I can inform the Deputy that my Department has a full suite of policies and procedures in place relating to data protection, as required by legislation, including a data breach policy. My Department's Data Protection Officer oversees robust mandatory training for all staff and engages in regular data protection awareness-raising campaigns. The information on data breaches requested by the Deputy, recorded by my Department since the introduction of the GDPR in 2018, is set out in the table beneath:
|
Year
|
No. of Recorded Personal Data Breaches
|
Nature of Breaches
|
|
2024 (ytd)
|
28
|
Lost/Stolen Device – 8
Confidentiality Breach (unintentional publication or sharing of personal data) – 20
|
|
2023
|
27
|
Lost/Stolen Device – 10
Confidentiality Breach (unintentional publication or sharing of personal data) - 17
|
|
2022
|
5
|
Lost/Stolen Device – 2
Confidentiality Breach (unintentional publication or sharing of personal data) -3
|
|
2021
|
6
|
Confidentiality Breach (unintentional publication or sharing of personal data) – 5
Cyber Attack – 1
|
|
2020
|
0
|
N/A
|
|
2019
|
1
|
Confidentiality Breach (unintentional publication or sharing of personal data) – 1
|
|
2018
|
4
|
Confidentiality Breach (unintentional publication or sharing of personal data) – 3
Ransomware Attack – 1
|
|
2013 - 2017
|
0
|
N/A
|