Introduction
On this page, you can read more about how to proceed if there is a data breach. If you have any questions about this, please contact info@neptunesbarista.com.
No rights can be derived from the information on this page.
Considerations
- Harm Jagerman is the owner of Neptune’s Barista, as you can see on this page.
- The owner is also referred to as the administrator.
- The owner emphasises the importance of proper security of (electronic) systems in which (personal) data is stored.
- Data breaches can always occur, no matter how well security is set up.
- The owner is obliged under the General Data Protection Regulation (AVG) to report (serious) data breaches to the Personal Data Authority and data subjects.
- The owner wishes to comply with legal obligations.
For these reasons, a protocol has been drawn up that forms the basis for acting after a data breach. This protocol is the same as available from Harm Jagerman’s website.
Definition of data breach
A data breach occurs when a security breach occurs that accidentally or unlawfully results in the destruction, loss, alteration or unauthorised disclosure of, or unauthorised access to, data transmitted, stored or otherwise processed.
Internal responsible data breach notification
Internal notification upon discovery of a data breach
There is no separate policy for internal reporting of a discovery of a data breach, because it is a company for which only one person works.
If possible, remote erasure and/or inaccessibility of the leaked data will be ensured.
Research
The investigation after discovering a data breach includes:
- Checking whether personal data has been lost.
- Checking whether personal data may be used unlawfully.
- Which systems are involved in this data breach?
- Whether a processor is involved in this incident.
Fight
Immediately after identifying the data breach, the investigation began. Countermeasures have also started. Adequate measures are taken to combat this data breach.
Determination of the consequences of a data breach
The investigation will have to lead to the possible consequences of the data breach based on the nature and extent of the data that has been leaked, and thus determine what the adverse effects on the data subjects may be.
Cooperation in providing data breach information
The discoverer/notifier of the data breach offers all cooperation to the administrator by providing answers (in writing) to the following questions as soon as possible:
- What happened?
A description of the incident - Did this incident occur accidentally, or was it deliberate?
Perhaps there was a hack, or it was a matter of “trying something out. - When was this discovered?
Date and time are necessary here. - What kind of data (registers) were leaked?
- Could the data be remotely erased or made inaccessible, and if so, was this done?
- What are the potential adverse effects on those affected?
- Which group(s) of people are affected?
- How many people were (approximately) affected by this?
- Is the data of individuals in other EU countries also affected by this data breach?
- Were technical and/or organisational measures already in place as a result of this incident?
Availability
It is possible that due to this data breach, the availability of the administrator will be reduced as the data breach will be given increased priority.
Decision in case of data breach
Within sixty (60) hours of identifying a data breach, a decision on further steps to be taken will follow. It then becomes clear whether a report should be made to the Personal Data Authority or data subjects.
In principle, a data leak is always reported to the Personal Data Authority, unless the data leak is unlikely to pose a risk to the rights and freedoms of data subjects.
Reporting the data breach is accompanied by answering questions as described in the section Cooperation in Providing Data Breach Information.
If a notification has been made to the Personal Data Authority, this will be reported to the data subjects if it poses a high risk to the rights and freedoms of natural persons, unless appropriate measures have since been taken that have averted the high risk.
Data breach notification
The administrator will make a notification to the Personal Data Authority/affected parties if necessary. This notification will be made within 72 hours of a data breach taking place.
Consequences of data breach notification
If the data breach has adverse consequences for data subjects, the administrator will make every effort to minimise these consequences. Depending on the nature and extent of the data breach for the data subjects will be determined:
- In what way data subjects will be informed (including, in any case, announcements on what types of personal data are affected, what the possible consequences are, what measures are being or have been taken and what data subjects themselves can do to prevent or limit damage).
- What aftercare do those involved receive?
- Which actions are necessary in the best interests of the organisation?
If the data breach has occurred – whether reported or not – adequate technical and/or organisational measures will be taken as soon as possible to prevent such data breaches in the future.
Maintain a data breach register.
The internal manager keeps a register of all data breaches, recording all details surrounding the data breach, such as:
- A description of the incident.
- Date and time of the data breach.
- Date and time of discovery of the data breach.
- Description of the type of personal data leaked.
- Description of the category or categories of data subjects affected.
- Description: number of people involved (approximate).
- Whether the data of individuals in other EU countries was also leaked.
- Whether the incident was reported to the Personal Data Authority and, if so, the date and time of reporting.
- Whether the incident was reported to those involved and, if so, the date and time of reporting.
- In what way were stakeholders informed?
- The consequences of the data breach, including, if possible, the date and time.
- What technical and/or organisational measures were taken following the data breach, including date and time?
Update
The data breach notification protocol was created on 11-04-2021 for the website of Harm Jagerman and amended in content for this website (neptunesbarista.com) on 03-12-2024.