Use cases

Flag incident reports that may be notifiable breaches

Reads each staff incident report for what happened, the data involved, whether it left and if it is contained. The privacy team decides on notifying.

Try it on this example

Example · A payroll file with bank details, sent to the wrong Sam at the cleaning contractor

Reporter's job title or team: Payroll administrator, Finance

Incident report

What happened? At about 4.40pm today I emailed the September payslip summary to the wrong Sam. I typed Sam and picked the first name that came up, which was Sam Pardew at Brightclean, our office cleaning contractor, instead of Sam Pardoe in Finance. I only noticed when Sam Pardoe asked me at 5.15pm where the file was. What data was involved? The attachment is an Excel file with the name, employee number, salary, tax code, National Insurance number, bank sort code and account number of everyone paid through the head office payroll, around 180 people. It also has a column showing who is on statutory sick pay this month. It was not password protected. Who received it or could see it? Sam Pardew at Brightclean, on his Brightclean email address. I don't know if anyone else can see his inbox. What have you done so far? I tried to recall the email but it has already gone outside our system. I emailed Sam Pardew at 5.20pm asking him not to open the file and to delete it and confirm. I have also rung Brightclean's office but it went to voicemail. No reply yet. I have told my manager.
  1. Does the incident report say what happened, what data was involved and who received it or could see it?Yes99%
  2. What kind of incident does the report describe?Sent to the wrong person100%
  3. Does the incident involve information about identifiable people?Yes99%
  4. Does the incident involve health, children's, financial account, government ID or password data, or other sensitive data?Yes99%
  5. Did the data reach, or could it have reached, someone outside the organisation?Yes97%
  6. Does the report say the data was recovered or the exposure was closed?No90%
  7. Does the report say whether the data or device was encrypted or password protected?Not protected100%
  8. Roughly how many people does the report suggest the data is about?Many people100%
  9. How soon should the privacy team read this incident report?Urgent100%

These are real answers stored from one run on this example.

The prism behind it

Flag incident reports that may be notifiable breaches9 questions

Fields

  • Reporter's job title or team
  • Incident report

Context

Incident reports sent by staff of Oakmere Homes, a housing association in England, through the internal incident form or the incident mailbox: an email or letter sent to the wrong person, a lost laptop or phone, a shared link left open, a suspicious login, a supplier telling us about an incident at their end. Each report is read so that the ones that may be personal data breaches reach the privacy team straight away, at any hour, and IT faults with no personal data go to IT. Rules we follow (UK GDPR): - A personal data breach is a breach of security that leads to personal data being lost, destroyed, changed, disclosed or accessed without authority, by accident or unlawfully. - A breach must be reported to the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of us becoming aware of it, unless it is unlikely to put people's rights and freedoms at risk. When the risk to people is likely to be high, they must be told too. Whether a breach is notifiable is a judgment for the privacy team. These answers only sort and prioritise the reports. Code records when the report arrived, runs the 72-hour clock and reads any number of people the report states. Nothing here judges the member of staff who made the report.

Questions

  1. Does the incident report say what happened, what data was involved and who received it or could see it? Yes / No

    Read the report. Yes: The report says what happened, what kind of data or device was involved, and who received it or could have accessed it, or that nobody could. No: The report leaves out at least one of these, so the privacy team would have to ask the reporter before judging it.

  2. What kind of incident does the report describe? Choice

    Read the report. Choose the option that describes how the incident happened. If more than one fits, choose the first cause.

    • Sent to the wrong person An email, letter, file or parcel went to the wrong recipient, or other people were copied in by mistake.
    • Lost or stolen A device, paper file or storage media was lost or stolen.
    • Outside access Someone outside the organisation got into a system or account, including a phished or compromised account.
    • Staff misuse A member of staff looked at or used records without a work reason, or took data when leaving.
    • Shared too widely Data was published or left open to too many people, such as a public link, wrong folder permissions or a document posted online.
    • Data unavailable or destroyed Data was encrypted by ransomware, deleted, corrupted or could not be reached.
    • Incident at a supplier A supplier or partner that holds our data reports an incident at their end.
    • Not a data incident An IT fault, a physical problem or a security concern with no data exposed, lost or changed.
  3. Does the incident involve information about identifiable people? Yes / No

    Read the report. Count names, contact details, account or tenancy records, case notes, photos, recordings, and any file or device the report says held details about customers, tenants, staff or others. Yes: The incident involves details about people who could be identified. No: The incident involves no information about identifiable people, such as a broken printer or a company-only price list.

  4. Does the incident involve health, children's, financial account, government ID or password data, or other sensitive data? Yes / No

    Read the report. Count health or disability information, data about children, ethnic origin, religion, sexual life or orientation, criminal records, bank or card details, National Insurance, passport or other ID numbers, and passwords or security answers. Yes: The report says at least one of these was involved. No: The report mentions none of these. Names, addresses and contact details on their own do not count.

  5. Did the data reach, or could it have reached, someone outside the organisation? Yes / No

    Read the report. Count a wrong recipient outside the organisation, a device lost in a public place, a public link, and outside access to a system. Yes: The data reached, or could have reached, someone outside the organisation. No: The data stayed inside the organisation, such as an email sent to the wrong colleague, or nothing left at all.

  6. Does the report say the data was recovered or the exposure was closed? Yes / No

    Read the report. Count a recipient who confirmed deletion, a link removed, a device found or wiped remotely, or a password reset on a compromised account. Asking for deletion with no reply yet does not count. Yes: The report says the data was recovered or the exposure was closed. No: The report says nothing of the kind, or says the exposure is still open or unconfirmed.

  7. Does the report say whether the data or device was encrypted or password protected? Choice

    Read the report. A negative statement, such as "it was not password protected", counts as saying the data was not protected.

    • Protected The report says the data or the device was encrypted or password protected.
    • Not protected The report says the data or the device was not encrypted or not password protected.
    • Not stated The report does not say either way.
  8. Roughly how many people does the report suggest the data is about? Choice

    Read the report. Give a rough band only; code reads any number the report states.

    • One person The data is about one person.
    • A few people The data is about a handful of people, such as a household or a short list.
    • Many people The data is about dozens of people or more, or a whole list, spreadsheet, mailbox or database.
    • Not stated The report gives no way to tell how many people the data is about.
  9. How soon should the privacy team read this incident report? Scale

    Read the whole report and judge the risk to the people whose data is involved. This sets the order of the queue; it is not a decision on whether the breach is notifiable.

    • Log only No personal data is involved, or none could have been seen by anyone who should not see it.
    • Routine Personal data is involved but the exposure is small and closed, such as one ordinary email to the wrong colleague, deleted.
    • Today Personal data reached or could reach someone outside, or the exposure is not yet closed, but no sensitive data and not many people.
    • Urgent Sensitive data or many people are involved, and the data reached or could reach someone outside and is not yet recovered.

Lens columns

enough_detail, enough_detail_probability, incident_type, incident_type_probability, personal_data_involved, personal_data_involved_probability, sensitive_data_involved, sensitive_data_involved_probability, left_the_organisation, left_the_organisation_probability, contained, contained_probability, encryption, encryption_probability, people_affected, people_affected_probability, review_priority, review_priority_average

Run it on your own text

Add this prism in the app, change any question, and test it on a file of your own.

Ask for an invite