Early access — working v1
Breach notification · PDPA s.12B
Praxis Breach is a mobile-first wizard any employee can open on discovery. It mirrors the Commissioner's Annex B form, triages significant harm across the five statutory triggers, runs a live 72-hour countdown and routes the draft to your DPO for approval — nothing is ever recorded as filed without it.

The person who notices a breach is a receptionist, a developer, a night manager. If the process starts only when the DPO is found, the clock is already running against you.
Annex B is precise. Filled in from memory at 2 a.m., it is incomplete or wrong — and a wrong notification is its own problem.
The 72-hour notification is the beginning. The 7-day data-subject notice and the 30-day phased update are where organisations quietly fall over once the crisis passes.
Any employee can start the clock immediately on discovery. No DPO gatekeeping is required to begin — only to file.
A live 72-hour countdown from the awareness timestamp, cross-checked against the form's own “submitted within 72 hours?” answer, with staged reminders at T-48h, T-24h, T-4h and overdue.
Notification is structured into the exact Annex B fields, cutting errors against completing a static form under pressure.
Server-enforced DPO review: submitted → under review → approved or rejected → filed. Nothing can be recorded as filed before DPO approval, and nothing auto-files with the Commissioner.
The deadline engine spawns the 7-day data-subject notification and 30-day phased-update clocks so they are not forgotten once the initial filing is done.
An append-only, SHA-256 hash-chained audit log with a tamper-detection endpoint provides evidence of the process for the Commissioner or in a later dispute.
Built for the phone in the pocket of whoever finds the problem — and for the DPO who has to sign what goes out.
Any employee opens the wizard on a phone. The awareness timestamp starts the 72-hour countdown; no personal data leaves the device until the user actively submits.
22 questions mirroring the official notification form, section by section, in the Commissioner's own wording.
Automated triage across the five statutory triggers, including an automatic flag when more than 1,000 data subjects are affected.
The draft is emailed to the DPO as a pre-filled Annex B preview and enters the review queue: submitted → under review → approved or rejected.
The DPO files with the Commissioner. The system will not record a notification as filed without DPO approval.
7-day data-subject notification and 30-day phased-update deadlines are spawned automatically, with staged reminders until each is closed.
A 22-question wizard mirroring the official Annex B form verbatim across all sections — no framework, loads instantly, works on any phone.
Automated triage across the five statutory triggers, including an auto-flag for more than 1,000 affected data subjects.
From the breach-awareness timestamp, cross-checked against the form's own “submitted within 72 hours?” answer.
Submitted → under review → approved / rejected → filed. Nothing can be recorded as filed before DPO approval.
Downstream 7-day and 30-day clocks with T-48h, T-24h, T-4h and overdue reminder emails.
Append-only, SHA-256 hash-chained, with an audit-verification endpoint for tamper detection.
Downloadable, printable and emailable as a pre-filled draft to the DPO.
No personal data leaves the device until the employee actively submits the draft.
A separate, access-controlled review screen for the DPO, designed to sit behind your identity provider.
Give every client a breach-reporting front door that lands in the firm's review queue — with the record already structured in Annex B when the call comes in.
One intake for every entity and site, a review queue you control, and downstream clocks that do not depend on someone remembering.
The same 72-hour clock applies to a clinic or a rental operator as to a bank. This is how a small team meets it without a privacy department.
Praxis Breach is a working release. We are opening it to a small number of organisations who will run real drills through it and tell us where it breaks. It is included in every suite plan as it ships.
Tell us how breach reporting works in your organisation today — who finds it, who files it, and how the DPO gets involved. We will set you up and walk your team through a drill.
Praxis Breach structures and evidences professional analysis. It does not provide legal advice, and it does not replace the review and approval of an appropriately qualified person before reliance or issue.
Every suite plan includes all seven applications as each ships — licensed by client workspace, never by seat. See plans.
Praxis DPIAImpact assessments on the 2026 DPIA Guideline
Praxis Frontiers.129 cross-border transfer assessments
Praxis Privacy AuditPrivacy-notice audit against statutory text
Praxis Breachs.12B breach notification with a live 72-hour clock
Praxis SchemaData mapping and Records of Processing Activities
Praxis PassportCitation-backed adequacy reference across jurisdictions
Praxis IntegrityPublic verification registry for every issued report