys, admin passwords).
- Disable affected user accounts.
- Rotate TikTok Shop API credentials and update IP allowlist.
- Isolate affected systems if necessary.
Phase 3: Notify (within 72 hours)
- TikTok Shop: Notify via partner support channels with incident details, affected seller data, and containment actions taken.
- ICO (UK GDPR): If the breach is likely to result in a risk to individuals' rights and freedoms, notify the Information Commissioner's Office within 72 hours at ico.org.uk or phone 0303 123 1113.
- Affected customers/sellers: Notify directly if the breach is likely to result in a high risk to their rights and freedoms.
- Internal: Document the incident in an incident log with full timeline.
Phase 4: Eradicate & Recover
- Remove the root cause (patch vulnerabilities, close access vectors).
- Restore systems from clean backups if necessary.
- Verify systems are secure before restoring normal operations.
- Re-issue credentials with enhanced security controls.
Phase 5: Post-Incident Review (within 2 weeks)
- Conduct a review of the incident, timeline, and response effectiveness.
- Identify lessons learned and update this plan and related security policies.
- Implement additional preventive measures as identified.
5. Notification Timeline
| Recipient | Timeline | Method |
|---|
| TikTok Shop Partner Support | Within 72 hours | Partner support ticket |
| Information Commissioner's Office (ICO) | Within 72 hours | ico.org.uk / 0303 123 1113 |
| Affected customers/sellers | Without undue delay | Email notification |
| Stripe (if payment data involved) | Within 24 hours | Stripe support portal |
6. Communication Channels
- Internal: Direct communication via phone and verified email. Incident log maintained as a shared document.
- TikTok Shop: Partner support portal and dedicated partner contact channels.
- Customers: Email from the official company domain (britishcraftstudio.com).
- Regulators: ICO online breach report form or phone hotline.
7. Data Breach Response for TikTok Shop Data
If the incident involves TikTok Shop seller or customer data accessed via the API:
- Immediately revoke TikTok Shop API credentials.
- Identify which seller data was accessed and the time period.
- Notify TikTok Shop with: affected seller IDs, data types exposed, time of breach, containment actions, and remediation plan.
- Offer to assist TikTok Shop and affected sellers with data deletion or correction as required.
8. Plan Review
This Incident Response Plan is reviewed at least annually and updated following any security incident to incorporate lessons learned. The plan is available to all relevant personnel and partners upon request.