Its almost becoming every day practice that we read in the newspapers about personal data of employees, students, patients etc. literally lying on the street. Sometimes an USB stick was lost, a smartphone got stolen or files are put out as waste paper.
A data leak exists when personal data is held by third parties who should not have access to that data. The risk of data leaks is increasing, since our personal data is stored in so many different databases.
A data leak can cause adverse effects on the privacy of the person concerned because the leaked data can be misused. Identity fraud is one example of misuse, but also undesired profiling or the infringement of anonymity is a possibility.
Due to a number of incidents in which large amounts of personal data was exposed, the need for better protection and security of data arose. The result (in the Netherlands) is the introduction of a (Dutch) law, which includes an obligation for responsible parties to report data leaks caused by a security error.
This security error can consist of a technical or organizational failure like poor password management, the loss of an USB stick, an email to a wrong sender or deliberately human acting such as hacking.
According to the Dutch legislator, the notification obligation should result in more awareness, in order to achieve better preserving (and thus restoring the confidence in handling personal data).
With the introduction of a notification obligation the party responsible is obligated to report the data leak. This will force educational and research institutions that process personal data to report certain security breaches that result in theft, loss or misuse of personal data to (both) the Dutch Data Protection Authority and/or the person concerned. In this way data leaks will be prevented that have an unnecessarily large impact on the privacy of the affected individuals.
So how does a company know when to report a data leak? Essentially, the following three questions need to be answered affirmative:
- Is there a breach of security (a data leak)?
- Is the processed data lost or exposed to unlawful processing as a result of this breach?
- Has this exposure resulted in serious or likely adverse effects on the protection of the processed personal data or privacy of those involved?
If an institution does not meet with the requirement of notification a large fine is risked of up to 810,000 euros, or 10% of the yearly revenue. In practice, a lot of companies are not (sufficiently) aware of their obligations under privacy laws and this might not be different for the obligation to report data leaks. Hopefully this fine will ensure institutions to find their way to the guidelines regarding data breaches.
How can companies and institutions prepare for this law prescribing the notification obligation? A few guidelines:
- Chart the data streams of the organization;
- Check the current security measures. Assess the potential risks of data loss and adjust the security policy where necessary;
- Create a clear internal procedure (action plan);
- Maintain a strict policy with regard to the processing of personal data;
- Make an inventory of the contracts with the processors and adapt where necessary;
- Consider encryption so that notification can be omitted.
Will this lead to a safer data world? We do hope so, but it remains to be seen. We will certainly keep you posted.
This post was co-written by Nina Lodder. Nina is finishing her masters degree in Private Law at the VU Amsterdam and is currently doing an internship at SOLV advocaten / a law firm which specializes in Technology, Media and Communication.