"GDPR 2018 - 2023"
41 Loss of control of paper files

Case Summary Actions Taken

A public sector health service provider discovered a data The organization immediately reported the breach to
breach when patient medical records were found in an the Data Protection Commission (DPC), complying
abandoned storage cabinet on an unoccupied hospital with GDPR Article 33.
premises. The breach was exacerbated when an
unauthorized individual gained access to the restricted A representative from the organization was
premises and posted photographs of the files on social dispatched to secure and remove the files from the
media. unoccupied premises.

"stop dreaming and
Resolution Key Takeaway

start doing"
The breached patient records were secured, and the This case underscores the critical need for proper
organization took steps to ensure the files were no longer records management policies and security measures.
accessible to unauthorized individuals. It's essential to track files, maintain secure storage
facilities, and establish clear procedures for record
The organization cooperated with the DPC's investigation retention or deletion to prevent unauthorized access
and implemented recommendations provided by the and data breaches.

The GDPR rules relevant to this case include Article 33 (Notification of a personal data breach)
GDPR Rule and general principles around data security and accountability outlined throughout the GDPR.
Compliance with these rules is essential to prevent and respond to data breaches effectively.
42 Ransomeware Attack

Case Summary Actions Taken

An organization operating in the leisure industry reported The organization promptly notified the DPC about the
a ransomware attack to the Data Protection Commission ransomware attack, aligning with GDPR Article 33.
(DPC). The attack potentially encrypted or disclosed the They took immediate steps to isolate the
personal data of up to 500 customers and staff stored on compromised server and prevent further unauthorized
the organization's server. The breach was traced back to access.
a compromised modem router, but backup data was
securely stored in the cloud.

Resolution QUOTE Key Takeaway

The organization worked closely with the DPC, This case emphasizes the importance of robust

"stop dreaming and

implementing recommendations to improve its
information and communication technology (ICT)
cybersecurity measures, employee training, and
proactive responses to data breaches. Maintaining
infrastructure. secure backup systems and conducting regular

start doing"
They conducted a thorough analysis to ensure no further
security assessments are vital for GDPR compliance
and data protection.
malware was present.

Enhanced security measures were put in place to protect

the processing of personal data.

Employee training on cybersecurity risks was initiated.

Relevant GDPR rules include Article 33 (Notification of a personal data breach) and the GDPR's
fundamental principles for data security and accountability. Compliance with these rules, as well
as the DPC's recommendations, helped the organization address the breach and enhance its
data protection practices.
43 Disclosure of CCTV footage via social media

Case Summary Actions Taken

A property management company notified the Data The property management company communicated
Protection Commission (DPC) that an employee of a with staff who received the footage, instructing them
security company, contracted by them, used a personal to delete it and refrain from further dissemination.
mobile phone to record CCTV footage of two members of
the public engaged in an intimate act, which had been The DPC was promptly informed of the incident,
captured by the management company's security complying with GDPR Article 33.
cameras. The employee subsequently shared the video
via WhatsApp with a limited number of individuals.

Key Takeaway

"stop dreaming and

Both the property management company and the security
company were able to demonstrate the existence of
This case highlights the significance of not only
having data protection policies and procedures in
adequate data protection policies and procedures. place but also ensuring adequate oversight and

start doing"
The property management company, in response to DPC
recommendations, improved oversight and supervision to
supervision to enforce compliance. Training and clear
guidelines are essential to prevent personal data
ensure compliance with these policies. breaches.
Additional data protection training was delivered to staff
with an emphasis on personal data breaches.
Signage prohibiting the use of personal mobile devices
in the CCTV control room was displayed.

Relevant GDPR rules include Article 33 (Notification of a personal data breach) and the GDPR's
emphasis on accountability, oversight, and compliance with data protection policies. By
enhancing oversight and implementing additional training, the property management company
worked to address shortcomings in its data protection practices.
44 Breach Notification (Voluntary Sector) — Ransomware Attack

Case Summary Actions Taken

In May 2020, the Irish Data Protection Commission The data processor and data controller promptly
(DPC) received a breach notification from an Irish data notified the DPC in compliance with GDPR Article 33.
processor and a data controller operating in the voluntary The DPC initiated communication with both parties,
sector, who had enlisted the processor for web hosting seeking to understand potential non-compliance areas
and data management services. The breach resulted related to data protection regulation.
from a ransomware attack that occurred in the data
center used by the processor, where malware gained
access through a Remote Desktop Protocol (RDP) port

on the server.

