We apply technical and organizational measures according to the type of data: HTTPS, access limited by role, httpOnly session cookie, private S3 bucket with SSE-AES256 encryption, CV downloads through short-lived signed URLs, file type and size limits, and Turnstile on the contact and rights forms.
If a security incident causes accidental or unlawful destruction, leak, loss, alteration, disclosure or unauthorized access, and there is a reasonable risk to your rights, we will report it to the Agency by the most expeditious means and without undue delay (Article 14 sexies). We keep an internal record of the nature of the incident, its effects, the categories and approximate number of people affected, and the measures taken.
If the incident involves sensitive data (for example CVs that may include health or union membership, or expected salary as socioeconomic data), data of children under 14, or economic, financial, banking or commercial data, we will also notify each affected person in clear language: which data, possible consequences and the measures adopted. If individual notice is not possible, we will publish a notice in a nationwide mass medium.