Chapter 17
Data Breaches and Reporting Obligations
IN THIS CHAPTER
Defining and categorizing data breaches
Exploring risk factors and consequences caused by a breach
Determining whether a breach has occurred — and taking appropriate action
Knowing when (and where) to send notifications
Documenting breaches and evidence of your investigation into the breach
Sanctions for not following breach protocol
As a data controller or a data processor, your obligation is to secure personal data that you process. If your organization suffers a personal data breach, you have to carry out certain reporting and recordkeeping requirements. Although the only data breaches you tend to hear about are those of large companies, small businesses can suffer data breaches, too. Data breaches more often than not happen accidentally and thus aren’t always a result of malicious intentions.
In this chapter, I ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access