"stop dreaming and

Resolution Key Takeaway

The DPC engaged intensively with both the data This case underscores the importance of ensuring

start doing"
controller and processor, issuing technical and data protection compliance and oversight, especially
organizational questionnaires to identify areas of potential when engaging data processors. Adequate
non-compliance. agreements, oversight, and agreements for
The DPC concluded the case by providing international data transfers are crucial for GDPR
recommendations to both the data controller and compliance.
Ongoing engagement between the DPC and both parties
ensured the implementation of DPC recommendations.

Relevant GDPR rules include Article 33 (Notification of a personal data breach) and Article 28,
which outlines the requirements for data processing agreements and the responsibilities of data
controllers and processors. Engaging intensively with the DPC and implementing their
recommendations helped both parties address potential non-compliance areas.
45 Breach Notification - Erroneous Publication on Twitter

Case Summary Actions Taken

A public sector organization informed the Data Protection The organization notified the DPC about the
Commission (DPC) that they had unintentionally inadvertent publication, complying with GDPR Article
published personal data through their social media 33.
platform, specifically Twitter. This publication of personal The offending tweet was removed without undue
data occurred in violation of the organization's policy to delay.
anonymize all content that could potentially identify
individual data subjects. The organization attributed the
incident to human error, and the offending tweet was
promptly removed.

Key Takeaway

"stop dreaming and

The DPC examined the matter and, based on the actions
taken to mitigate the risk of a recurrence, concluded its
This case emphasizes the importance of human error
as a potential source of data breaches. It also
investigation. underscores the need for organizations to have clear

start doing"
The DPC issued additional recommendations to the
organization, focusing on the proper use of social media
policies in place for anonymizing content and secure
access control to social media platforms to prevent
platforms and secure access control. the unintentional disclosure of personal data.

Relevant GDPR rules include Article 33 (Notification of a personal data breach) and the GDPR's
principles regarding data protection and accountability. Compliance with these principles and the
DPC's recommendations is essential for addressing data breaches and preventing their
46 Breach Notification - Bank Details sent by WhatsApp

Case Summary Actions Taken

A private financial sector organization notified the Data The organization promptly notified the DPC of the
Protection Commission (DPC) about an incident where a data breach in accordance with GDPR Article 33.
customer requested their IBAN and BIC numbers, and a The customer who received the incorrect information
staff member, who personally knew the customer, used contacted the organization and deleted the data from
their personal mobile phone to send the information via their device.
WhatsApp. Unfortunately, the staff member sent details The organization reminded its staff to use only
related to another customer to the requesting individual. authorized methods of communication for handling
such requests.

Key Takeaway

"stop dreaming and

The DPC issued several recommendations, including
using approved organizational communication tools,
This case underscores the importance of following
approved organizational communication practices,
ensuring staff understand acceptable and non-acceptable especially when handling sensitive customer data.

start doing"
behavior when using such tools, and providing
appropriate GDPR and Data Protection Act 2018 training
Adequate training and awareness of data protection
obligations are crucial to prevent unauthorized data
to staff. disclosures.

Relevant GDPR rules include Article 33 (Notification of a personal data breach) and the GDPR's
principles regarding data protection and accountability. Compliance with these principles, along
with the DPC's recommendations, is essential for addressing data breaches and improving data
protection practices.
47 Breach Notification - Processor Coding Error

Case Summary Actions Taken

The Data Protection Commission (DPC) received Credit unions reported the issue to the DPC as a
separate breach reports from 12 credit unions that breach in accordance with GDPR Article 33.
utilized the services of the same data processor based in The affected credit unions engaged with the
the UK. The processor's breach resulted from a coding processor directly and through a user group to identify
error made when implementing measures related to the affected records, establish correct coding procedures,
Covid-19 pandemic response. Credit unions report and send corrected CCR returns to the Central Bank.
information to the Central Bank of Ireland for the Central
Credit Register (CCR), which lenders and credit rating

agencies use to verify borrowers' debts and credit

Resolution Key Takeaway

"stop dreaming and

The data processor worked with the credit unions to
rectify the coding error and ensure accurate CCR returns.
Effective processing contracts are crucial for ensuring
that processors assist controllers in meeting their

start doing"
These cases highlight the importance of processing
contracts that properly implement the requirements of
obligations, including security of processing and
reporting and responding to breaches. Collaboration
Article 28 of the GDPR. between data controllers and processors is essential
in rectifying data breaches.

