Unlock|cia||Laure Baccauw||

Data Breaches: what is it and what are our obligations?

For the last four years, we have faced numerous alerts about data breaches. That said, it’s important to understand what a data breach really is and what our data protection obligations are once it occurs? 

According to article 4(12) of the GDPR, a personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed. 

This broad definition covers all three pillars of security: confidentiality, integrity, availability.(CIA) However, it is not always easy to identify if a security incident qualifies as a personal data breach. Therefore, categorizing the incident according to the CIA principles can be useful to identify whether it is a personal data breach. 

Let’s talk about the CIA principles: There are three different types of breaches that we must be aware of, which can be referred to as the CIA principles. Two typesConfidentiality Breaches and Integrity Breachesare relatively easy to identify. A Confidentiality Breach occurs when data is accessed or disclosed to an unauthorized person, whilst an Integrity Breach is when data is altered by an unauthorised person, making it inaccurate or incomplete.

However, there is a third type of breach that is more difficult to identify: an Availability Breach. This type of breach is when data is no longer accessible or usable on demand by an authorized entity, either temporally or definitively. 

cia

Understanding these types of breaches is critical, as they can occur in any sector — but some industries are particularly vulnerable due to the sensitivity of the data they process. One such sector is healthcare, where the consequences of a breach can be both severe and far-reaching. 

Over the past few years, the digital transformation in the healthcare sectors has been faster than ever. Paper-based systems have been replaced by electronic health records, with more and more clinical trials collecting data from e-systems and/or recording it in electronic database. Medical web-based smart devices have been developed to improve diagnosis and treatment. All of these developments have the clear aim to help save patients’ lives or make them far more comfortable.

However, this expansion of e-connected systems also opens doors to attackers. Personal data breaches are widely observed in the healthcare sector because health data is more valuable on the black market than any other data including financial data. 

In April 2022, the CNIL fined Dedalus Biologie, a company that markets software solutions for medical analysis laboratories, 1,5 million of euros after a massive data leak involving nearly 500,000 individuals, which was revealed in the press. The breach included family names, first names, social security numbers, names of the prescribing doctor, dates of the examination, but most notably, medical information (HIV, cancers, genetic diseases and data, pregnancies, drug treatments followed by the patient) of the individuals, and this was disseminated on the Internet. 

This is just one example among thousands. Data breaches have been increasing in recent years. In fact, in its last survey on GDPR fines and data breaches, DLA Piper published that there have been over 130,000 personal data breaches have been notified to regulators. For perspective, that is an average of 356 breach notifications per day, an 8% increase on last year’s daily average of 331 notifications. 

Powered by MyData-TRUST

Want to subscribe to our newsletter ?

Name(Required)
Privacy(Required)