HPMA Data Breach Process

HPMA Data Breach Process

This document outlines the action steps and responsibilities to be taken in the result of a data breach of information covered by the General Data Protection Regulations. 

A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. This includes breaches that are the result of both accidental and deliberate causes. It also means that a breach is more than just about losing personal data. 

Examples of a data breach are* :- 

  • access by an unauthorised third party; 
  • deliberate or accidental action (or inaction) by a controller or processor; 
  • sending personal data to an incorrect recipient; 
  • computing devices containing personal data being lost or stolen; 
  • alteration of personal data without permission; and 
  • loss of availability of personal data. 

 *NB this list is not exhaustive, if you are not sure please contact the Data Protection Officer 

Actions to take after a data breach  

Data Protection Officer Lorna Reeves & Data Controller Julie Rogers 

1) Inform your Data Protection Officer (DPO)Upon noticing there has been a data breach (someone has accessed, or shared information protected by GDPR and secure storage). 

The obligation of notifying and keeping watch for a breach falls to all involved in the handling of data, regardless of role. 

On notifying the Team, we must determine the information that has been leaked or stolen. 

2) Assess scope and impact: Identify the extent of the impact, and the scope of the personal data breach; i.e.: 

  • Ascertain that personal data was breached. 
  • Estimate the number of data subjects whose personal data was possibly breached. 
  • Determine the possible types of personal data that were breached. 
  • List security measures that were already in place to prevent the breach from happening. 

As personal data breaches are to be reported within 72 hours by the controller, this step should be a high priority and should focus on providing sufficient information to the DPO for this notification to the Data Protection Authority. 

3) Notify the relevant parties: The DPO of your organisation should inform the Data Protection Authority if your organisation is the controller of personal data. If the risk to the rights and freedoms of data subjects is high, the data subjects should also be informed by the DPO of the controller. However, if your organisation is the processor of personal data, the DPO should notify the responsible person stated in your contract with the controller. 

The communication should include contact details of the DPO, details of the breach, likely impact, actions already in place, and those being initiated to minimise the impact of the data breach. Also, it is important to mention that further impact is being investigated (if required), and necessary actions to mitigate the impact are being taken. 

4) Deep dive, contain and notify: While the DPO is notifying the relevant authorities, it is critical that the incident team continues the deep dive on the following two tracks in parallel: 

  • Taking all possible measures to reduce the risk and contain further unauthorised access – this may be to move the data, changing passwords and protections. 
  • Continuing to refine the original estimate of the number of data subjects breached and the types of personal data that were breached 

As details are being discovered, the DPA or controller may be updated on the current situation. 

If the freedoms and rights of data subjects are significantly impacted, the DPO of the controller would need to decide if the data subjects also need to be informed. If so, the public relations or communications team of the company should be involved in this communication. 

5) Review and monitor: Once the personal data breach has been contained, the organisation should conduct a review of existing measures in place and explore the possible ways in which these measures can be strengthened to prevent a similar breach from reoccurring. All such identified measures should be monitored to ensure that the measures are satisfactorily implemented. 

And, while you take the above steps, always keep a log of your actions and keep a data breach register.  

Actions of the Data Protection Officer 

Contact the Data Controller, you must compile a report of the company name, data and type of breach. Estimation (if not known) of the type of information breached and number of those affected. 

The UK Data Protection regulator is the ICO https://ico.org.uk/for-organisations/ 

After discussion with the Data Controller, if the initial view is that the matter requires reporting, access the ICO site, click ‘Report a Breach’ and follow the self-assessment to ascertain if this breach needs to be formally reported. Follow the step-by-step actions on the site. 

 

Date Prepared: 4th January 2025 

 Prepared By:  Lorna Reeves 

 Agreed By:      Trustees, January 2025  

 Date Reviewed: (due January 2026) 

More Similar Posts