In accordance with the announcement, we invite you to the second part of the study on the guidelines adopted by the European Data Protection Board regarding examples of reporting data breaches.

In the first part of the study, we focused on cases of breaches related to hacking attacks or human errors.
Theft, loss of devices,
or documents
A common case is the loss or theft of portable devices. In such cases, the data controller must consider the circumstances of the processing operation, such as the type of data stored on the device, as well as the measures taken prior to the breach to ensure an appropriate level of security. All these elements affect the potential consequences of the data breach. Assessing the risk can be difficult, as the device is no longer available.
Such breaches can always be considered breaches of confidentiality. However, if there is no backup for the stolen database, the type of breach may also involve a breach of availability and integrity.
Example 10
In example number 10, EROD takes us to a kindergarten from which two tablets were stolen. The tablets contained an application that included personal data of children attending the kindergarten: name and surname, date of birth, personal data regarding the children's education. Both the encrypted tablets, which were turned off at the time of the break-in, and the application were protected by a strong password. Backup data was effectively and easily accessible to the data controller. Upon discovering the break-in, the kindergarten issued a command to remotely wipe the memory of the tablets.
What should be done?
Due to the risk, it is necessary to document internally.
In this specific case, the data controller took appropriate measures to prevent a potential data breach and mitigate its effects by implementing device encryption, introducing appropriate password protection, and securing a backup of the data stored on the tablets. A remote device management system was also applied, which resulted in the deletion of the data stored there.
The data breach described above would have concerned the confidentiality, availability, and integrity of the relevant data; however, due to the appropriate actions taken by the data controller before and after the data breach, none of these occurred. As a result of the measures implemented, the confidentiality of the data remained intact. Furthermore, the backup copy ensured the continuous availability of personal data, which meant that no potential negative impact could arise.
In light of these facts, it is unlikely that the data breach described above posed a threat to the rights and freedoms of the individuals whose data is concerned, and therefore there was no need to notify the supervisory authority or the individuals whose data is concerned. However, this data breach must also be documented in accordance with Article 33(5).
Example 11
An employee's electronic notebook from a service company was stolen. The stolen notebook contained the names, surnames, addresses, and dates of birth of over 100,000 clients. Due to the unavailability of the stolen device, it was not possible to identify other categories of personal data affected by the breach. The hard drive of the notebook was not encrypted. Personal data could be recovered from daily backups.
What should be done?
Due to the risk, it is necessary to: document internally, report to the supervisory authority, and notify the individuals whose data is concerned.
EROD points out that the data controller did not take any prior security measures, which is why the personal data stored on the stolen device was easily accessible to anyone who came into possession of it.
This breach concerns the confidentiality of data stored on the stolen device. The notebook containing personal data was vulnerable to attacks in this case because it had no password protection or encryption. The lack of basic security measures increases the level of risk of harm to the individuals whose data is concerned. The large number of individuals affected by the breach increases the risk.
When assessing the risk, data controllers should consider the potential consequences and negative effects of the breach of confidentiality.
As a result of the breach, individuals whose data is concerned may fall victim to identity theft based on the data available on the stolen device, which is why the risk is considered high.
The implementation of device encryption and the use of strong password protection for the stored database could prevent a data breach that would pose a threat to the rights and freedoms of the individuals whose data is concerned. In light of these circumstances, it is necessary to notify the supervisory authority. Notifying the individuals whose data is concerned is also required.
Example 12
In the twelfth example, the EROD takes us to a rehabilitation center. The discussed facility did not have access control mechanisms in place. A paper log containing basic identity and health information of patients was stolen. The data was stored only on paper, and no backup copy was available to the doctors treating the patients. The logbook was not secured in any way.
What should be done?
Due to the risk, it is necessary to: document internally, report to the supervisory authority, and notify the individuals whose data is concerned.
This case serves as an example of a high-risk data security breach. Due to the lack of appropriate precautions, sensitive health data as defined in Article 9(1) of the GDPR was lost. This breach concerns the confidentiality, availability, and integrity of the relevant personal data.
When was the last time
you conducted a risk analysis?
The data breach described above may seriously affect the individuals whose data is concerned. Therefore, notifying the supervisory authority and informing the affected individuals is mandatory.
Preventive Measures
The EDPB in guidelines 01/2021 proposes example safeguards for devices and documents that reduce the impact of breaches of the data processed on them.
