By
Alex Franch
February 1, 2023
As an SME, your organisation must understand what a data breach is, how to identify one and when it should be notified to the Information Commissioner's Office (ICO). The below blog post outlines the basics of data breaches with examples to help you contextualise this for your organisation.
Contents
What is a data breach?
Data breaches are defined by the GDPR as:
“A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed” (Article 4(12) GDPR).
Article 29 Working Party Guidelines (WP29) further clarifies the above to mean:
What about the temporary loss of data?
The WP29 guidance advises that temporary loss of data can be a data breach if the lack of access impacts the rights and freedoms of individuals (example of this below). If the temporary loss is more serious then the breach may even need to be notified to the ICO. In any case, temporary data loss should be documented as with permanent losses of data to show your organisation’s accountability.
What is personal data?
Personal data is defined under Article 4 (1) GDPR as:
“Any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person”.
It can be both objective, such as the name and email of a person or subjective, such as thoughts and opinions on them, for example, when organisations make assessments on individuals to provide them access to products like banking or insurance. Subjective data also includes data of an individual’s viewpoints and their interactions within society like their behaviours and actions. WP29 also draws our attention to how data need not be accurate or correct to be considered personal data; this is why the GDPR have separate provisions for correcting wrongly held information.
Personal data also has to relate to natural persons. A person is a natural person from birth until their death, regardless of their nationality or residency as the right to privacy is considered a universal right. Whilst the rules on data related to the deceased are slightly different, WP29 suggests that it may be easier to treat them the same way as that of natural persons because the data of the deceased may indirectly contain data to the living. For example, sensitive data on a deceased person with haemophilia may indirectly identify their offspring with the same condition.
What is not personal data?
Data relating to organisations are not considered personal data. Other information not considered personal data include:
However, this does not mean that national data laws cannot apply which deems certain data as personal data. Other legal regimes unrelated to data regulations may also apply such as criminal or intellectual property law. Your organisation may need to assess this on a case by case basis.
Examples of data breaches
See a detailed analysis of the impact of leaked data for this one hotel reservation platform where the credit card details of over 100,000 customers were exposed here.
When should the ICO be notified?
If you experience a personal data breach you need to consider whether this poses a risk to people and the likelihood and severity of the risk to people’s rights and freedoms, following the breach. After this assessment, if it’s likely there will be a risk then you must notify the ICO; if it’s unlikely then you don’t have to report it but you must justify this decision and document it.
If you are reporting a breach, it should be reported to the ICO without undue delay and within the first 72 hours of the breach, starting from when you became aware of it. A failure to notify the ICO of a relevant data breach may lead to a fine of up to EUR 10m or 2% of your annual global turnover, whichever is higher.
Click here for an online assessment of whether you should report to the ICO.
You should also assess the impact on individuals as organisations should report a data breach to data subjects without undue delay if there is ‘a high risk to the rights and freedoms of natural persons’, for example, if the data breach infringes on their safety in any way. However, the threshold for reporting to data subjects is a higher bar than reporting to the ICO so it is likely that you would need to report to the ICO first, in any case. In other instances, reporting a data breach to data subjects too often can sometimes cause fatigue so that a serious one is not taken with the gravity it deserves.
For information on how to notify a data breach, please see our future post on notifications.
How to prevent a data breach?
Conducting risk assessments such as a Data Protection Risk Assessment (DPIA) and recording this can help you minimise data breaches. Risk assessments can help you identify how old your software is, where vulnerabilities may lie and the level of training your staff have received for you to manage the overall likelihood of a data breach within your organisation. The Privasee dashboard is a quick and simple way for your organisation to keep on top of these components and helps you coordinate the intersection between multiple risk conditions. With features that help you record the time and date of DPIAs and the person responsible for conducting them can help you better manage your overall data risks with increased oversight. Preventing data breaches need not be costly nor a headache with the right tools.
*https://ec.europa.eu/info/law/law-topic/data-protection/reform/what-personal-data_en
**https://kyc-chain.com/how-to-identify-a-data-breach-and-report-it-quickly/
Disclaimer
This article does not constitute legal advice in any form and only seeks to break down some of the main points set out by publicly available sources such as the ICO.
Sources and further resources
European Commission - What is Personal Data?
Article 29 Working Party Opinion 4/2007 on the concept of personal data
Article 29 Working Party Guidelines on Personal data breach notification under Regulation 2016/679
Ensure your policies are always up to date with Privasee, an AI powered GDPR compliance solution that does it all.