Expert Advice Community

Guest

Data breaches

  Quote
Guest
Guest user Created:   Jul 23, 2018 Last commented:   Jul 23, 2018

Data breaches

Under the pre GDPR legislation in relation to a financial institution, data of a financial nature was defined as any name, account number, credit card number, that could be used to identify an individual, and any unauthorized disclosure was deemed to be a reportable breach. That same definition is omitted from 2018 GDPR legislation. Is such a breach no longer deemed to be reportable? Many thanks for your time and expertise.
0 0

Assign topic to the user

EU GDPR DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

EU GDPR DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Andrei Hanganu Jul 23, 2018

Answer:

Article 4 – Definitions of the EU GDPR (https://advisera.com/gdpr/definitions/) defines personal data as “any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;” so this definitely includes the account number as we ll as credit card number.

As regards to data breaches, notifying data breaches was not required under the old directive but is now under the EU GDPR under certain circumstances that relate to the likelihood of the breach affecting the rights and freedom of the data subjects. So, unless there is no risk to the data subject a controller can choose not to notify a breach. However, if we are talking about financial data is most likely that there would be a risk for the affected data subjects thus the breach would need to be reported.

To learn more about data breaches check out our webinar “A How-to Guide for GDPR Data Breach Notifications” (https://advisera.com/eugdpracademy/webinar/a-how-to-guide-for-gdpr-data-breach-notifications-free-webinar-on-demand/)

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jul 23, 2018

Jul 23, 2018

Suggested Topics