- Encrypt data stored on computers.
- Use passwords on all devices. Encrypt all mobile electronic devices in such a way that requires entering a complex password to decrypt.
- Use multi-factor authentication.
- Use MDM (Mobile Devices Management) software.
- If possible and appropriate for the specific data processing, personal data should be stored on a central server rather than on the end device.
- Device usage policies.
- Ensure access controls to premises to enable the physical security of mobile devices when left unattended.
Mailing Error
The source of risk in this case is also internal human error. The data controller cannot do much after it has occurred, which is why prevention is even more important than in other types of breaches.
Example 13
In the next example, the EDPB discusses a case involving a sales company. Due to an employee's mistake, the packages were mixed up, resulting in both products along with invoices being sent to the wrong individuals. This means that both customers received the wrong orders, including invoices containing personal data. Upon discovering the breach, the data controller canceled the orders and sent them to the correct recipients.
What should be done?
Due to the risk, it should be documented internally.
The invoices contained personal data required for successful delivery (name, address, and purchased item along with its price). It is important to identify how human error could have occurred and how it could have been prevented. In this specific case, where the risk is low, due to the absence of special categories of personal data or other data whose misuse could lead to significant negative consequences. The breach is not the result of a systemic error on the part of the data controller and concerns only two individuals. No negative impact on the individuals could be identified.
Even if the breach itself does not pose a significant risk to the rights and freedoms of the data subjects, it is often unavoidable to inform them of the breach, as their cooperation is necessary to mitigate the risk.
Example 14
The employment department of a public administration office sent an email to individuals registered in its system as job seekers regarding upcoming training sessions. By mistake, a document containing all personal data of all those job seekers (name, email address, postal address, social security number) was attached to this email. The number of individuals affected by the leak exceeds 60,000. The office then contacted all recipients and requested them to delete the previous message and not to use the information contained therein.
What should be done?
Due to the risk, it is necessary to: document internally, report to the supervisory authority, and notify the data subjects.
In the case of sending such messages, stricter rules should have been implemented, and additional control mechanisms should be considered.
The number of affected individuals is significant, and the involvement of their social security numbers along with other more basic personal data further increases the risk, which can be classified as high.
As mentioned earlier, the ways to effectively mitigate the risk associated with such a breach are limited, and although the data controller requested the deletion of the message, they cannot compel the recipients to do so, nor can they ensure that the request will be fulfilled. The execution of all types of notifications should be evident in such cases.
Example 15
A list of participants in an English law course taking place at a hotel for 5 days is mistakenly sent to 15 former participants instead of to the hotel. The list contains the names, email addresses, and dietary preferences of 15 current participants. Only two participants filled out their dietary preferences, stating that they are lactose intolerant. The data controller immediately discovers the error after sending the list and informs the recipients of the mistake, requesting them to delete the list.
What should be done?
Due to the risk, it is necessary to: document internally.
The risk arising from the nature, sensitivity, quantity, and context of personal data is low. The personal data includes sensitive information regarding the dietary preferences of two participants. Even though the information that someone is lactose intolerant constitutes health data, the risk that this data will be used in an experimental manner should be considered relatively low.
Practical DPO Course
will confirm your high competencies
In summary, the EROD states that the breach did not have a significant impact on the individuals concerned. The fact that the data controller promptly contacted the recipients upon discovering the error can be considered a mitigating factor.
In light of the above, it is unlikely that the breach posed a threat to the rights and freedoms of the individuals concerned, and therefore, it was not necessary to notify the supervisory authority or the individuals whose data is concerned. However, the breach should be documented in internal records.
Example 16
An insurance group offers car insurance. To this end, it regularly sends customized policies regarding premiums via regular mail. In addition to the name and address of the policyholder, the letter includes the vehicle registration number, insurance rates for the current and next insurance year, approximate annual mileage, and the policyholder's date of birth.
The letters are packaged using automatic packing machines. Due to a mechanical error, two letters for different policyholders are placed in one envelope and sent to one policyholder by mail. The policyholder opens the letter at home and views their correctly delivered letter, as well as the incorrectly delivered letter of another policyholder.
What should be done?
Due to the risk, it is necessary to: internally document and report to the supervisory authority.
The impact on the affected individual should be considered moderate, as information that is not publicly available, such as the date of birth or vehicle registration numbers, and if the insurance rate increases, information about a potential accident, will be disclosed to an unauthorized recipient.
