DATA PROTECTION - 09.03.2021

Unnecessary data breach reports

Around a third of the data breach self-reports submitted to the Information Commissioner’s Office (ICO) are unnecessary. So when should you self-report?

Enforcing authority. The Information Commissioner’s Office (ICO) is responsible for enforcing data protection legislation, including the UK General Data Protection Regulation(GDPR) . This legislation requires data controllers to self-report data breaches in certain circumstances. However, the ICO has revealed that nearly a third of the self-reports it’s received since the GDPR’s inception are actually unnecessary, e.g. because they don’t meet the minimum threshold.

Legal requirement. So, when is a business under a legal duty to self-report a data breach to the ICO? This only needs to occur where a data breach is likely to pose a risk of harm to the data subjects who are involved; if there’s no risk of harm to data subjects, then no data breach self-report is required. A data breach can include the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, any personal data.

Defining harm. Rather unhelpfully, the GDPR doesn’t define the meaning of “harm” but it may include any type of physical, psychological, emotional, financial or reputational damage. This is a matter for the business involved in the data breach to decide and, when doing so, the situation must be viewed from the data subject’s perspective.

Tip. You can determine whether a data breach self-report is necessary by following the ICO’s free online self-assessment tool (see The next step ). It takes approximately five minutes to complete. If it concludes that no data breach self-report is necessary, keep a copy of the result for your records. Where a risk of harm is likely the ICO must be notified within 72 hours of you becoming aware of the data breach.

For further information on the ICO’s data breach self-assessment tool, visit https://www.tips-and-advice.co.uk , Download Zone, year 22, issue 11.

A data breach self-report is only necessary when there’s a likely risk of harm to the data subjects involved. The ICO’s online self-assessment tool will help you determine whether such a self-report is necessary.

© Indicator - FL Memo Ltd

Tel.: (01233) 653500 • Fax: (01233) 647100

subscriptions@indicator-flm.co.ukwww.indicator-flm.co.uk

Calgarth House, 39-41 Bank Street, Ashford, Kent TN23 1DQ

VAT GB 726 598 394 • Registered in England • Company Registration No. 3599719