This translation is provided for information only. Only the Dutch version is legally binding.
Data Breach Notification Protocol
Considerations
- Dena Textile Productions B.V. attaches importance to the proper security of its (electronic) systems in which personal data are stored and processed.
- It can never be entirely prevented that a data breach will occur.
- Under the General Data Protection Regulation (GDPR), Dena Textile Productions B.V. is obliged to report (serious) data breaches to the Autoriteit Persoonsgegevens (the Dutch Data Protection Authority) and to the data subjects.
- Dena Textile Productions B.V. wishes to comply with its statutory obligations.
- Dena Textile Productions B.V. has therefore formulated a policy in order to act as adequately as possible should a data breach nevertheless occur.
1 - Definition of a data breach
A data breach occurs when a breach of security takes place that accidentally or unlawfully leads to the destruction, loss, alteration or unauthorised disclosure of, or unauthorised access to, data transmitted, stored or otherwise processed.
2 - Internal officer responsible for reporting data breaches
Dena Textile Productions B.V. has appointed an internal officer responsible for handling data breaches. This responsible officer is the Marketing department, with Rolf van Eden as the primary point of contact.
3 - Internal report upon discovery of a data breach
Anyone who discovers a data breach at Dena Textile Productions B.V. reports this without delay to the internal responsible officer. Where possible, the person who discovered the data breach simultaneously ensures that the leaked data are immediately erased remotely or rendered inaccessible.
4 - Investigation by the internal responsible officer
The internal responsible officer investigates, among other things: whether personal data have been lost or may be used unlawfully; who or which departments within the organisation are involved in the data breach; whether a processor is involved in the incident.
5 - Containment of the data breach
The internal responsible officer stops the data breach if this is still possible and furthermore takes the necessary measures to contain the data breach as effectively as possible.
6 - Determining the consequences of a data breach
The internal responsible officer investigates the possible consequences of the data breach on the basis of the nature and scope of the data that have been leaked and determines what the adverse consequences for the data subjects may be.
7 - Cooperation in providing information about the data breach
The person who discovered/reported the data breach provides full cooperation to the internal responsible officer by answering, as quickly and as thoroughly as possible (in writing), questions concerning: what happened; accident or malicious intent; when it happened; when it was discovered; type of leaked data; encryption status; possibility of remote erasure; possible consequences; affected groups; number of persons; involvement of EU countries; technical/organisational measures.
8 - Availability of staff after discovery of a data breach
The officer responsible for the department from which the data breach originated, as well as the person who discovered the data breach and everyone who, by virtue of their position or knowledge, is able to take organisational and/or technical measures, keep themselves available during the first 24 hours after discovery.
9 - Decision on reporting data breaches
The internal responsible officer decides as soon as possible, but in any event within 60 hours of discovery, whether reporting is necessary. In principle, a data breach is always reported to the Autoriteit Persoonsgegevens, unless it is unlikely that the data breach poses a risk to the rights and freedoms of the data subjects.
10 - Reporting data breaches to the Autoriteit Persoonsgegevens and/or data subjects
The internal responsible officer ensures that the report is made. Reporting takes place as soon as possible after discovery and no later than within 60 hours of discovery of the data breach. No other employee may make a report independently.
11 - Consequences of reporting data breaches
In the event of adverse consequences, the internal responsible officer determines the manner of information, aftercare and necessary actions. If a data breach has occurred - whether or not it has been reported - adequate technical and/or organisational measures are taken as soon as possible.
12 - Maintaining a register of data breaches
The internal responsible officer maintains a register containing: description of the incident, date/time of the data breach, date of discovery, type of data, categories of data subjects, number of persons, involvement of EU countries, notification status to the authorities and data subjects, information methods, consequences, and measures taken.
Questions about a (possible) data breach can be directed to privacy@dena.nl.