The likelihood of misuse of this data falls within the range of low to moderate; however, although many recipients are likely to throw the incorrectly received letter in the trash, in individual cases, it cannot be completely ruled out that the letter will be published on social networks or that the unauthorized recipient will contact the policyholder.
According to the GDPR, the breach must be reported to the supervisory authority.
Measures to Prevent Mailing Errors
- Establishing precise standards for sending letters/emails, leaving no room for interpretation.
- Providing appropriate training for staff on sending letters/emails.
- When sending emails to multiple recipients, they are by default listed in the "BCC" field.
- Applying the four-eyes principle.
- Using automatic addressing instead of manual, with data extracted from an available and up-to-date database; the automatic addressing system should be regularly reviewed for hidden errors and incorrect settings.
- Implementing a message delay (e.g., a message can be deleted/edited within a specified time after clicking the "send" button).
- Awareness training on the most common errors leading to personal data breaches.
- Training and brochures regarding procedures in the event of incidents leading to breaches of personal data protection and whom to inform (including the DPO).
Social Engineering
The last category that the EDPB focuses on in its guidelines is social engineering. These are simply frauds, utilizing social engineering techniques to persuade another person to achieve our goals.
Example 17
In the penultimate example, the EDPB takes us to a telecommunications company, specifically to its customer service department. An employee answers a call from a person claiming to be a customer. The presumed customer requests the company to change the email address to which billing information should be sent. The employee verifies the customer's identity by asking for certain personal data in accordance with the procedures in place at the company. The caller correctly provides the VAT number and mailing address of the requested customer (as they had access to these elements).
After verification, the operator makes the requested change, and from that moment on, billing information is sent to the new email address. The procedure does not provide for notifying the previous email contact. In the following month, the authorized customer contacts the company asking why they are not receiving invoices at their email address and is met with a call requesting a change of email contact. Later, the company realizes that the information was sent to an unauthorized user and reverses the change.
What should be done?
Due to the risk, it is necessary to: document internally, report to the supervisory authority, and notify the individuals concerned.
The EDPB emphasizes the importance of prior security measures. The breach is associated with a high level of risk, as billing data may provide insights into the private life of the individual concerned (e.g., habits, contacts) and may lead to material harm (e.g., stalking).
UODO Control.
For us, it's routine!
In light of this case, the customer verification process needs to be clearly refined. The methods used for authentication were insufficient. The malicious party could impersonate the intended user by using publicly available information to which they otherwise had access. In return, EROD proposes the introduction of an out-of-band multi-factor authentication method, for example, verifying a modified request by sending a confirmation request to the previous contact or adding additional questions and requiring information visible only on previous invoices.
Example 18
The last case prepared by EROD concerns an attack on the email of a supermarket. Three months later, the supermarket chain detects that someone set a rule to redirect all messages containing the phrases “invoice,” “payment,” “bank transfer,” “credit card authentication” to an external email address. Furthermore, in the meantime, the chain fell victim to a social engineering attack, in which someone impersonated a supplier and changed the bank account details of the actual supplier to their own. The company was unable to determine how the attacker gained access to the email accounts but suspected that a group of employees from the accounting department was responsible for the compromised email.
By redirecting emails based on keywords, the attacker obtained information about a total of 99 employees:
- names and salaries for the given month concerning 89 individuals,
- names, marital status, number of children, salaries, working hours, and other payroll information for 10 employees whose contracts had been terminated.
The data controller only notified the 10 individuals who no longer work for the supermarket chain.
What should be done?
Due to the risk, it is necessary to: document internally, report to the supervisory authority, and notify the individuals concerned.
Since the breach could lead to both material damages (e.g., financial losses) and non-material damages (e.g., phishing), the personal data breach may result in a high risk to the rights and freedoms of individuals. Therefore, all 99 employees should be informed of the breach, not just the 10 employees.
The fact that the breach could have occurred and remained undetected for such a long time, along with the possibility that social engineering could have been used to change a larger amount of data over time, highlighted serious issues in the data controller's IT security system. These issues must be addressed immediately, with an emphasis on automated reviews and change controls, incident detection, and response measures. Data controllers processing sensitive data, financial information, etc., bear greater responsibility for ensuring adequate data security.
EROD indicates that all employees and the supervisory authority should be notified of the breach.

