Sign Up

What is 8 + 4?

Have an account? Sign In Now

Sign In

What is 8 + 4?

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

What is 8 + 4?

Have an account? Sign In Now

Please type your username.

Please type your E-Mail.

Please choose an appropriate title for the question so it can be answered easily.
Please choose the appropriate section so the question can be searched easily.

Type the description thoroughly and in details.

What is 8 + 4?

Sign InSign Up

Watercooler by DPOrganizer

Watercooler by DPOrganizer Logo Watercooler by DPOrganizer Logo

Watercooler by DPOrganizer Navigation

Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Categories
    • GDPR
    • Privacy Management
    • Professional Development
    • Software tips and tricks
    • Polls
  • Help
  • About Watercooler
Home/ Questions/Q 2905
Next
In Process
Anonymous
  • 0
Asked: February 10, 20212021-02-10T20:54:52+01:00 2021-02-10T20:54:52+01:00In: GDPR, Privacy Management

What is a low level of risk for data breach reporting

  • 0

I am working with my team in Ireland on a misdirected mail issue. The mail contained name (incorrect) address and account number only. Root cause human error in adding his account details.
The DPA in Ireland lists 4 levels of risk associate with a breach Low, Medium, High &Severe. It states ‘notification of any personal data breach to the DPC, unless they can demonstrate it is unlikely to result in a risk to data subjects’.
Do we need to notify the regulator of this breach,even if its low risk

  • 2 2 Answers
  • 0 Followers
  • 0
Answer
Share
  • Facebook

    2 Answers

    • Voted
    • Oldest
    • Recent
    1. AudreyB

      AudreyB

      • 0 Questions
      • 1 Answer
      • 0 Best Answers
      • 1 Point
      View Profile
      AudreyB
      2021-02-15T12:49:20+01:00Added an answer on February 15, 2021 at 12:49 pm

      I recently used the assessment tool from https://www.mikemuha.com/

      The DPC questioned how I had determined the category of risk and accepted this tool as my methodology.

      • 1
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn
    2. rich

      rich

      • 1 Question
      • 6 Answers
      • 0 Best Answers
      • 6 Points
      View Profile
      rich Rising star contributor
      2021-02-11T00:24:52+01:00Added an answer on February 11, 2021 at 12:24 am

      I suggest you review the following document – https://www.dataprotection.ie/sites/default/files/uploads/2019-10/Data%20Breach%20Notification_Practical%20Guidance_Oct19.pdf

      The business needs to do a risk assessment (Pages 7-10, and 17) to understand the potential impacts to the rights and freedoms of the impacted data subjects (and also taking into consideration the number of data subjects impacted). If the account number, name and address and in context of other freely available public information could pose a level of risk to the individuals then, even if low, the guidance from the DPC is to report. It appears that this determination has happened and even though low it meets the bar according to the DPC practises.

      • 0
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn

    Leave an answer
    Cancel reply

    You must login to add an answer.

    What is 8 + 4?

    Forgot Password?

    Sidebar

    Ask A Question

    Trending contributors

    Smurf333

    Smurf333

    • 11 Answers
    Bronze contributor
    Dave_Wylie

    Dave_Wylie

    • 28 Answers
    Bronze contributor
    CRodica

    CRodica

    • 6 Answers
    Rising star contributor
    Ian G

    Ian G

    • 5 Answers
    Rising star contributor
    Andrea

    Andrea

    • 15 Answers
    Bronze contributor

    Recent questions

    • Ian G

      Revoke.com - new third party portal for customer right requests

      • 0 Answers
    • Anonymous

      Instagram!!

      • 0 Answers
    • Olga

      DPO in EU and UK

      • 1 Answer
    • Smurf333

      DBS scenario with HR retaining excessive information for longer than ...

      • 0 Answers
    • CRodica

      Parties role towards employees data for administrative purposes

      • 0 Answers

    Explore

    • Home
    • Categories
      • GDPR
      • Privacy Management
      • Professional Development
      • Software tips and tricks
      • Polls
    • Help
    • About Watercooler

    Footer

    Your privacy

    • Cookie notice
    • Privacy notice

    Terms and policy

    • Acceptable Use Policy
    • Terms of Use

    © 2021 DPOrganizer. All Rights Reserved. With Love by DPOrganizer.