When a personal data breach occurs, one of the first and most important decisions a controller must make is whether the incident needs to be reported. That decision is not simply determined by whether personal data has been lost, disclosed or accessed without authorisation — the UK GDPR requires controllers to assess the risk that the breach creates for the rights and freedoms of the affected individual.
There are two distinct thresholds. Under Article 33 UK GDPR, a personal data breach must be notified to the ICO unless it is unlikely to result in a risk to individuals. Under Article 34, the individuals must be informed where the breach is likely to result in a high risk to their rights and freedoms. The distinction is important – a breach may require notification to the ICO without necessarily requiring notification to the affected individuals.
Making that assessment requires more than applying a simple formula or asking whether the breach appears serious. Controllers must consider the particular circumstances of the incident, including the nature and sensitivity of the information involved, who has received or may have access to it, the ease with which individuals can be identified, the potential consequences for those individuals and the likelihood of those consequences occurring. The number of people affected is relevant but a breach involving a single individual can still present a significant or high risk.
This article looks at how controllers should approach that risk assessment and the factors that should be considered when deciding whether a personal data breach must be reported to the ICO and whether the affected individuals must also be informed.
The law:
Article 4 UK GDPR definitions:
‘Personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
‘Personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
Article 33 UK GDPR– the breach reporting requirements to the ICO:
In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the Commissioner, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification under this paragraph is not made within 72 hours, it shall be accompanied by reasons for the delay.
Article 34 – the ommunication of a personal data breach to the data subject
When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.
When does a data breach need to be reported?
Although the UK GDPR has the obligation to notify a breach, it is not a requirement to do so in all circumstances as the notification to the ICO is required unless a breach is unlikely to result in a risk to the rights and freedoms of individuals. Communication of a breach to the individual is only triggered where it is likely to result in a high risk to their rights and freedoms. This risk exists when the breach may lead to physical, material or non-material damage for the individuals whose data have been breached. Examples of such damage are discrimination, identity theft or fraud, financial loss and damage to reputation. When the breach involves personal data that reveals racial or ethnic origin, political opinion, religion or philosophical beliefs, or trade union membership, or includes genetic data, data concerning health or data concerning sex life, or criminal convictions and offences or related security measures, such damage should be considered likely to occur.
What factors should be considered when assessing risk?
There are several factors to consider when assessing risk. Recitals 75 and 76 state that generally when assessing risk, consideration should be given to both the likelihood and severity of the risk to the rights and freedoms of data subjects. The focus is wholly about the resulting risk of the impact of the breach on individuals. The controller should assess the specific circumstances of the breach, the data affected, and the potential level of impact on individuals, as well as how likely this risk will materialise, as set out below:
• The type of breach — the type of breach that has occurred may affect the level of risk presented to individuals. For example, a confidentiality breach whereby medical information has been disclosed to unauthorised parties may have a different set of consequences for an individual to a breach where an individual’s medical details have been lost, and are no longer available.
• The nature, sensitivity, and volume of personal data – when assessing risk, a key factor is the type and sensitivity of personal data that has been compromised by the breach. Usually, the more sensitive the data, the higher the risk of harm will be to the people affected, but consideration should also be given to other personal data that may already be available about the data subject. Breaches involving health data, identity documents, or financial data such as credit card details, can all cause harm on their own, but if used together they could be used for identity theft. A combination of personal data is typically more sensitive than a single piece of personal data.
• Ease of identification of individuals — an important factor to consider is how easy it will be for a party who has access to compromised personal data to identify specific individuals, or match the data with other information to identify individuals. Depending on the circumstances, identification could be possible directly from the personal data breached with no special research needed to discover the individual’s identity, or it may be extremely difficult to match personal data to a particular individual, but it could still be possible under certain conditions. Identification may be directly or indirectly possible from the breached data, but it may also depend on the specific context of the breach, and public availability of related personal details.
• Severity of consequences for individuals — depending on the nature of the personal data involved in a breach, for example, special categories of data, the potential damage to individuals that could result can be especially severe, in particular where the breach could result in identity theft or fraud, physical harm, psychological distress, humiliation or damage to reputation. If the breach concerns personal data about vulnerable individuals, they could be placed at greater risk of harm. Whether the controller is aware that personal data is in the hands of people whose intentions are unknown or possibly malicious can have a bearing on the level of potential risk.
• Special characteristics of the individual – a breach may affect personal data concerning children or other vulnerable individuals, who may be placed at greater risk of danger as a result. There may be other factors about the individual that may affect the level of impact of the breach on them.
• Special characteristics of the data controller — the nature and role of the controller and its activities may affect the level of risk to individuals as a result of a breach. For example, a medical organisation will process special categories of personal data, meaning that there is a greater threat to individuals if their personal data is breached, compared with a mailing list of a newspaper.
• The number of affected individuals — a breach may affect only one or a few individuals or several thousand, if not many more. Generally, the higher the number of individuals affected, the greater the impact of a breach can have. However, a breach can have a severe impact on even one individual, depending on the nature of the personal data and the context in which it has been compromised. Again, the key is to consider the likelihood and severity of the impact on those affected.
Therefore, when assessing the risk that is likely to result from a breach, the controller should consider a combination of the severity of the potential impact on the rights and freedoms of individuals and the likelihood of these occurring. Clearly, where the consequences of a breach are more severe, the risk is higher and similarly where the likelihood of these occurring is greater, the risk is also heightened. The focus should always be on the real-world impact the breach could have on the individuals concerned, considering both the likelihood of harm and its potential severity. The reasoning behind that assessment should also be clearly documented, particularly where the decision is made not to notify the ICO or the affected individuals.
Kristy Gouldsmith