What to do if your organisation experienced a data breach

A data breach is a critical incident that occurs when unauthorised individuals gain access to sensitive or confidential information, potentially compromising the security and privacy of individuals or organisations. In today’s interconnected digital landscape, the risk of data breaches is a pressing concern for businesses and individuals alike. Recognising and promptly addressing a data breach is crucial not only for mitigating the immediate impact but also for safeguarding against long-term consequences.

This article aims to guide you through the essential steps of responding to a data breach – from understanding why reporting is imperative to outlining the process of reporting. In the ever-evolving realm of cybersecurity, knowledge is critical, and being equipped with the right information empowers individuals and organisations to navigate the challenges posed by data breaches effectively.

 

Is data breach a serious incident ?

Short answer: Yes, it is. The organization that experienced a data breach will be legally required to take some steps, which vary depending on the extent of the data breach. In some cases, notifying the relevant Data Protection Authority will be required.

Where to report data breach in UK ?

In the UK, the relevant Data Protection Authority is the Information Commissioner’s Office (ICO) – website ico.org.uk

Its approach is to encourage compliance. Where it finds issues, it take fair, proportionate and timely regulatory action to guarantee that individuals’ information rights are properly protected. If a data breach occurs, and it is likely to result in a risk to the rights and freedoms of individuals, organisations are generally required to report the breach to the ICO.

The reporting of a data breach is subject to the General Data Protection Regulation (GDPR) and the Data Protection Act 2018.

Does every incident must be reported ?

You need to consider the likelihood and severity of the risk to people’s rights and freedoms, following the breach . . . if it’s likely there will be a risk then you must notify the ICO; if it’s unlikely then you don’t have to report. You do not need to report every breach to the ICO

No, not every incident must be reported. As we can red on ICO website: “You need to consider the likelihood and severity of the risk to people’s rights and freedoms, following the breach . . . if it’s likely there will be a risk then you must notify the ICO; if it’s unlikely then you don’t have to report. You do not need to report every breach to the ICO

Source: ico.org.uk/for-organisations/report-a-breach/personal-data-breach-assessment

On the same subpage there is also possibility to carry out a self-assessment that is necessary to determine whether your organisation have to report to the ICO or not.

Timeline for Reporting

Organisations must report a data breach to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it.

According to the information found on the ICO website, organisations must report a data breach to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it

Source: ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide

Report it even if you do not have all the details about a particular breach, and mention that you will provide the information within a few days. This is important.

If the breach is likely to result in a high risk to the rights and freedoms of individuals, the affected data subjects (individuals whose personal data has been compromised) may also need to be informed, usually by email or any other legally accepted means.

How to report a breach to the ICO?

For guidance use that page ico.org.uk/for-organisations/report-a-breach

You can find there 4 sections that help to determine where to report

  • UK GDPR personal data breach (DPA 2018)
  • Trust service provider breach (eIDAS)
  • Communications services security breach (PECR)
  • Digital Service Provider incident reporting (NIS)

Keep in mind that if there is a breach impacting individuals in EEA countries, it will involve the EU GDPR. Consequently, in your breach response strategy, it is crucial to determine the European data protection agency that would serve as the primary supervisory authority for the affected processing activities.

Information to include in the report

The GDPR specifies the information that should be included in a breach report to the ICO. This includes details about the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences of the breach, and the measures taken or proposed to address the breach.

If you have any doubt, seek for advice from the ICO

How internal reporting can help the organisation ?

Organisations are encouraged to have internal processes in place to detect, report, and investigate data breaches promptly. Internal reporting should involve the organisation’s data protection officer (if applicable) and relevant personnel.

It is crucial for organisations to document their response to the data breach, including the decision-making process, actions taken, and any communication with data subjects or the ICO. This documentation is essential for demonstrating compliance with the GDPR.

ICO is more likely to impose lower penalties or do not impose at all if it is seen that organisation take every possible step to prevent data breach or mitigate the possibility its occurrence. Organisations that can show they have implemented robust security measures, provided adequate training, and promptly responded to breaches are more likely to receive favourable consideration. Demonstrating a strong commitment to data protection and actively implementing measures to prevent breaches is always viewed positively.

Fines and Penalties if you fail to report to ICO

For serious breaches of the data protection principles, ICO has the power to issue fines of up to £17.5 million or 4% of your annual worldwide turnover, whichever is higher.

Failure to report a data breach when required to do so can result in fines and penalties. As we can read on ICO website “For serious breaches of the data protection principles, we have the power to issue fines of up to £17.5 million or 4% of your annual worldwide turnover, whichever is higher.

Source: ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-sharing/data-sharing-a-code-of-practice/enforcement-of-this-code

When to notify Law Enforcement ?

In certain cases, especially if the breach involves criminal activity, notifying the police or specialised cybercrime units may be necessary. Criminal activities associated with a data breach involve the use of the compromised information for illegal purposes. This may include activities such as hacking, identity theft, fraud, unauthorised financial transactions, ransom demands, cyber extortion, or other offences that exploit the data obtained through the breach. The criminal activities are the actions taken by malicious actors or cybercriminals who exploit the breached data for personal gain or to cause harm.

If you have any doubt what to do. There is a few organisations that provide help. The most important is The National Cyber Security Centre (NCSC). The NCSC may become involved to offer assistance, advice, and expertise.

Their website: ncsc.gov.uk

What is the Financial Conduct Authority (FCA)

You might have heard that if the data breach involves financial information or affects financial institutions you need to notify FCA as well. No, you do not need.

In the United Kingdom, there is a Memorandum of Understanding (MoU) between the Information Commissioner’s Office (ICO) and the Financial Conduct Authority (FCA). According to this MoU, if a personal data breach occurs in the financial services sector, the primary responsibility for notifying the FCA lies with the ICO.

Your responsibility is notifying the ICO. If necessary, the ICO will deal with the FCA directly.

Law you need to familiarise yourself with

It’s important for organisations to familiarise themselves with the specific requirements of the GDPR and the Data Protection Act 2018 and to update their data breach response plans accordingly. Do it in advance. Seeking legal advice can also be beneficial to ensure compliance with data protection regulations in the UK.