Home
Data breach
In the event of a data breach, there is a breach of the security of personal data. This concerns access to or destruction, alteration, loss or release of personal data without this being the intention.
A data breach therefore not only includes the actual release/leakage and processing of personal data, but also if there is the possibility to do so. Some examples of data breaches:
- an unencrypted lost USB stick with personal data;
- a lost or stolen insufficiently secured phone/laptop/tablet (private or business) with personal data or access to a Health-RI account with personal data;
- printed documents with personal data that lie unattended at a photocopier;
- if you determine that you have access to personal data that you should not have access to;
- sending sensitive personal data to an incorrect e-mail address (ie to someone it was not intended for);
- or break-in into a computer containing personal data or access to a Health-RI account containing personal data by a hacker.
Data breach notification obligation
The data breach notification obligation, is part of the General Data Protection Regulation (GDPR). The reporting obligation means that companies and organizations must report a (suspected) data breach: risk of loss or unlawful processing of personal data. The report is made to the Dutch Data Protection Authority (AP). In some cases, Health-RI must also report the data breach to all parties involved, i.e. to the people whose data has been leaked.
Report incident
If you have (a suspicion of) a data breach, report this immediately to the Health-RI servicedesk.