1. What is a personal data breach?
- Availability Breach i.e. the loss, accidental or unlawful destruction of personal data
- Integrity Breach – an alteration or unauthorised change to personal data.
- Confidentiality Breach – unauthorised disclosure of or access to personal data
2. How does a personal data breach occur?
According to Verizon’s 2021 Data Breach investigations Report, data 85% of data breaches involved a human element. Employees are a big threat to data security and can cause breaches in several ways including:-
- inadvertent action e.g. sending data to wrong recipients
- negligent actions e..g failing to follow stipulated security policies
- malicious actions e.g. phishing attempts directed at employees or malicious actions by former employees
Some famous data breaches involving employees include the Snapchat data breach in which an attacker pretending to be the company’s CEO, Evan Speigel, tricked an employee into emailing payroll information. The information related to over 700 current and former employees. In 2020, hackers comprised the credentials of two Marriott employees and gained access to 5.2 million records of hotel guests. In 2018, a former CISCO employee gained unauthorised access to the company’s cloud infrastructure and deleted 456 virtual machines thereby compromising 16,000 WebEx customer accounts.
- device (e.g. laptops or mobile phones) theft or loss
- poor information security measures such as use of public WIFI networks; and
- external hacking attempts including malware, DDOS attacks
3. What should we do in case of a breach?
- nature of personal data breached. Regulation 35 (1) of the draft Data Protection (General) Regulations outlines types of data breaches that result in real harm to the data subjects.
- how the data breach occurred – time, key actors
- number of people of affected
- the impact of the breach on affected individuals
4. What is the best way to manage a breach?
There is no standard way of responding to a data breach, it all depends on the nature and size of your organisation. A good starting point would be to develop an incident response plan. The DPO should assemble an internal team to help in formulating the plan. The plan should articulate the steps to take in the event of a breach. In particular,
- how to identify and how to escalate the breach to the privacy team. Ideally, all breaches should be escalated to the privacy team who in turn should form a response team.
- the plan should outline a criteria for assessing and rating the severity of the risk (the criteria in point 3 above can be included in the assessment matrix)
- identify members of the response team and their roles and responsibilities. This includes responsibilities around investigation and actions to take in addressing the breach. The response team should include a broad range of stakeholders within the organisation e.g. IT, Risk, Compliance, HR, Customer Service, Legal, CEO and the Board etc
- how to notify the Data Commissioner and the data subjects of a breach
5. What information should a breach notification contain?
- the date and time
- how it arose including classes and volume of data affected
- the number of persons affected and potential harm
- the actions taken to contain it and prevent future occurrence