Menu

Filter by
content
PONT Data&Privacy

0

When does a data breach pose a high risk?

Autoriteit Persoonsgegevens February 26, 2020

Question & Answer

ANSWER

A data breach poses a high risk when it may result in physical, material or immaterial damage to the individuals involved. In these cases, you should assume that you must report the data breach to the Autoriteit Persoonsgegevens (AP) and to those affected. Unless there is an exception to the reporting requirement.

Physical damage
For example, when crucial medical data has been erased so that there is a risk that someone will (temporarily) not receive the necessary care. Or when professional confidentiality is breached.

Property damage
For example, when there is a chance that someone could place orders online at someone else's expense. Or other forms of financial loss or identity theft or fraud.

Intangible harm
Such as the potential for discrimination, reputational damage or invasion of one's privacy.

Examples high risk

A high risk exists if a data breach could lead to:

  • Discrimination: for example, in a data breach involving data about race, religion or sexual orientation.

  • Identity theft or fraud: for example, in a data breach involving complete passport copies. Or the BSN combined with other personal data.

  • Financial losses: for example, in the case of a data breach involving credit card information that risks allowing someone to place orders online at someone else's expense.

  • Reputational damage: for example, in a data breach involving data on problematic debt, addiction or performance at work.

  • Breach of professional secrecy: for example, in the case of a data breach involving medical data.

A high risk also exists when the data breach could lead to:

  • the unauthorized undoing of pseudonymized personal data.

  • a significant economic or social disadvantage.

  • A situation where the individuals concerned cannot exercise their rights and freedoms. Or cannot exercise control over their personal data.

Other examples of high-risk data breaches:

  • Data breach involving special personal data

  • Data breach involving criminal personal data

  • Data breach involving information on personal aspects, intended for profiling or use. In particular, profiling based on information about job performance, economic situation, health, personal preferences or interests, reliability, behavior and location.

  • Data breach involving personal data of vulnerable groups. Such as the disabled, people who are ill, children and the elderly.

  • Data breach involving a large amount of personal data and affecting a very large group of people.