How to Prevent a Data Breach

Learning how to prevent a data breach is a key part of GDPR compliance. In an era defined by the exchange of information, personal data is an invaluable currency. However, with great data comes great responsibility. Data breaches have become increasingly common, leaving individuals and organisations vulnerable to the legal and operational consequences. This article explores personal data breaches, offering a comprehensive guide on how to prevent them.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

Contents

What is Personal Data?

Personal data is defined as:

anything that by itself or in combination with other data could lead to someone being identified”

That is a very broad definition and as such virtually anything could be personal data. Examples of personal data include:

  • name

  • date of birth

  • address

  • telephone numbers

  • personal preferences

  • health data

  • financial information

When processing personal data care must be taken to ensure that it is kept safe and secure. The level of security needed to prevent a data breach depends on the volume and sensitivity of the data held.

What is a Data Breach?

A data breach is defined as “the accidental or deliberate and inappropriate access to, alteration of, or deletion of personal data”.

Again, this is very broad. Note that a data breach includes the accidental inappropriate access to records. It is easy for a data breach to happen without external or malicious action. Examples of a data breach include:

  • a member of staff accessing the customer records of friends or family for non-work related reasons

  • an email containing personal data being sent to the wrong recipient

  • paper records being accidentally left in a public place

  • electronic records being available online because of inadequate security

  • the loss of personal data due to hacking

The Consequences of a Data Breach

Data breaches can lead to a multitude of consequences, ranging from financial losses to reputational damage. Understanding the potential fallout is essential in motivating proactive data protection.

There are some specific legal offences relating to data breaches set out in the Data Protection Act 2018 (DPA). There are also potential civil consequences, regulatory action from the Information Commissioner, and severe reputational risks from a data breach.

Apart from administrative fines, the DPA 2018 also outlines several criminal offences related to data protection. These offences can result in criminal prosecution, leading to more severe penalties, including imprisonment and unlimited fines. Prosecution can happen to a company and an individual. The criminal offences under the DPA 2018 include:

Unlawful Obtaining, Disclosure, or Procurement of Personal Data

This offence involves intentionally obtaining, disclosing, or procuring personal data without the data controller’s consent. It also covers the sale, offering, or possession of unlawfully obtained personal data. Convictions for this offence can result in imprisonment for up to two years or an unlimited fine.

Re-Identification of De-Identified Personal Data

The Act prohibits intentionally re-identifying de-identified personal data without the data controller’s consent. Re-identification involves linking anonymised or pseudonymised data with additional information to identify individuals. Convictions under this offence carry the penalty of imprisonment for up to two years or an unlimited fine.

Alteration of Personal Data to Prevent Disclosure

This offence pertains to intentionally altering personal data with the aim of preventing its disclosure. It is primarily aimed at preventing individuals from accessing their personal information. The penalty for this offence includes imprisonment for up to two years or an unlimited fine.

Failure to Comply with an Enforcement Notice

A failure to comply with an enforcement notice issued by the ICO is a criminal offence. Organisations or individuals who fail to comply may face criminal prosecution. If convicted, the penalty can include an unlimited fine imposed by the court.

Offences by Directors, Managers, or Officers of Corporate Bodies

Section 194 of the DPA holds directors, managers, or officers of corporate bodies personally liable for offences committed by their organisations if the offence was committed with their consent, connivance, or neglect. Convictions under this section can lead to a prison terms of up to two years or an unlimited fine.

It’s important to note that criminal offences under the DPA 2018 require proof of intent or recklessness. Mere negligence or accidental breaches typically fall under the scope of administrative fines rather than criminal prosecution.

Civil and Regulatory Action

If someone has suffered a personal data breach they can bring a claim for compensation through the civil courts. Such claims could lead to awards for damages, and of course legal costs for both sides. The Information Commissioner cannot consider a claim for compensation.

Regulatory Fines

The Information Commissioner can levy fines for breaching GDPR. These fines are classified into two tiers, depending on the severity of the violation:

Tier 1: Up to £8.7 million or 2% of annual global turnover (whichever is higher).

Tier 1 fines are typically applied for less severe infringements, such as not conducting data protection impact assessments, failing to maintain records of data processing activities, or inadequate data security measures. For example, a failure to report a data breach cold result in a Tier 1 fine.

Tier 2: Up to £17.5 million or 4% of annual global turnover (whichever is higher).

Tier 2 fines are reserved for more serious breaches, including significant violations of individuals’ rights, failure to obtain proper consent, or insufficient security measures leading to a data breach.

The specific amount of the fine within the given range depends on various factors, including the nature, gravity, and duration of the infringement, the organisation’s level of cooperation with the ICO, and the extent of the damage caused to individuals. Therefore the exact penalty will be decided on a case by case basis.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

How to Prevent a Data Breach

There are a number of important actions organisations can take to reduce the risk of a data breach. These actions include:

Understanding the Regulatory Landscape

Various data protection regulations, including the General Data Protection Regulation (GDPR), have stringent requirements for safeguarding personal data. Understanding these regulations is a critical step in avoiding data breaches.

