Cyber Law & Compliance

Null Stackers is built compliance-first — from the Prevention of Electronic Crimes Act (PECA) 2016 to Global GDPR standards.

Download Audit Report

PECA 2016 Mapping

PECA SectionOffencePrimary Technical DefenceSecondary Defence
Section 3Unauthorised AccessMFA + JWT Short-ExpiryRate Limiting + RBAC
Section 6Data DamageParameterised Queries (ORM)Input Validation + CI Lint
Section 9Electronic FraudImmutable Escrow Audit TrailAnomaly Detection Alerts

Data Breach Incident Response Plan

Under GDPR / NIST SP 800-61 / ISO/IEC 27035

72-Hour Legal Window
0 – 2 Hours

Identification & Containment

Lead
CTO (Muhammad Umer)
Legal Basis
GDPR Art. 33
  • Isolate affected server/service
  • Revoke compromised tokens
  • Capture forensic snapshots
  • Alert founders (CEO, CTO, COO, CMO)
2 – 12 Hours

Investigation & Scope

Lead
CTO + COO
Legal Basis
GDPR Art. 33(3)
  • Log analysis (SIEM/CloudWatch)
  • Enumerate affected data subjects
  • Determine root cause (CVE/Injection)
  • Classify Severity (Tier 1-3)
Within 72 Hours

Notification

Lead
CEO (Hanzala) + Legal
Legal Basis
GDPR Art. 33 / PECA 2016
  • Notify EU DPA / FIA Wing
  • Trigger automated user emails
  • Force password resets
  • Publish Platform Status Notice
24 – 96 Hours

Remediation & Recovery

Lead
CTO + Engineering Team
Legal Basis
GDPR Art. 32
  • Patch/Remove vulnerability
  • Rotate ALL secrets (DB, JWT, API)
  • Restore from clean hashed backup
  • Full penetration test of component
Within 30 Days

Post-Incident Review

Lead
All Founders (3-of-4 Vote)
Legal Basis
GDPR Art. 5(2)
  • Conduct formal PIR meeting
  • Update security policies
  • Implementation of new controls
  • Final closure report to regulators

Compliance Framework Reference

GDPR

European Union

72-hr notification, data minimisation, right to erasure.

PECA 2016

Pakistan

Criminalises unauthorised access, data damage, electronic fraud.

IT Act 2000

India

Section 43A - Data protection for sensitive personal data.

ISO/IEC 27035

Global Standard

5-phase IRP: Plan, Detect, Assess, Respond, Learn.

NIST SP 800-61

Engineering

Preparation, Detection, Analysis, Containment, Recovery.

PDPA (Draft)

Pakistan

Consent-based collection and localisation requirements.