# V2 Privacy Ops On-Call Runbook

Privacy ops maintains 24/7 breach-response coverage for launch services. The
rotation is owned by the DPO delegate, supported by security incident command,
legal, customer support, platform relations, and regional counsel.

## Rotation

| Role                       | Primary duty                                                                    | Backup           |
| -------------------------- | ------------------------------------------------------------------------------- | ---------------- |
| Privacy incident commander | Opens the incident, starts the legal clock, owns the decision log               | DPO delegate     |
| DPO delegate               | Determines privacy impact, regulator path, and DSR implications                 | Privacy counsel  |
| Security incident lead     | Preserves evidence, scopes systems, coordinates containment                     | SRE lead         |
| Legal escalation           | Applies privilege where appropriate, approves notices                           | Regional counsel |
| Player communications      | Drafts player notices and support macros                                        | Support director |
| Platform relations         | Notifies Sony, Microsoft, Nintendo, Steam, Epic, and cloud partners as required | Release manager  |

The on-call schedule is reviewed weekly and before each release gate. Any gap in
commander, DPO, security, or legal coverage blocks release promotion.

## Breach SLA

The breach clock starts when the privacy incident commander confirms that a
security incident involves personal data. The default notification target is 72
hours for GDPR-style obligations. Local rules can be stricter or use a different
clock, so the commander records the applicable framework in the incident brief
before any external notice is sent.

Brazil incidents that create relevant risk or damage route to ANPD review under
the LGPD incident workflow. Quebec incidents route to Quebec CAI and affected
persons where Law 25 criteria are met. Platform incidents also follow the
applicable platform DPA and security addendum.

## First Hour

1. Create the privacy incident record in the audit platform.
2. Assign incident commander, DPO delegate, security lead, and legal escalation.
3. Freeze routine deletion jobs for potentially relevant evidence.
4. Identify affected systems, data categories, regions, age bands, and
   sub-processors.
5. Capture the initial risk statement, containment status, and decision log.

## First 24 Hours

1. Complete data-subject impact scoping.
2. Determine whether minor accounts, sensitive categories, authentication data,
   payment data, or moderation evidence are involved.
3. Validate cross-border processor involvement and DPA notice duties.
4. Draft regulator, platform, and player notices.
5. Decide whether staged notification is required because facts remain
   incomplete.

## First 72 Hours

1. Send required regulator and player notifications or record why notification
   is not required.
2. Publish support macros and account-protection steps.
3. Add the incident to the quarterly privacy review packet.
4. Create remediation owners, due dates, and verification evidence.

## Erasure And DSR Hold

When an incident intersects with active erasure, access, portability, or
rectification requests, privacy ops records whether legal hold limits
fulfillment. The subject receives the normal DSR confirmation plus any legally
required explanation of delayed or partial fulfillment.

## Closeout

Closeout requires DPO and legal approval, audit-platform export, player/support
communications signoff, and a post-incident review. Sanitized learnings feed the
public quarterly privacy summary when disclosure does not create security,
privacy, or privilege risk.