The primary GDPR rule relevant to these cases is Article 28, which outlines the responsibilities
and requirements for data processing contracts, particularly in terms of security of processing,
reporting, and responding to breaches. Compliance with these contractual obligations is vital for
maintaining data protection and data accuracy.
48 Repeated similar breaches

Case Summary Actions Taken

Over a 12-month period, the Data Protection Commission The DPC identified a pattern of breaches and raised
(DPC) received multiple notifications of similar breaches the issue with the controller, prompting them to
from a data controller in the financial sector. The acknowledge the systemic problem requiring senior
controller provided services through a nationwide retail management attention.
network operated by a third party, acting as its processor. Interim measures were adopted, including staff
These breaches occurred when existing customers used retraining, increased supervision, and on-screen
different addresses during purchases at the processor's notices for processor staff to confirm customer
outlets, leading to sales documents being sent to old address accuracy.

addresses, not the new ones registered with the
controller. Recent changes in the controller's customer
database systems were not synchronized with sales
The controller worked on a technical solution, and
interim measures were implemented.

procedures, causing the issue. The controller had

"stop dreaming and

instructed the processor to ensure address changes
before accepting purchase requests, but some counter
staff didn't consistently follow these procedures.

Resolution start doing" Key Takeaway

The controller modified its IT systems to prevent sales This case highlights the DPC's role in monitoring
documents from being sent to incorrect customer breaches to identify systemic issues, the importance
addresses, successfully stopping recurring breaches. of coordinated information systems, and the
unintended consequences of system changes.
Controllers must also ensure that processors clearly
understand and adhere to data processing
procedures to protect data subjects and comply with
the GDPR.

Relevant GDPR principles include Article 33 (Notification of a personal data breach) and Article
GDPR Rule 28, emphasizing the need for processors to follow agreed-upon procedures. Controllers and
processors must work together to avoid systemic issues that can lead to data breaches.
49 Unauthorised disclosure arising from video conferencing

Case Summary Actions Taken

During the pandemic, an educational institute used video The organization reported the breach to the Data
conferencing for student presentations, which were recorded Protection Commission (DPC).
for external examiners. The plan was to keep these The recordings accessible to students were
recordings private from students. However, after two deleted, and the excerpts were removed from
sessions, the lecturers' discussions about the students' work social media. The DPC conducted an assessment
were also recorded. It was mistakenly believed that only the and provided comprehensive recommendations.
lecturers could access these discussions, but in reality, all

participants, including students, had access. The students
received automatic links to these files, which contained
personal remarks about some students. Consequently,
students accessed and shared these recordings, including
the personal comments, on messaging apps and social

"stop dreaming and

media, breaching privacy and confidentiality unintentionally.

Resolution start doing" Key Takeaway

The breach was resolved, and steps were taken to remove This case underscores the risks associated with
the shared excerpts. video conferencing technology and similar tools. It
The DPC issued recommendations to improve IT equipment emphasizes the importance of ensuring that those
usage and ensure compliance with data protection policies. who operate such applications are familiar with
how they work and follow data protection laws.
Controllers must also ensure that data protection
policies and procedures align with current
practices and technologies.

Relevant GDPR rules include the principles of data protection, data minimization, and the
importance of ensuring that personal data is processed in compliance with data protection laws.
This case emphasizes the need for careful handling of data in education and the use of
technology to prevent unintended breaches.
50 Disclosure due to misdirected email

Case Summary Actions Taken

A statutory body responsible for investigating complaints The statutory body promptly notified the Data
about experts' professional conduct, training, or Protection Commission (DPC) of the breach, as
competence reported a personal data breach. The required by GDPR Article 33.
breach occurred when a letter regarding a complaint The organization informed all affected individuals
against a specialist was mistakenly attached to an email about the breach, the risks involved, and the
and sent to an incorrect address. The attached letter measures taken in response, in compliance with
contained personal data, including health data, and was GDPR Article 34.
encrypted. However, the password for decrypting the

letter was sent in a separate email to the same incorrect

Resolution Key Takeaway

"stop dreaming and

The DPC reminded the organization of its ongoing
obligation to secure accidentally disclosed personal data
This case underscores that misaddressed emails are
a common cause of data breaches. While encryption

handling personal data. start doing"

and the importance of ensuring email security when is a valuable tool for protecting against accidental
disclosures, it is advisable to use a separate, secure
The statutory body initiated a comprehensive review of all medium, such as a phone call or SMS message, to
its data protection processes, policies, and procedures. share encryption passwords to mitigate the risk of
sending it to the wrong recipient.

The relevant GDPR rules in this case include Article 33 (Notification of a personal data breach)
and Article 34 (Communication of a personal data breach to the data subject). The case
highlights the importance of ongoing vigilance in securing personal data and the necessity for
robust data protection processes.

