A lost laptop, an email sent to the wrong person or a ransomware attack are all personal data breaches. What you do in the first hours decides how large the damage will be, for people and for the organization.
First steps
- Stop the leak: isolate the system, change passwords, recall the email if you can.
- Delete nothing. You need the logs and evidence to understand what happened.
- Immediately inform the person responsible for incidents and the DPO.
Assess what happened
- What data is affected and how sensitive is it?
- How many people are affected?
- Is the data encrypted or unreadable to anyone else?
- What could the consequences be for people: fraud, discrimination, financial loss?
Notifications
Under the GDPR, with which Law 124/2024 is aligned, a breach is notified to the supervisory authority within 72 hours of the organization becoming aware of it, unless it is unlikely to result in a risk to people. When the risk is high, the affected people are also told, in plain language and with advice on how to protect themselves.
72 hours pass quickly, especially over a weekend. Decide in advance who makes the notification decision and who prepares it.
Document everything
Record what happened, what the effects were and what measures you took, even when you decide not to notify. After the incident, review what allowed it to happen and update your response plan.
