Cyber Law & Compliance
Null Stackers is built compliance-first — from the Prevention of Electronic Crimes Act (PECA) 2016 to Global GDPR standards.
Download Audit ReportPECA 2016 Mapping
| PECA Section | Offence | Primary Technical Defence | Secondary Defence |
|---|---|---|---|
| Section 3 | Unauthorised Access | MFA + JWT Short-Expiry | Rate Limiting + RBAC |
| Section 6 | Data Damage | Parameterised Queries (ORM) | Input Validation + CI Lint |
| Section 9 | Electronic Fraud | Immutable Escrow Audit Trail | Anomaly Detection Alerts |
Data Breach Incident Response Plan
Under GDPR / NIST SP 800-61 / ISO/IEC 27035
72-Hour Legal Window
0 – 2 Hours
Identification & Containment
Lead
CTO (Muhammad Umer)
Legal Basis
GDPR Art. 33
- Isolate affected server/service
- Revoke compromised tokens
- Capture forensic snapshots
- Alert founders (CEO, CTO, COO, CMO)
2 – 12 Hours
Investigation & Scope
Lead
CTO + COO
Legal Basis
GDPR Art. 33(3)
- Log analysis (SIEM/CloudWatch)
- Enumerate affected data subjects
- Determine root cause (CVE/Injection)
- Classify Severity (Tier 1-3)
Within 72 Hours
Notification
Lead
CEO (Hanzala) + Legal
Legal Basis
GDPR Art. 33 / PECA 2016
- Notify EU DPA / FIA Wing
- Trigger automated user emails
- Force password resets
- Publish Platform Status Notice
24 – 96 Hours
Remediation & Recovery
Lead
CTO + Engineering Team
Legal Basis
GDPR Art. 32
- Patch/Remove vulnerability
- Rotate ALL secrets (DB, JWT, API)
- Restore from clean hashed backup
- Full penetration test of component
Within 30 Days
Post-Incident Review
Lead
All Founders (3-of-4 Vote)
Legal Basis
GDPR Art. 5(2)
- Conduct formal PIR meeting
- Update security policies
- Implementation of new controls
- Final closure report to regulators
Compliance Framework Reference
GDPR
European Union
72-hr notification, data minimisation, right to erasure.
PECA 2016
Pakistan
Criminalises unauthorised access, data damage, electronic fraud.
IT Act 2000
India
Section 43A - Data protection for sensitive personal data.
ISO/IEC 27035
Global Standard
5-phase IRP: Plan, Detect, Assess, Respond, Learn.
NIST SP 800-61
Engineering
Preparation, Detection, Analysis, Containment, Recovery.
PDPA (Draft)
Pakistan
Consent-based collection and localisation requirements.