INCIDENT RESPONSE PLAN DATA BREACH INCIDENT RESPONSE PLAN Privacy by Design/International Schools March 7-8, 2019
Normal day at the school Your school has online apps to process students’ data and severeal other tools to communicate with parents and other schools One Friday evening, there is a report in the news stating that your hosting provider is a target of massive hack Estimates are that millions of citizens’ data is at risk At the end of report there are logos of organisations that are at risk, and your school’s logo is blinking among them You are DPO and you phone seems to be almost going off due to mails, sms and other messages
In a perfect world…. … your school would have: Clear incident response plan with roles & responsibilities Confirmed communication channels with one dedicated contact point A media-trained director(s) to give statements Dedicated 24/7/365 contacts to all your third parties A back-to-back responsibility chain in all 3rd party agreements Operations continuation plan
If you have none of those Get hold of IT, Legal, Communications and management level asap Check yourself or get Legal reviewing your agreement with target company Contact the target company to establish communication channel Contact other schools’ representatives Agree on giving statements and on one single contact point Agree on giving information at your website (if not compromised) or any other means to your datasubjects Agree on steps to define width and depth of breach notification for authorities Instruct your call center and reception staff
Your first priority = students and teachers Under GDPR and several other regional laws you must ensure the security of the data of end-users The type of data and their quantity are important, yes but other considerations include: Possibly a criminal investigation an e-discovery process Employee and school-board considerations If police is involved, they want to keep things quiet, but the press not Try to limit damages while complying with legal requirements
Co-ordination and co-operation are the key It is important to have a consistent approach Coordinate with other schools Is it possible to agree on common statement –or let the target speak? Follow-up to be agreed Post mortem to be agreed – lessons learned Ensure that mistakes are not repeated, but corrected