Early access — working v1 Breach notification · PDPA s.12B

When a breach is discovered, the 72-hour clock has already started. Make sure your people can start the record just as fast.

Praxis Breach is a mobile-first wizard any employee can open on discovery. It mirrors the Commissioner's Annex B form, triages significant harm across the five statutory triggers, runs a live 72-hour countdown and routes the draft to your DPO for approval — nothing is ever recorded as filed without it.

Working v1 — opening to a small number of organisations Annex B mirrored verbatim, all sections Nothing auto-files with the Commissioner
72 hlive countdown from breach awareness
22questions, mirroring the official Annex B form
5statutory significant-harm triggers triaged
7 / 30 daysdownstream data-subject and phased-update clocks
The problem

The first hour of a breach is spent finding out who to tell.

Discovery is not where the DPO sits

The person who notices a breach is a receptionist, a developer, a night manager. If the process starts only when the DPO is found, the clock is already running against you.

A static form under time pressure

Annex B is precise. Filled in from memory at 2 a.m., it is incomplete or wrong — and a wrong notification is its own problem.

The obligations after the filing

The 72-hour notification is the beginning. The 7-day data-subject notice and the 30-day phased update are where organisations quietly fall over once the crisis passes.

What you get

Any employee can start it. Only the DPO can file it.

No “who do I tell” bottleneck

Any employee can start the clock immediately on discovery. No DPO gatekeeping is required to begin — only to file.

The deadline is watched for you

A live 72-hour countdown from the awareness timestamp, cross-checked against the form's own “submitted within 72 hours?” answer, with staged reminders at T-48h, T-24h, T-4h and overdue.

The official fields, not a memo

Notification is structured into the exact Annex B fields, cutting errors against completing a static form under pressure.

Governance preserved

Server-enforced DPO review: submitted → under review → approved or rejected → filed. Nothing can be recorded as filed before DPO approval, and nothing auto-files with the Commissioner.

Downstream obligations automated

The deadline engine spawns the 7-day data-subject notification and 30-day phased-update clocks so they are not forgotten once the initial filing is done.

Process-integrity evidence

An append-only, SHA-256 hash-chained audit log with a tamper-detection endpoint provides evidence of the process for the Commissioner or in a later dispute.

How it works

Discovery to filing, with the DPO in the loop.

Built for the phone in the pocket of whoever finds the problem — and for the DPO who has to sign what goes out.

01
Start on discovery

Any employee opens the wizard on a phone. The awareness timestamp starts the 72-hour countdown; no personal data leaves the device until the user actively submits.

02
Answer Annex B

22 questions mirroring the official notification form, section by section, in the Commissioner's own wording.

03
Triage significant harm

Automated triage across the five statutory triggers, including an automatic flag when more than 1,000 data subjects are affected.

04
Route to the DPO

The draft is emailed to the DPO as a pre-filled Annex B preview and enters the review queue: submitted → under review → approved or rejected.

05
File — and only then

The DPO files with the Commissioner. The system will not record a notification as filed without DPO approval.

06
Run the downstream clocks

7-day data-subject notification and 30-day phased-update deadlines are spawned automatically, with staged reminders until each is closed.

What is inside

The whole s.12B workflow, on a phone.

Mobile-first wizard

A 22-question wizard mirroring the official Annex B form verbatim across all sections — no framework, loads instantly, works on any phone.

Significant-harm triage

Automated triage across the five statutory triggers, including an auto-flag for more than 1,000 affected data subjects.

Live 72-hour countdown

From the breach-awareness timestamp, cross-checked against the form's own “submitted within 72 hours?” answer.

Server-enforced DPO review

Submitted → under review → approved / rejected → filed. Nothing can be recorded as filed before DPO approval.

Deadline engine

Downstream 7-day and 30-day clocks with T-48h, T-24h, T-4h and overdue reminder emails.

Hash-chained audit log

Append-only, SHA-256 hash-chained, with an audit-verification endpoint for tamper detection.

Annex B report preview

Downloadable, printable and emailable as a pre-filled draft to the DPO.

Client-only until you submit

No personal data leaves the device until the employee actively submits the draft.

Token-gated DPO console

A separate, access-controlled review screen for the DPO, designed to sit behind your identity provider.

Built to be defended

Governance first, speed second — and both on the record.

Authority
The DPO retains sign-off. The workflow makes it faster to reach them, not possible to bypass them.
Timestamps
Awareness, submission, review and filing are all recorded against the countdown, so the 72-hour question has an answer with evidence.
Audit log
Append-only and SHA-256 hash-chained, with a verification endpoint — process-integrity evidence for the Commissioner or a later dispute.
Data handling
The wizard runs client-side; nothing is transmitted until the employee submits. Submitted payloads are stored structured, not as loose documents.
Testing
An end-to-end integration suite runs against a real database on every change to the review workflow.
Roadmap, stated plainly
Bahasa Malaysia toggle, PDF export, offline support and SIEM/ITSM integration are open items. We describe them as direction, not availability.

Who runs it

Law firms

Give every client a breach-reporting front door that lands in the firm's review queue — with the record already structured in Annex B when the call comes in.

Enterprise DPOs

One intake for every entity and site, a review queue you control, and downstream clocks that do not depend on someone remembering.

Clinics, e-commerce, hotels & rentals

The same 72-hour clock applies to a clinic or a rental operator as to a bank. This is how a small team meets it without a privacy department.

How to get it

Early access — for organisations that want the record ready before the breach.

Praxis Breach is a working release. We are opening it to a small number of organisations who will run real drills through it and tell us where it breaks. It is included in every suite plan as it ships.

Early access · working v1

Request early access

Tell us how breach reporting works in your organisation today — who finds it, who files it, and how the DPO gets involved. We will set you up and walk your team through a drill.

  • Working v1 backend and mobile wizard
  • Included in every suite plan as it ships
  • Founding-cohort terms through the Design Partner Programme
Common questions

Before you commit.

That is the point. The wizard is designed for the person who discovers the breach, on their phone, with the Commissioner's own questions in order. They cannot file — only the DPO can — but they can start the record immediately.

No, and it never will. The DPO reviews, approves and files. The system enforces that order and records it.

The deadline engine spawns both clocks the moment the initial notification is approved, with staged reminders until each is closed.

Not yet. A BM toggle, PDF export, offline support and SIEM/ITSM integration are open roadmap items.

Request early access. We are onboarding a small number of organisations now, and Praxis Breach is included in every suite plan as it ships.

No. Praxis Breach structures the notification and evidences the process. Whether and what to notify remains the decision of the DPO and appropriately qualified advisers.

Praxis Breach structures and evidences professional analysis. It does not provide legal advice, and it does not replace the review and approval of an appropriately qualified person before reliance or issue.

PDPA Act 709 (Act A1727 amendments)s.12B breach notification · Annex B72-hour · 7-day · 30-day clocks
Part of the Praxis suite

One subscription. Every application.

Every suite plan includes all seven applications as each ships — licensed by client workspace, never by seat. See plans.

Any employee starts it. Your DPO signs it. The clock is watched for you.

Run a breach drill through Praxis Breach.

Praxis BreachRequest early access