Sign Up

What is 8 + 4?

Have an account? Sign In Now

Sign In

What is 8 + 4?

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

What is 8 + 4?

Have an account? Sign In Now

Please type your username.

Please type your E-Mail.

Please choose an appropriate title for the question so it can be answered easily.
Please choose the appropriate section so the question can be searched easily.

Type the description thoroughly and in details.

What is 8 + 4?

Sign InSign Up

Watercooler by DPOrganizer

Watercooler by DPOrganizer Logo Watercooler by DPOrganizer Logo

Watercooler by DPOrganizer Navigation

Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Categories
    • GDPR
    • Privacy Management
    • Professional Development
    • Software tips and tricks
    • Polls
  • Help
  • About Watercooler
Home/ Questions/Q 9049
Next
In Process
CRodica
CRodica

CRodica

  • 2 Questions
  • 6 Answers
  • 0 Best Answers
  • 6 Points
View Profile
  • 0
Asked: June 17, 20222022-06-17T11:39:10+01:00 2022-06-17T11:39:10+01:00In: GDPR

Distribution list data breach

  • 0

How would you tackle an incident where data was sent to multiple unintended distribution lists externally and no response comes back to confirm that data was deleted?

Thanks

  • 2 2 Answers
  • 0 Followers
  • 0
Answer
Share
  • Facebook

    2 Answers

    • Voted
    • Oldest
    • Recent
    1. Smurf333

      Smurf333

      • 1 Question
      • 11 Answers
      • 0 Best Answers
      • 11 Points
      View Profile
      Smurf333 Bronze contributor
      2022-06-27T12:01:47+01:00Added an answer on June 27, 2022 at 12:01 pm

      Firstly, I would look at following any internal SOP you have for dealing with incidents. Secondly, you should consider assessing the incident, either using an internally agreed process, or looking at the regulator’s web site (ICO in the UK) to determine if it is reportable. If you don’t have an internal SOP, once again look at the regulator’s site for guidance and follow that. In the event that you have not received responses, a chaser would be the first option, and you should also re-assess the risk. Thereafter, if you have not done so already you need to consider the interests of the data subjects impacted by the incident and warn them of the potential impact and corrective action that you as an organisation will take and also the action they need to consider to mitigate any damages. Hope that helps.

      • 0
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn
    2. LucyR

      LucyR

      • 0 Questions
      • 1 Answer
      • 0 Best Answers
      • 1 Point
      View Profile
      LucyR
      2022-06-17T12:38:39+01:00Added an answer on June 17, 2022 at 12:38 pm

      Try again, but ultimately it’s out of your control. If you document the incident as a breach and what you have reasonably done to mitigate it, that covers the ‘accountability’ angle.

      • 0
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn

    Leave an answer
    Cancel reply

    You must login to add an answer.

    What is 8 + 4?

    Forgot Password?

    Sidebar

    Ask A Question

    Trending contributors

    Smurf333

    Smurf333

    • 11 Answers
    Bronze contributor
    Dave_Wylie

    Dave_Wylie

    • 28 Answers
    Bronze contributor
    CRodica

    CRodica

    • 6 Answers
    Rising star contributor
    Atis

    Atis

    • 4 Answers
    Ian G

    Ian G

    • 5 Answers
    Rising star contributor

    Recent questions

    • Ian G

      Revoke.com - new third party portal for customer right requests

      • 0 Answers
    • Anonymous

      Instagram!!

      • 0 Answers
    • Olga

      DPO in EU and UK

      • 1 Answer
    • Smurf333

      DBS scenario with HR retaining excessive information for longer than ...

      • 0 Answers
    • CRodica

      Parties role towards employees data for administrative purposes

      • 0 Answers

    Explore

    • Home
    • Categories
      • GDPR
      • Privacy Management
      • Professional Development
      • Software tips and tricks
      • Polls
    • Help
    • About Watercooler

    Footer

    Your privacy

    • Cookie notice
    • Privacy notice

    Terms and policy

    • Acceptable Use Policy
    • Terms of Use

    © 2021 DPOrganizer. All Rights Reserved. With Love by DPOrganizer.