How to manage a personal data breach
Published by a LexisNexis Risk & Compliance expert
Practice notesHow to manage a personal data breach
Published by a LexisNexis Risk & Compliance expert
Practice notesData security is a cornerstone of the UK General Data Protection Regulation (UK GDPR). The sixth data protection principle (the integrity and confidentiality principle) requires you to take appropriate technical and organisational measures to process personal data in a manner that ensures appropriate security, including:
- •
protection against unauthorised or unlawful processing
- •
accidental loss, destruction or damage
This Practice Note reflects ICO guidance on personal data breaches under the UK GDPR. It also contains additional useful practical information set out in ICO guidance on data security breach management issued under the previous data protection regime. This guidance has now been withdrawn.
This Practice Note also reflects guidance issued by the European Data Protection Board (EDPB). According to the ICO, although the UK has left the EU, these guidelines continue to be relevant.
Data security requirements
Article 32 puts more flesh on the bones of the GDPR’s integrity and confidentiality principle. You are required to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk,
To view the latest version of this document and thousands of others like it,
sign-in with LexisNexis or register for a free trial.