My Department is committed to protecting the rights and privacy of data subjects and adhering to obligations as a data controller under data protection legislation.
The Department deals with personal data breaches in line with the Department of Health’s Data Breach Management Policy. All personal data breaches are assessed on a case-by-case basis. Once a potential breach has been detected and secured, a risk assessment is undertaken to determine the risk to the rights and freedoms of the affected data subjects. Under the GDPR, the Department must notify personal data breaches to the DPC unless it is unlikely to result in a risk to data subjects. Where a breach is likely to result in a high risk to data subjects, the Department must also inform those individuals without undue delay. All incidents are logged and reviewed to prevent a similar breach from reoccurring.
The table below sets out the number of personal data breaches logged by my Department since the introduction of the General Data Protection Regulation (GDPR) in 2018 to date.
|
Year
|
Total Breaches
|
Type of Breach
|
|
2018
|
4
|
Human Error; Unauthorised Use/Access to Data
|
|
2019
|
2
|
Human Error
|
|
2020
|
16
|
Human Error; Loss or Theft
|
|
2021
|
20
|
Human Error; Unauthorised Use/Access to Data; Hacking Attack; Loss or Theft
|
|
2022
|
9
|
Human Error; Unauthorised Use/Access to Data; Loss or Theft; Temporary Loss of Availability
|
|
2023
|
14
|
Loss or Theft; Human Error; Unauthorised Use/Access to Data
|
|
2024
|
8
|
Human Error; Loss or Theft; Unauthorised Use/Access to Data
|