Notice
HSC reprimanded for delayed breach notification (2024-07-04)
IssuedView on ODPA's website Source document
Summary
This is a public statement issued by the Guernsey Office of the Data Protection Authority (ODPA) reprimanding the Committee for Health and Social Care (HSC) for failing to notify the Authority and affected individuals of a personal data breach within the timeframes required by the Data Protection (Bailiwick of Guernsey) Law, 2017. It sets out the facts, the Authority's reasoning, and the sanction imposed, and is intended to guide other controllers on breach notification expectations.
- What happened: HSC became aware in December 2023 of a breach affecting three individuals' personal data (including substance misuse information) but did not notify the Authority until 52 days later, and did not notify affected individuals until 50 and 62 days later.
- Legal requirements breached: Section 42(2) requires notice to the Authority as soon as practicable and no later than 72 hours after becoming aware of a breach, unless not practicable; section 43(1) requires written notice to affected individuals as soon as practicable where a breach poses a high risk to their significant interests.
- Authority's finding: The Authority found HSC had sufficient information from the outset to know a breach had occurred and had no valid reason for the delay; HSC breached sections 42 and 43 of the Law.
- Sanction: The Authority issued a reprimand to HSC under section 73 of the Law following an Inquiry under section 69.
- Guidance for controllers: Where full information is not yet available, an initial report to the Authority must still be made within 72 hours, with further details provided in stages; individuals must be given sufficient information in a timely manner.
Although this statement concerns a specific controller, it serves as a reminder to all controllers under the Bailiwick of Guernsey data protection regime of the strict 72-hour breach notification obligation to the Authority and the 'as soon as practicable' notification obligation to affected individuals where high risk is present.
Key obligations
- Controllers must notify the ODPA of a personal data breach as soon as practicable and no later than 72 hours after becoming aware of it, unless not practicable, providing an initial report even if full details are unavailable, with further information supplied in stages.
- Controllers must give written notice of a personal data breach to affected individuals as soon as practicable where the breach is likely to pose a high risk to their significant interests.
Applies to
controllers, data controllers (public statement addressed to Committee for Health and Social Care, applicable guidance to controllers generally)
Deadlines
- 72 hours after becoming aware of a breach: Initial notification to the Authority must be made within this period unless not practicable, per section 42(2) of the Law.
- 29 July 2024: Deadline for HSC to appeal the Authority's determination to the Court under section 84 of the Law (28 days from the determination).