Incident Response Policy
Established: August 1, 2026 / Last updated: August 22, 2026 / Published: August 19, 2026 / 日本語
1. Purpose
This policy defines the framework and procedures of Daiichi Co., Ltd. (the "Company") for responding quickly and appropriately to information security incidents (data breaches, unauthorized access, system outages, etc.) — or suspected incidents — involving systems, applications, and data obtained from the TikTok Platform (collectively, "Covered Data"), in order to minimize damage.
2. Roles and Responsibilities
The Company operates with an effective staff of one person; the same individual holds all roles — CEO, technical operations, and security practice — enabling rapid decision-making and execution.
-
Incident Commander: Koji Sugawa
- Responsibilities: Incident awareness, containment decisions, investigation of scope and impact, execution of corrective measures, and reporting to external parties (TikTok, affected users, legal authorities, etc.).
3. Definition of Incidents
Incidents covered by this policy include:
- Leakage of TikTok API access keys or credentials (access tokens, etc.)
- Unauthorized access to servers or databases storing Covered Data
- Compromise of development devices or environments through malware or ransomware
- Accidental deletion or alteration of user data, or misdirected transmission to external parties
- Detection of data use that violates TikTok terms or our Privacy Policy
4. Response Procedures (Communication Pathways and Flow)
Step 1: Detection and Containment
- Upon detecting an anomaly (alerts, logs, external reports), immediately isolate the affected server, account, or network segment to prevent further damage.
- Revoke or reset access to the TikTok API (tokens).
Step 2: Investigation
- Analyze access logs and system history to determine what happened, when, how, and identify the scope of affected data (number of records and fields).
Step 3: Notification and Reporting
- Reporting to TikTok: If a leak of TikTok user data is detected or suspected, promptly notify the support channel or designated incident reporting channel via TikTok Partner Center, in accordance with TikTok's terms.
- Reporting to users and authorities: If a personal data breach occurs and notification obligations arise under applicable law (including Japan's APPI), promptly notify affected individuals and report to the Personal Information Protection Commission and other relevant authorities.
Step 4: Recovery and Lessons Learned
- Fix the vulnerability and restore data from verified-safe backups.
- Review root causes and implement preventive measures (password changes, MFA hardening, firewall rule revisions, etc.).
5. Contact Point
- Organization: Daiichi Co., Ltd.
- Incident contact: Koji Sugawa, Representative Director
- Email: kufajp@903k.com
Established: August 1, 2026
Last updated: August 22, 2026
Responsible party: Koji Sugawa, Representative Director
