Incident Response Plan

British Craft StudioVersion 1.0 · June 2026

1. Purpose

This Incident Response Plan outlines the procedures British Craft Studio ("the Company") will follow to detect, assess, contain, and report data security incidents — including unauthorised access, data breaches, or suspected exposure of personal data — particularly data accessed through the TikTok Shop API integration.

2. Roles & Responsibilities

RoleResponsibility
Incident LeadBusiness owner. Coordinates response, makes decisions on containment and notification.
Technical ContactIdentifies scope, revokes access/credentials, implements containment measures.
CommunicationsNotifies affected parties (TikTok Shop, customers, ICO) and manages communications.

In a small organisation, these roles may be held by the same individual. The Incident Lead is the business owner or a designated senior staff member.

3. Incident Detection & Reporting

  • Any suspected security incident must be reported to the Incident Lead immediately upon discovery.
  • Indicators of a potential incident include: unauthorised access alerts, unexpected API activity, missing or altered data, compromised credentials, or reports from customers/partners.
  • All reports are logged with date, time, description, and reporter details.

4. Response Phases

Phase 1: Identify & Assess (0–4 hours)

  • Confirm whether a genuine incident has occurred.
  • Determine scope: what data is affected, how many records, which systems.
  • Classify severity: Low (no personal data at risk), Medium (limited personal data exposed), High (significant personal data or seller data breached).

Phase 2: Contain (0–24 hours)

  • Revoke compromised credentials immediately (API keys, admin passwords).
  • Disable affected user accounts.
  • Rotate TikTok Shop API credentials and update IP allowlist.
  • Isolate affected systems if necessary.

Phase 3: Notify (within 72 hours)

  • TikTok Shop: Notify via partner support channels with incident details, affected seller data, and containment actions taken.
  • ICO (UK GDPR): If the breach is likely to result in a risk to individuals' rights and freedoms, notify the Information Commissioner's Office within 72 hours at ico.org.uk or phone 0303 123 1113.
  • Affected customers/sellers: Notify directly if the breach is likely to result in a high risk to their rights and freedoms.
  • Internal: Document the incident in an incident log with full timeline.

Phase 4: Eradicate & Recover

  • Remove the root cause (patch vulnerabilities, close access vectors).
  • Restore systems from clean backups if necessary.
  • Verify systems are secure before restoring normal operations.
  • Re-issue credentials with enhanced security controls.

Phase 5: Post-Incident Review (within 2 weeks)

  • Conduct a review of the incident, timeline, and response effectiveness.
  • Identify lessons learned and update this plan and related security policies.
  • Implement additional preventive measures as identified.

5. Notification Timeline

RecipientTimelineMethod
TikTok Shop Partner SupportWithin 72 hoursPartner support ticket
Information Commissioner's Office (ICO)Within 72 hoursico.org.uk / 0303 123 1113
Affected customers/sellersWithout undue delayEmail notification
Stripe (if payment data involved)Within 24 hoursStripe support portal

6. Communication Channels

  • Internal: Direct communication via phone and verified email. Incident log maintained as a shared document.
  • TikTok Shop: Partner support portal and dedicated partner contact channels.
  • Customers: Email from the official company domain (britishcraftstudio.com).
  • Regulators: ICO online breach report form or phone hotline.

7. Data Breach Response for TikTok Shop Data

If the incident involves TikTok Shop seller or customer data accessed via the API:

  • Immediately revoke TikTok Shop API credentials.
  • Identify which seller data was accessed and the time period.
  • Notify TikTok Shop with: affected seller IDs, data types exposed, time of breach, containment actions, and remediation plan.
  • Offer to assist TikTok Shop and affected sellers with data deletion or correction as required.

8. Plan Review

This Incident Response Plan is reviewed at least annually and updated following any security incident to incorporate lessons learned. The plan is available to all relevant personnel and partners upon request.

British Craft Studio — Incident Response PlanPage 1 of 1