Beiträge in diesem Abschnitt

Data breach & GDPR

What: The following guidelines should clarify what personal data breach under GDPR is, and what Support must do the moment a possible breach comes up.

Why: GDPR sets strict rules for spotting, escalating and reporting personal data breaches, including tight deadlines. This guide gives Support a clear way to tell the difference, and a fixed process to follow once a breach is confirmed.

How: Use the decision tree below to check whether something is a personal data breach, then follow the reaction steps if it is.

What data types can be critical?

data-classification-table2.png

What is a personal data breach?

Under GDPR, a personal data breach happens when a security failure leads to personal data being accidentally or unlawfully destroyed, lost, altered, or disclosed to/accessed by someone who shouldn’t have it. It doesn’t have to be intentional, and it doesn’t have to involve an outside attacker – an honest mistake counts too.

There are three types:

Confidentiality breach

Personal data is disclosed to, or accessed by, someone who shouldn’t see it (e.g. an email sent to the wrong recipient, a document shared with the wrong permissions).

Integrity breach

Personal data is altered without authorisation (e.g. records changed by mistake, or by an attacker).

Availability breach

Personal data is lost, or access to it is lost, without a proper backup (e.g. a stolen laptop, a deleted database, a ransomware attack).
 

Quick examples:

Usually a breach

An email with personal data sent to the wrong recipient · a laptop or phone with unencrypted customer data is lost or stolen · a support agent’s login is compromised and used to view schools’ data · a misconfiguration exposes one school’s data to another · a file with personal data is accidentally published publicly.

Usually not a breach

A customer mistypes their own information into a form · a phishing email is received but not opened or acted on · an authorised colleague accesses a record as part of their normal job · a planned system change makes a feature briefly unavailable with no data affected · a user has simply forgotten their password, with no sign of unauthorised access.

Decision tree

Step 3: Reaction in case of data breach

  1. Inform your manager and the DPO right away
    As soon as you suspect a breach, contact your manager (Torben) and the DPO (Sandra K). Don’t wait until you’re fully sure, as GDPR requires fast action, so it is more important to be quick than to be completely sure.
  2. Log it as a ticket
    Write a ticket including: date/time, what data was affected, who is affected, the likely cause, and the possible consequences. Tag it "GDPR/Data Breach" and set the priority to Urgent.
  3. Escalate to the DPO
    Send the ticket information to the DPO so the breach can be logged centrally. Contact Sandra K through teams, and do not assign a ticket to her!
  4. Follow-up steps
    • Agree on ownership

Agree with your manager and/or the DPO who will be responsible for handling the follow-up actions.

  • Notify affected customers

The responsible person notifies the GDPR contact(s) at the affected school(s), within the required timeframe.

  • Authority reporting, if required

The DPO decides whether the breach must be reported to the Danish Data Protection Authority (Datatilsynet), and handles that reporting. SpeedAdmin only reports internal data breaches to the DPO, as breaches concerning customer data are handeled by the customers themselves.

Not sure whether something is serious enough to escalate? Always ask your manager or the DPO rather than deciding on your own.

Good to know:

GDPR gives a 72-hour deadline from the moment a breach is discovered for reporting it to the Data Protection Authority, when reporting is required. This is why speed – informing your manager and the DPO immediately – matters more than being 100% certain before you say anything.

War dieser Beitrag hilfreich?
0 von 0 fanden dies hilfreich