Personal Data Breaches occur when a person's data has been accidentally or unlawfully:
- Destroyed
- Lost
- Altered
- Disclosed without authorisation, whether that be accidentally or deliberately.
What is required when a breach happens?
Under the GDPR, it is required that when certain types of breaches involving personal data occur, these will need to be reported to the relevant supervisory authority within 72 hours of becoming aware of it. Following on from this, should the breach be of such a high risk to the data subject, they should be informed without delay.
Records will need to be maintained by the party who is liable for the breach. The way in which you will need to assess the breach is to identify the risk the breach poses to the data subject's rights and freedoms as well as the severity of that risk. We would recommend legal advice is taken at that stage, if not, documentation is key to being able to justify why a breach has not been reported.
However, with appropriate measures to prepare for, manage and react to data breaches and ultimately reduce the possibility of their occurrence, it is possible that certain breaches do not have to be reported. It is therefore key to establish how in your day to day business, breaches could occur. It is very easy for these to happen, for example leaving your phone on the train or sending an email to the wrong recipient. Certain scenarios require simple solutions; however this will not always be the case.
Should a breach need to be reported, Article 33 of the GDPR sets out what needs to be reported when a breach occurs, this includes:
- The nature and extent of the personal breach
- Who your Data Protection Officer or other point of contact is, and their contact details
- What are the likely consequences of this data breach
- Measures taken by yourself as the controller to address and mitigate the effects of the breach itself
Any failure to disclose a breach, even if this be due to internal analysis suggesting it does not need to be reported, may result in the aforementioned fines. Therefore advice should always be sought in these scenarios.
Our skilled Dispute Resolution Team can help individuals and businesses to resolve disputes relating to Data Protection. This may include disputes about the processing of personal data, the right to erasure, and the right to object to processing.