What is a Breach for GDPR

Поділитися
Вставка
  • Опубліковано 13 чер 2024
  • Looking to achieve GDPR compliance within your organisation? Arrange a demo and free 14-day trial of Keepabl's award-winning Privacy Management SaaS: bit.ly/3iUcHLq
    Can you recognise a personal data breach? You need to, because GDPR introduced obligations on every business, as controllers, to record all personal data breaches and to notify certain ones to the regulators and others to the affected individuals.
    In the time it takes to have a coffee, we’ll look at what exactly IS a personal data breach, identify the 3 types of breach, learn the 4 Key Facts and look at 20 examples from regulators!
    Want more top tips on how to operationalise Privacy at your organisation? Sign up to the Keepabl monthly newsletter: privacykitchen.tv/newsletter
    Links
    GDPR
    eur-lex.europa.eu/legal-conte...
    UK ICO on Breaches
    ico.org.uk/for-organisations/...
    The EDPB-endorsed Article 29 Working Party 2018 Guidelines on Personal Data Breach Notification under GDPR, WP250rev.01
    ec.europa.eu/newsroom/article...
    Article 29 2014 Working Party Opinion 03/2014 on Personal Data Breach Notification under the e-Privacy Directive
    ec.europa.eu/justice/article-...

КОМЕНТАРІ • 24

  • @ppa5164
    @ppa5164 6 місяців тому

    Very simple, easy to understand and concise video, super helpful!

  • @anggelngilah173
    @anggelngilah173 Місяць тому

    I learn about risikan

  • @taffmister
    @taffmister 2 місяці тому

    Hello. Where do I stand with a ex employee. I left the fire service due to false allegations, I then joined the police. Once in the police they asked for a reference from the fire service. They replied back the don’t give a detailed reference. 3 months late messaged back stating my investigation. No one asked or gave permission for this. Where do I stand????

  • @PrivacyKitchen
    @PrivacyKitchen  2 роки тому

    ​Looking to achieve GDPR compliance within your organisation? Arrange a demo and free 14-day trial of Keepabl's award-winning Privacy Management SaaS: bit.ly/3xawICg

  • @happydays9613
    @happydays9613 Рік тому +2

    What if the breach was a deliberate, search of personal details which was unauthorised use for personal advantage or gain, resulting in catastrophically effecting another persons well-being.
    What then?

    • @PrivacyKitchen
      @PrivacyKitchen  Рік тому +1

      There are cases on this including a recent one in Spain. National laws can set out criminal offences for data protection breaches and misuse of computer systems including unauthorised access.

  • @Ali54314
    @Ali54314 Рік тому +1

    This video is very good and helpful thank you so much for this.
    I would like to share my incident and if you could provide your view it will be great of you.
    I requested for CCTV footage under sujbect access request with Apple regarding an incident in store. They have deleted the footage and apologied saying we failed. ICO has told me they will ask them to improve future incident better.
    I am at loss on everything, esp with the racist incident in store.. what can I do?

  • @marcusyoung3485
    @marcusyoung3485 11 місяців тому

    If u was to use a company laptop in a cafe and ask the person during a call if this is stil there email and address but none else in the cafe is this a breach ?

  • @cpuuk
    @cpuuk Рік тому

    Do you need to have a registered DPO in order to notify ICO of a personal data breach?

    • @PrivacyKitchen
      @PrivacyKitchen  Рік тому

      Hi, no, not at all. Most private entities don't need a DPO for example and they can still report (notify) breaches.

  • @UKSkateboarding
    @UKSkateboarding Рік тому +1

    Is it a breach if my childrens school has shared information ie personal information with 3rd party companies without getting my permission to do so?

    • @PrivacyKitchen
      @PrivacyKitchen  Рік тому

      You'll appreciate we can't give specific advice. Best to contact the school and ask them about this. It's not necessarily a breach but everything is fact-specific.

  • @acousticleo4354
    @acousticleo4354 Рік тому

    I have a question. In UK, I bought an electronic device, the Application necesary to set up and run this electronic device wasn't available in Google Play store. So I called support centre and they emailed me a link to a Web page to download the phone application. I was anxious to open my new gadget and this webpage contained virus/malware my personal mail( containing all type of sensitive data)was open. After some time I notice the phone working really bad and reset it afraid of Virus. Is this a data breach? Many thanks! #PrivacyKitchen

  • @scottelev896
    @scottelev896 Рік тому

    Hi
    I had an occupational health report left out in a communal area where I work. The person who left it out investigated it themselves and decided no data was breached. Two months later they reported it to the organisation.
    Any ideas?

    • @rossblack9559
      @rossblack9559 7 місяців тому

      You would have to prove it got into someone else's hand.

  • @mumblic
    @mumblic 2 роки тому

    What if the breach is the fault of the user. For example people still use the same password for different services/websites.
    What if a hacker (or better a 3th person) logs in with the credentials, copy the data, (and then delete everything.)
    If the user complains later, does this need to be reported. This would mean you have daily breaches, if you have a large number of accounts on your website.
    The credential breach was caused by other person

    • @PrivacyKitchen
      @PrivacyKitchen  2 роки тому

      Hi there, sorry for the late reply. A breach is a breach no matter how it was caused, accidental, deliberate, insider, outsider.

  • @davestechandtrek
    @davestechandtrek 2 роки тому +1

    What about if a mobile phone is handed into a mobile phone repair shop and the owner uses that phone and leaves himself a google review using that person phone and google account?

    • @PrivacyKitchen
      @PrivacyKitchen  2 роки тому +2

      Hi there. We do provide a full range of services (our Keepabl SaaS platform, Privacy Policy Pack and Privacy Kitchen training), however we don't provide advisory services. We'd be delighted to recommend consultants and lawyers to you that we work with if you'd like to email us at hello@keepabl.com? In terms of your comment, what we can say as a general comment not specific to your situation (and this obviously isn't legal advice) is that someone using the phone of another person without authorisation is wrong on a number of levels!

  • @abhinavsharma9739
    @abhinavsharma9739 3 роки тому

    NIIT

  • @DrunkRubberDuck
    @DrunkRubberDuck Рік тому

    This is pretty pointless, when you know that absolutely nothing changed in MS Windows user agreements - as it is stated in their compliance agreement, IF you choose to use Windows 10 or 11 you are giving MS right to access your photos, email contents etc. whenever and if MS wants it, so no - GDPR is a lot of smoke and mirrors!

  • @potatius6421
    @potatius6421 Рік тому

    as to the first thing you cited: don't wear a suit made from plastic and doesn't fit you...wink wink