The Real-Life Consequences Of A Data Breach

30th September 2024

A data breach can have far-reaching consequences for an organisation and its customers, employees and stakeholders. A data breach is defined by the ICO as:

“a security incident that has affected the confidentiality, integrity or availability of personal data.” – Source

This could include data that is shared or leaked accidentally or as a result of a cyberattack or other deliberate attempts to obtain data unlawfully. Data doesn’t have to be stolen or go missing for a data breach to have occurred. Sending an email to multiple addresses without using a secure bulk mailing method or using ‘cc’ instead of ‘bcc’ could also constitute a breach. If the email was sent to an internal business email address, this could be okay (if a little unprofessional) but if it was sent to external email addresses, then this would be considered a personal data breach. It will all depend on the nature and category of personal data within, or attached to the email.

The term ‘loss’ within the GDPR obligation is given a very wide definition and could mean the loss of equipment containing personal data, loss of manual documents or corruption of datasets which you are unable to recover and for which there is no usable backup.

All potential personal data breaches must be reported internally

If you say to an employee ‘You must report any data breach to the compliance team’ I find that they start to engage in mental gymnastics. Is this a breach? is this not a breach? Do we need to report it? etc. We recommend to our clients that internally they do not use the term ‘breach’, but refer to ‘data incidents’. Your personal data breach policy, standard operating procedure or guidance can give out the very simple guidance, ‘If you suspect that a data incident has occurred, notify the Data Protection Officer (DPO), Compliance or IT Team immediately’. You can then give a few examples of what would be considered a data incident with your organisation. 

Should all data breaches be reported to the ICO?

As mentioned above, EVERY data incident needs to be reported internally to the relevant person or team. As part of the Integrity and Confidentiality and Accountability Principles, Organisations are obliged to keep accurate records of all data breaches regardless of their cause or seriousness. 

It is for the DPO or compliance lead to assess each incident and whether it reaches the threshold to report to the appropriate Regulator. In the UK, if an incident is reportable, it must be reported to the Information Commissioner’s Office (ICO) within 72 hours of the organisation becoming aware of the breach. 

When should a data breach be reported to the ICO? 

Article 33 of the UK GDPR sets out the threshold at which a Controller should report a personal data breach. However, the language is a little clumsy, it says:

In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons.’ 

In plain language, this means that a DPO, or compliance lead must assume that every incident is to be reported unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Risks and freedoms would refer to any situation in which an individual could suffer distress or harm, for example, physically, emotionally or financially.

If there is a possibility that an individual may suffer harm, damage or distress then a report must be made. If it is unlikely then no report needs to be made.

The data breach report to the ICO should contain information about the amount of individuals whose data is involved, how many personal data records were compromised, the contact information of the data protection officer (if there is one), the potential consequences of said data breach, and what measures have been or will be taken to mitigate the effects.

An organisation could become aware of a data breach without having all the information above right away. In these cases, the ICO can be informed of the breach within 72 hours, and the rest can be provided later, following an investigation to uncover the full extent of the data breach.

Prevention is better than cure

A Controller should have considered any potential risks to people’s rights and freedoms before any processing started by performing a DPIA, or data privacy impact assessment. This would avoid or minimise possible risks at the design or build stage.

Data breach consequences for individuals

As well as notifying the ICO of a data breach, the individuals whose data was involved may need to be informed too. Article 34 states that data subjects must be informed of a data breach if it is “likely to result in a high risk to the rights and freedoms of individuals”.

Including the caveat ‘high risk’ raises the bar for when a Controller must inform a data subject. The risk cannot be tenuous but reasonably possible or likely. A high risk would include data elements leading to financial losses, reputational harm and discrimination, identity fraud, damages to their credit score, and other problems in addition to emotional distress. A report may also need to be made if a significant number of data subjects are affected.

Some types of personal data including special category, or sensitive data, could have far-reaching effects – consider the potential impact of a data breach involving children’s data, the data of vulnerable adults, medical records, or anti-discrimination information (sexuality, religion, political views etc). It could have serious effects on their health and even personal safety.

Data breach consequences for organisations

Businesses and other organisations are also harmed by data breaches. People are less likely to trust a business that has experienced a data breach and will be unwilling to deal with that business in the future. This can result in lower share prices and a loss of sales. A data breach can be an expensive occurrence – the organisation will have extra expenses from a data breach, from compensating affected clients and investing in new security measures to legal fees and penalties. It may be possible that an organisation will need to partially or completely shut down their operations while an investigation into the data breach takes place. 

How to avoid data breaches

Organisations need to take proactive measures to prevent data breaches and reduce the impacts of a potential data breach. Here are some tips:

  • Keep updated with all data protection laws and regulations in your areas of operation to make sure you are compliant.
  • Invest in security measures like multi-factor authentication and access controls.
  • Keep all software up to date to protect against vulnerabilities.
  • Use effective and secure backup and archive mechanisms, and test the restore process regularly.
  • Train employees to recognise potential threats to data security such as phishing and social engineering.
  • Perform regular security audits to identify any potential weaknesses before they get exploited.
  • Data should not be stored for longer than is needed and pseudonymisation, anonymisation and encryption should be used so that any leaked data will not be readable
  • Perform DPIAs to assess the risks when planning new data processing activities, and take steps to reduce those risks
  • Have a plan in place for if a data breach occurs, including procedures for containment and mitigating any damage

Controllers need to have a robust framework in place for identifying and managing personal data breaches, including effective policies and guidance. If you need some advice and guidance on reducing your risk of data breaches, we are here to help – get in touch with Griffin House Consultancy here.

 

Author: Mike Martin LLM

Mike is an information governance specialist and one of the founder Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details