Insights from EDPB’s Latest Case Digest on Data Security and Breach Notification

14th February 2024

The European Data Protection Board (EDPB) is an independent European body that ensures data protection laws are applied within the EU. This January, they unveiled a comprehensive one-stop-shop case digest, focused on Security of Processing and Data Breach Notification. This pivotal publication marks a significant step in the ongoing journey towards robust data protection practices. This case digest was produced by the EDPB’s Support Pool of Experts (SPE), a group of experts in different fields of data protection law. View here

This case digest delves into the nuanced areas of data security and data breaches, and how the GDPR is applied to real-world scenarios. From tackling sophisticated cyber threats like hacking and ransomware to addressing inadvertent data exposures, the digest provides a 360-degree view on the enforcement and interpretation of GDPR’s Article 32 on security of processing and Articles 33 & 34 on data breach notification. Documents like this help to guide data protection authorities and organisations on what actions to take in the event of a security breach. 

Insights From The Case Digest

Here’s an example of a case involving a data breach, and how the Controller handled it.

A data breach occurred due to a malicious attack. The breach involved unauthorised access to personal data, potentially compromising sensitive information. Upon discovering the breach, the Controller (the organisation ultimately responsible for managing personal data) took immediate action. They isolated their systems to contain the cyber attack and conducted a forensic analysis to understand the extent of the breach.

Key Actions Taken

System Isolation

The Controller closed their servers and isolated the systems, a crucial step in containing the breach and preventing further unauthorised access.

Forensic Analysis

A thorough analysis was conducted to understand the breach’s nature, scope, and impact. This helped in identifying the compromised data and the breach’s source.

Technical Measures at the Network Level

The organisation implemented technical measures to secure its servers and network, such as activating existing backups and enhancing server security,

Involvement of Senior Management and Legal Teams

This approach ensured that the incident was managed with the appropriate level of seriousness and compliance.

Post-Breach Measures

Post-incident, the organisation took steps to strengthen its overall security posture. This included hiring an external security company for an audit, reviewing and updating security measures, and monitoring IT tools.

Regulatory Compliance and Notification

In line with GDPR requirements, the Controller documented the breach, assessed the risk to individuals’ rights and freedoms, and notified the relevant supervisory authority within the mandated timeline.

This example demonstrates the importance of having robust incident response plans and the need for immediate action following a data breach. The case also illustrates the GDPR’s comprehensive approach, requiring both preventive measures and a well-orchestrated response to data breaches.

A Valuable Resource

This digest is a vital resource for Data Protection Authorities (DPAs) and organisations alike, as it features detailed analyses of various security incidents and how they were handled. This can enhance their understanding of the law and increase their ability to respond promptly to any future data breaches. For organisations, this document can highlight the adequacy of their data security measures and give them a chance to preemptively assess and strengthen their data protection frameworks, ensuring compliance with GDPR mandates. Thus, the case digest is not just a record of past decisions; it’s a dynamic tool for continuous improvement in data security practices.

You can read the full case digest at the EDPB website here. 

 

Author: Paul Adams LLB (HONS)

Paul is an information governance specialist and one of the founder Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details