Data Classification

Not all data holds the same value or risk. Classifying data based on sensitivity can help prioritise security measures.

Types of data that may require special handling include:

  • data about children

  • information relating to physical, mental or sexual health

  • information about ethnicity, gender, religious beliefs and other protected characteristics

Access Control

Given the definition of a data breach above it is important that people are only able to access the data that they need. For example, HR colleagues may need to access staff data, but other people usually won’t. IT staff can have wide ranging access to data, so their employment contracts will need clauses explaining their duties to access data appropriately.

Encryption and Pseudonymisation

Data encryption is an effective safeguard against breaches. Understanding the different encryption methods and when to use them is important. There are two key elements to encryption:

  • encryption in transit, when data are encrypted when travelling from one place to another

  • encryption at rest, when data are encrypted while stored on a server or personal devices

Pseudonymisation is when data is anonymised before it is shared, but a pseudonym is added to allow reidentification where necessary. This is a useful technique in fields such as medical research or auditing customer service records.

Network Security

Network security is a critical component of data protection. By implementing robust network security measures, organisations can help to protect their data from a data breacg

Network security encompasses a wide range of technologies and practices, including:

  • Firewalls: Firewalls monitor and control incoming and outgoing network traffic, blocking unauthorised access to resources.

  • Intrusion detection and prevention systems (IDS/IPS): IDS/IPS systems monitor network traffic for suspicious activity and can block or alert on malicious traffic.

  • Antivirus and antimalware software: Antivirus and antimalware software protects devices from malware infections.

In addition to these technologies, organisations should also implement strong network security policies and procedures. These policies and procedures should cover a wide range of topics, including:

  • Password management: Password management policies should require users to create and use strong passwords and to change them regularly.

  • Acceptable use: Acceptable use policies should define the acceptable use of network resources and prohibit activities that could put the network at risk.

  • Incident response: Incident response plans should outline the steps that should be taken in the event of a network security incident.

By implementing robust network security measures and policies, organisations can help to protect their data from a wide range of threats.

Network Security Examples

Here are some specific examples of how network security can help to protect data:

  • A firewall can prevent an unauthorised user from accessing a company’s internal network and stealing sensitive data.

  • An IDS/IPS system can detect and block malicious traffic before it reaches a company’s network, preventing malware infections and data breaches.

  • Antivirus and antimalware software can protect company devices from malware infections, which can lead to data loss or theft.

  • Data encryption can protect data from unauthorised access, even if it is stolen or compromised.

  • Access control can restrict access to sensitive data to authorised users, reducing the risk of data breaches.

Overall, network security is an essential part of any data protection strategy. By implementing robust network security measures, organisations can help to keep their data safe and secure.

Data Protection Training

A well-informed team is the first line of defense against data breaches. When people understand their duties they will know how to prevent a data breach, and can spot things going wrong before they become a crisis.

It is important that people have role specific training rather than there being a one-size-fits-all approach. As noted above different people with different roles need different training to help them get data protection right.

Data Deletion

Data protection doesn’t end when it’s no longer needed. Proper data disposal is often an overlooked aspect of data protection.

It is important to be clear about how long personal data will be retained by having a clear retention schedule, and take steps to destroy personal data that has reached the end of its retention period.

What the retention period may be will be up to you but you do need to ensure you do not keep personal information for longer than is necessary.

Third-Party Risks

Many data breaches are caused by third parties. If you are a data controller you will have responsibility for ensuring anyone who processes data on your behalf.

To mitigate the risk of a data breach there must be a clear contract, or data sharing agreement that sets out:

  • who is the data controller and who is the data processor

  • the data to be processed

  • the purpose of the processing

  • security arrangements to be maintained

  • oversight and auditing arrangements for the purposes of data security

Continuous Monitoring

Data protection isn’t a one-time effort. Regular monitoring and evaluation are crucial for ongoing security. There should be annual audits of data protection compliance, including data security.

In addition regular reports on data security, and any data breaches, should be made to the organisation’s board or management committee. In addition a data security related risk should be included on the corporate risk register to allow for scrutiny of efforts to prevent a data breach.

Learn More About GDPR

Gain the skills and confidence you need to develop and deploy effective GDPR systems. These five star rated, expert led courses are available online, in person and in house offering an ideal learning opportunity to all.

testimonial

Further Reading

To go into some of the concepts introduced in this article you may wish to read these related articles (click in the title of each article to see more):

Conclusion: Key Takeaways for Avoiding Data Breaches

Personal data breaches are a significant concern in today’s interconnected world. By understanding the nature of personal data, complying with relevant regulations, and implementing robust security measures, individuals and organisations can drastically reduce the risk of data breaches. This comprehensive guide serves as a roadmap to proactive data protection, emphasising the importance of a holistic approach to safeguarding personal information.