25.01.2018 Views

white_paper_on_data_protection_in_india_171127_final_v2

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

B. PERSONAL DATA BREACH NOTIFICATION<br />

The aggregati<strong>on</strong> of <strong>data</strong> <strong>in</strong> the hands of public and private entities leaves them vulnerable to<br />

<strong>data</strong> breaches. Data breaches can take many forms <strong>in</strong>clud<strong>in</strong>g; hackers ga<strong>in</strong><strong>in</strong>g access to <strong>data</strong><br />

through a malicious attack; lost, stolen, or temporary misplaced equipment; employee<br />

negligence; and policy and/or system failure. It is important to identify these threats and<br />

establish processes to deal with these breaches.<br />

2.11 Issues and Internati<strong>on</strong>al Practices<br />

(i)<br />

Def<strong>in</strong><strong>in</strong>g Data Breaches<br />

While <strong>data</strong> breaches may occur <strong>in</strong> various forms, these breaches can be classified us<strong>in</strong>g the<br />

fundamental pr<strong>in</strong>ciples of <strong>in</strong>formati<strong>on</strong> security, i.e. c<strong>on</strong>fidentially, <strong>in</strong>tegrity and availability.<br />

So, a pers<strong>on</strong>al <strong>data</strong> breach may be categorised as the follow<strong>in</strong>g:<br />

a. C<strong>on</strong>fidentiality breach: Where there is an unauthorised or accidental disclosure of, or<br />

access to, pers<strong>on</strong>al <strong>data</strong>.<br />

b. Integrity breach: Where there is an unauthorised or accidental alterati<strong>on</strong> of pers<strong>on</strong>al<br />

<strong>data</strong>.<br />

c. Availability breach: Where there is an accidental or unauthorised loss of access to, or<br />

destructi<strong>on</strong> of, pers<strong>on</strong>al <strong>data</strong>.<br />

Based <strong>on</strong> the circumstances, a breach can c<strong>on</strong>cern c<strong>on</strong>fidentiality, availability and <strong>in</strong>tegrity of<br />

pers<strong>on</strong>al <strong>data</strong> at the same time, as well as any comb<strong>in</strong>ati<strong>on</strong> of these. Whereas determ<strong>in</strong><strong>in</strong>g if<br />

there has been a breach of c<strong>on</strong>fidentiality or <strong>in</strong>tegrity is relatively clear, whether there has<br />

been an availability breach may be less obvious. Carefully def<strong>in</strong><strong>in</strong>g pers<strong>on</strong>al <strong>data</strong> breach is<br />

thus imperative.<br />

The EU GDPR def<strong>in</strong>es a ―pers<strong>on</strong>al <strong>data</strong> breach‖ as “a breach of security lead<strong>in</strong>g to the<br />

accidental or unlawful destructi<strong>on</strong>, loss, alterati<strong>on</strong>, unauthorised disclosure of, or access to,<br />

pers<strong>on</strong>al <strong>data</strong> transmitted, stored or otherwise processed”. 724 Article 29 Work<strong>in</strong>g Party<br />

guidance <strong>on</strong> pers<strong>on</strong>al <strong>data</strong> breach notificati<strong>on</strong> notes that there is a difference between a<br />

security <strong>in</strong>cident and a pers<strong>on</strong>al <strong>data</strong> breach. 725 A pers<strong>on</strong>al <strong>data</strong> breach is essentially a subset<br />

of a security <strong>in</strong>cident. All pers<strong>on</strong>al <strong>data</strong> breaches are security <strong>in</strong>cidents, not all security<br />

<strong>in</strong>cidents are necessarily pers<strong>on</strong>al <strong>data</strong> breaches. So, <strong>on</strong>ly a security <strong>in</strong>cident that hampers the<br />

security, c<strong>on</strong>fidentiality or <strong>in</strong>tegrity of pers<strong>on</strong>al <strong>data</strong> would result <strong>in</strong> a ‗pers<strong>on</strong>al <strong>data</strong> breach‘.<br />

724 Article 4(12), EU GDPR.<br />

725 Article 29 Data Protecti<strong>on</strong> Work<strong>in</strong>g Party, ‗Guidel<strong>in</strong>es <strong>on</strong> Pers<strong>on</strong>al <strong>data</strong> breach notificati<strong>on</strong> under Regulati<strong>on</strong><br />

2016/679‘, European Commissi<strong>on</strong> (3 October 2017), available at:<br />

http://ec.europa.eu/newsroom/document.cfm?doc_id=47741, (last accessed 10 November 2017).<br />

161

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!