GDPR questions and answers

GDPR: QUESTIONS AND ANSWERS

Category:
Incidents and Fines

Who should handle reports concerning security incidents in the context of whistleblower protection? Do employees other than the designated committee have such authority?

ANSWER

An interesting and not easy question. The likelihood of such a situation arising (especially given that the volume of whistleblower reports is unlikely to be significant) is slim, but theoretically possible. I see the solution in limiting to the maximum extent the number of persons handling the security incident, and additionally, before granting access to whistleblower data, I would propose obtaining from them declarations confirming that they are aware of the sensitivity of the data to which they have access and of the liability they face for disclosing whistleblower data or data relating to persons whose reports were involved. Admittedly, obtaining a declaration does not resolve the matter, but it is important to make those handling the security incident aware that they are not dealing with an "ordinary" incident, and it also gives us, as the controller, evidence that we have taken all possible steps to protect whistleblower data and data relating to persons covered by the report. Nevertheless, the security incident must be handled, which is also in the interest of persons whose data was compromised as a result of the incident.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.
Handling security incident reports in whistleblower protection | ODO 24 | ODO 24