Inappropriate Access is a Data Breach

People often labour under the impression that a data breach is some form of external malicious action or an IT or technical failure exposing people’s data. In fact a data breach under the GDPR is much broader than that. Article 4(12) of the GDPR defines it as:

a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;

Most people do not know how broad this is. Sending an email containing personal data to the wrong recipient is a data breach – although a relatively minor one.

Access to medical records

A much more serious one, as reported recently, is the inappropriate access of a person’s medical records.

People may think what they are doing is allowed. Perhaps because they happen to also work in the NHS, or that it is harmless. Far from it. People value their privacy and this kind of behaviour:

  • Causes real distress to the individuals affected
  • Reduces trust generally in public services and their ability to manage sensitive data

I have come across this scenario before. The financial, operational and reputational impact takes a lot of time and effort to address.

How To Prevent An Inappropriate Access Data Breach

To prevent this kind of breach occurring organisations must:

  1. Have clear policies setting out both what a data breach is
  2. Tell people who to talk to for help if they are unsure. This could be their line manager, data protection officer, Caldicott guardian etc.
  3. Tell people what to do if they think a data breach as occurred
  4. Set out the consequences for breaching the policy (I’m genuinely surprised how often organisations neglect this part)

They must also provide role specific training that sets out:

  • what a data breach is in terms that relate to what people do within an organisation e.g. accessing patient records they have no reason to
  • what the real world consequences of a data breach can be in terms of damage and distress
  • emphasising the fair and transparent part of the first data privacy principle: only do what you said you would and behave as people would expect

This is why generic one-size-fits-all mandatory training a lot of organisations go for simply doesn’t cut it.

If a data breach still occurs after this organisations must ensure they take the appropriate action, which sadly really ought to include disciplinary action of at least a written warning. That might appear harsh, but organisations react much more robustly for even the most minor financial transgressions and the same value must be put on data. Also, a failure to act robustly (or have the right training and policies in place) make it much more likely the ICO will take action against you.

Interested in GDPR Training?

Our GDPR training courses will help you and your team develop the practical applicable skills needed to ensure GDPR compliance, retain stakeholder confident and avoid data breaches.

Find out more about training here. 

 

Five star rating and testimonial