Channel Eye
Channel Eye subscribe
  • Home
  • Business
    • Appointments
    • Data Protection
    • Digital & Technology
    • Environment
    • Features
    • Finance
    • Interviews & Profiles
    • Leadership
    • Legal & Professional Services
    • People
    • Property
    • Retail & Hospitality
    • Transport
    • Wellbeing
  • Lifestyle
    • Arts & Culture
    • Charity & Community
    • Food & Drink
    • Health
    • Home
    • Music
    • Leisure
    • Travel
  • Events
    • Events in Jersey
    • Events in Guernsey
    • Events in Alderney
    • Events in Isle of Man
    • Virtual events
    • All events
    • Past Events
  • Directory
  • Location
    • Jersey
    • Guernsey
    • Alderney
    • Isle of Man
  • Advertise
  • Subscribe
No Result
View All Result
Channel Eye
No Result
View All Result
Channel Eye subscribe
Home Business Data Protection

Data protection: How to report a breach

April 20, 2021
in Business, Data Protection, Jersey
Disk drive JOIC
Share on LinkedInTwitterFacebookEmail

Do you know how to report a data breach? The law makes it clear that you must do so within 72 hours of becoming aware of the breach, where feasible.

The Data Protection (Jersey) Law 2018 (DPJL) includes a duty on all organisations to report certain types of personal data breach to the Jersey Office of the Information Commissioner (JOIC).

A breach is more than just losing personal data

A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.  This includes breaches that are the result of both accidental and deliberate causes.  It also means that a breach is more than just about losing personal data.

A personal data breach can be broadly defined as a security incident that has affected the confidentiality, integrity or availability of personal data.  In short, there will be a personal data breach whenever any personal data is lost, destroyed, corrupted or disclosed; if someone accesses the data or passes it on without proper authorisation; or if the data is made unavailable, for example, when it has been encrypted by ransomware, or accidentally lost or destroyed.

In short, there will be a breach whenever any personal data (including any special category data) is accidentally lost, corrupted or disclosed, or if someone accesses it or passes it on without proper authorisation to do so.

JOIC logoThis means that a breach can have a range of adverse effects on individuals, which include emotional distress, and physical and material damage. Some personal data breaches will not lead to risks beyond possible inconvenience to those who need the data to do their job.  Other breaches can significantly affect individuals whose personal data has been compromised.  You need to assess this case by case, looking at all relevant factors.

  • If the breach is likely to result in a high risk of adversely affecting individuals’ rights and freedoms, you must also inform those individuals without undue delay.
  • You should ensure you have robust breach detection, investigation and internal reporting procedures in place. This will facilitate decision-making about whether or not you need to notify the relevant supervisory authority and the affected individuals.
  • You must also keep a record of any personal data breaches, regardless of whether you are required to notify.
  • If your organisation uses a data processor and this processor suffers a breach, then they must inform you without undue delay as soon as it becomes aware.  This requirement allows you to take steps to address the breach and meet your breach-reporting obligations under the DPJL.
  • If you use a processor, the requirements on breach reporting should be detailed in the contract between you and your processor.

The Breach reporting guide from the JOIC (available here) explains the following;

  • Relevant breaches
    • What is a personal data breach?
    • Breach of encrypted information
  • Notifying the JOIC
    • Within 72 hours of becoming aware
    • What information to include
    • What happens next
  • Notifying data subjects
    • If a breach is likely to represent a high risk to their fundamental rights and freedoms
    • What to tell them
    • When and how to tell them
  • Keeping a log of personal data breaches

Useful links:

  • Online JOIC breach reporting form
  • More information about breach reporting

This content is provided by the Jersey Office of the Information Commissioner.


Contacting the Jersey Office of the Information Commissioner (JOIC)

Who are the JOIC? The Jersey Office of the Information Commissioner (JOIC) is the independent regulator who ensures that all personal information used in the course of commercial, charitable or club activities is done so fairly. This applies to paper and digital records containing personal information such as names, addresses, phone numbers, email addresses, payment details etc.

Explore the resources and guidance available on the JOIC’s website, or call the office on 01534 716530 to speak to a member of the team.

Do you have a question about Data Protection that you would like answered?  Drop us an email to Newsroom@ChannelEye.Media

Tags: Data protectionJOIC
ShareTweetShareSend
Tim Bullock

Tim Bullock

Related Posts

Jersey Office of the Information Commissioner strengthens team with senior appointments
Appointments

Jersey Office of the Information Commissioner strengthens team with senior appointments

February 28, 2023
Data Protection
Data Protection

Lessons to be learnt from data protection issues at Guernsey’s Health and Social Care

February 24, 2023
Digital Jersey launches a world first data trust
Digital & Technology

Digital Jersey launches a world first data trust

February 20, 2023
Next Post
See Forward compass

Jersey entrepreneur launches workplace wellbeing app

Channel Eye Sales
Caring Cooks
Channel Eye subscribe

Subscribe to our newsletter

Get the latest, no-nonsense, essential news and information direct to your inbox.
  • Home
  • Business
  • Lifestyle
  • Events
  • Directory
  • Privacy Policy
  • Contact
  • Advertise
  • Subscribe

© 2023 Channel Eye Limited

No Result
View All Result
  • Home
  • Business
    • Appointments
    • Data Protection
    • Digital & Technology
    • Environment
    • Features
    • Finance
    • Interviews & Profiles
    • Leadership
    • Legal & Professional Services
    • People
    • Property
    • Retail & Hospitality
    • Transport
    • Wellbeing
  • Lifestyle
    • Arts & Culture
    • Charity & Community
      • Macmillan
    • Food & Drink
    • Health
    • Home
    • Music
    • Leisure
    • Travel
  • Events
    • Events in Jersey
    • Events in Guernsey
    • Events in Alderney
    • Events in Isle of Man
    • Virtual events
    • All Events
    • Past Events
  • Directory
  • Location
    • Jersey
    • Guernsey
    • Alderney
    • Isle of Man
  • Advertise
  • Subscribe
  • Contact

© 2023 Channel Eye Limited

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.