How to Handle GDPR Breaches Within 72 Hours

178 views
•
May 14, 2019
by
RSAC Cybersecurity
YouTube video player
How to Handle GDPR Breaches Within 72 Hours

TL;DR

Treat any compromise involving personal data as a GDPR personal data breach, then assess whether it creates risk or high risk and is therefore reportable. Once the organization has a reasonable degree of certainty that personal data was involved, the 72-hour notification timeline begins, making consistent awareness criteria, rapid investigation, containment, and documented risk assessment essential.

Transcript

Okay, so it is my very great pleasure to introduce our next set of speakers who are going to be talking to us about breach notification and incident response under the GDPR. So they are Julia Jacobson, who is a partner in the Boston office of K&L Gates. Uh, her practice focuses on privacy, data protection and marketing, advertising and promotions, ... Read More

Key Insights

  • GDPR personal data is defined extremely broadly and may include information derived from many different sources. Organizations should initially assume that information is personal data until they can establish otherwise, because applying a narrower United States-style definition may cause relevant incidents to be overlooked.
  • A GDPR personal data breach includes accidental or unlawful destruction, loss, alteration, unauthorized disclosure, unauthorized access, or loss of availability involving personal data. The central question is not simply whether a breach occurred, but whether the resulting risk makes that breach reportable.
  • GDPR breach analysis differs from the common United States model because every incident involving personal data is treated as a breach before reportability is assessed. United States practice more commonly begins with an incident and then determines whether the event legally qualifies as a breach.
  • GDPR recognizes confidentiality, integrity, and availability breaches as distinct categories that must be considered during a multifactor risk assessment. Availability is particularly important because information can create regulatory risk when it becomes inaccessible, even if there is no demonstrated unauthorized disclosure.
  • Ransomware can create an availability breach by locking personal data. The difficult assessment is how long the information must remain unavailable before the event creates risk or high risk, since the discussion notes that GDPR guidance is less precise than some United States notification laws.
  • The 72-hour notification clock begins after the organization has a reasonable degree of certainty that an incident involved personal data. A preliminary investigation may therefore occur before the clock starts, but organizations must rapidly determine whether personal information was implicated and whether notification is required.
  • A consistent awareness standard is a defensible compliance practice when the meaning of reasonable degree of certainty remains unclear. Organizations should define the threshold in advance, apply it consistently across incidents, and avoid changing the interpretation merely to obtain a different notification outcome.
  • Risk mitigation can sometimes keep an incident below the notification threshold even after personal data has been compromised. Effective containment, established practices, and a documented assessment can reduce risk, but the organization must understand the applicable rules and demonstrate how its mitigation supports the conclusion.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What counts as a personal data breach under GDPR?

A GDPR personal data breach can involve accidental or unlawful destruction, loss, alteration, unauthorized disclosure, unauthorized access, or loss of availability affecting personal data. Because personal data is defined very broadly, organizations should not limit their analysis to identifiers associated with identity theft. Once personal data is involved, the event is treated as a breach and then assessed for reportability.

Q: When does the GDPR 72-hour notification clock begin?

The 72-hour timeline begins when the organization has a reasonable degree of certainty that an incident involved personal data. The discussion indicates that an organization may conduct a short initial investigation after first learning of a possible issue. Once personal-data involvement is established, it must assess the risk to affected people and notify within 72 hours when the applicable reporting threshold is met.

Q: What does reasonable degree of certainty mean for GDPR breach awareness?

Reasonable degree of certainty is the standard used to identify when an organization has become aware that a personal data breach occurred, but the discussion describes the phrase as loosely defined. A practical response is to select a clear organizational threshold, document it in policies, and apply it consistently. Consistency creates a more defensible position than changing the standard from one incident to another.

Q: How is GDPR breach analysis different from United States breach law?

GDPR starts from the position that a compromise involving personal data is a breach, after which the organization determines whether it is reportable based on risk. The United States model described in the discussion generally begins with an incident and then determines whether it legally becomes a breach. United States notification laws are also portrayed as more focused on identity theft or specific healthcare relationships.

Q: What are confidentiality, integrity, and availability breaches under GDPR?

A confidentiality breach concerns unauthorized access to or disclosure of personal data. An integrity breach concerns unauthorized or accidental alteration of that information. An availability breach concerns the loss, destruction, or inaccessibility of personal data. Organizations must consider all three categories in a multifactor risk assessment because each may affect whether the event presents risk or high risk to the people involved.

Q: Why can ransomware trigger GDPR breach obligations?

Ransomware may lock personal data and make it unavailable, creating an availability breach even when unauthorized disclosure has not been established. The organization must assess the duration and consequences of that unavailability and determine whether it creates risk or high risk. The discussion identifies this as a difficult area because the precise period of unavailability needed to cross a reporting threshold is unclear.

Q: How should an organization assess whether a GDPR breach is reportable?

The organization should first determine whether personal data was involved, then perform a multifactor assessment covering confidentiality, integrity, and availability. It must distinguish between the risk and high-risk thresholds referenced in the discussion and evaluate whether containment or other mitigation reduced the consequences. The conclusion should be supported by consistent criteria, documented reasoning, and an understanding of the applicable notification rules.

Q: Can containment prevent a GDPR breach from requiring notification?

Containment and other mitigation can sometimes reduce the effects of an incident enough to keep it below the notification threshold. The discussion emphasizes that even after data has escaped its expected controls, prompt action and good practices may lower the risk. An organization still needs to assess the incident, understand the regulatory criteria, and demonstrate why its mitigation supports a decision not to notify.

Summary & Key Takeaways

  • GDPR defines personal data extremely broadly, potentially covering data derived from almost any source. Unlike United States notification laws focused on identity theft or particular healthcare relationships, GDPR treats a personal-data compromise as a breach first, then requires the organization to determine through risk assessment whether that breach must be reported.

  • A GDPR breach may affect confidentiality, integrity, or availability. Availability is especially important because inaccessible data, including information locked by ransomware, may trigger assessment obligations even without conventional disclosure. Organizations must evaluate each relevant breach type and distinguish between the regulation's risk and high-risk thresholds when deciding what notification is required.

  • The 72-hour period begins when an organization has a reasonable degree of certainty that personal data was involved in an incident. Because that standard is not precisely defined in the discussion, organizations should adopt a consistent, defensible awareness threshold and support it with policies, prompt investigation, containment, mitigation, and documented decision-making.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