The Nullware Standard0 trackers on this page
Pledge 05 · Honesty when it goes wrong

If something goes wrong, you hear it from us first.

No system is perfect. What earns trust is how a business behaves when something fails. Members tell the people affected directly, plainly and quickly, before they read about it anywhere else.

72 heveryone else, afteryou, first
01

What usually happens instead

The breach is bad. The silence afterwards is often worse.

01
Finding out from the news
Customers learn about an incident weeks later, from a headline.
02
Unreadable notices
Legal wording that doesn’t say what was taken or what to do.
03
Minimising
“A small number of accounts” that turns out to be everyone.
04
No follow-up
Nothing about what caused it or what changed afterwards.
The pledge
The people affected hear it from us, first and plainly.

Every member keeps a written plan for data incidents. When someone gets unauthorised access to customer data, the people affected hear within 72 hours of the member confirming it: what happened, what was involved, and what to do. A lost device that was encrypted doesn’t count. The incident goes on the member’s public record within 30 days and stays for 24 months. Police or a regulator can ask for a delay; that changes when customers hear, never whether. This sits alongside any legal duty to report to a regulator.

Fineinside the line
Telling customers before every detail is known, then updating them.
Plain-language notices with clear next steps.
Offering practical help, like password resets or monitoring.
Publishing what was learned once the cause is fixed.
Neveroutside it
Waiting to tell customers until the story is public.
Notices designed to be ignored or misunderstood.
Understating how many people or what data was affected.
Keeping incidents off the public record.
02

When something goes wrong

The plan every member writes down in advance. Step three is the one that matters most to customers.

1
Discover
The member finds out, or is told, that customer data may have been exposed.
2
Contain
Stop it getting worse: close the gap, change credentials, secure what’s left.
3
Tell customers
Everyone affected hears it directly from the member within 72 hours, in plain language, with what happened and what to do.
4
Record it publicly
Within 30 days the incident goes on the member’s public record, with what was done about it. It stays there for 24 months.
5
Fix and review
Find the cause, fix it properly, and share what changed at the next review.
03

How we check

Members show us their written incident plan during review, including who makes the call to notify customers. At re-certification we look at any incidents since the last review and how they were handled against the plan.

This page is general information, not legal advice.
04

Questions

Does a breach mean losing membership?
No. Handling it honestly is exactly what the Standard asks for. Hiding it, or ignoring the plan, is what leads to removal.
Isn’t this already a legal requirement?
The law sets duties to report certain incidents, often to a regulator. The pledge adds the customer: they hear it directly, in plain words, whenever someone gets unauthorised access to their data.
Previous · pledge 04Every channelOn toThe Nullware Standard
Ready to be honest when it counts?

Membership tells customers you’ll be straight with them, especially on a bad day.

Apply to joinTake the self-check