Flag incident reports that may be notifiable breaches
Reads each staff incident report for what happened, the data involved, whether it left and if it is contained. The privacy team decides on notifying.
Try it on this example
Reporter's job title or team: Payroll administrator, Finance
Incident report
- Does the incident report say what happened, what data was involved and who received it or could see it?Yes99%
- What kind of incident does the report describe?Sent to the wrong person100%
- Does the incident involve information about identifiable people?Yes99%
- Does the incident involve health, children's, financial account, government ID or password data, or other sensitive data?Yes99%
- Did the data reach, or could it have reached, someone outside the organisation?Yes97%
- Does the report say the data was recovered or the exposure was closed?No90%
- Does the report say whether the data or device was encrypted or password protected?Not protected100%
- Roughly how many people does the report suggest the data is about?Many people100%
- How soon should the privacy team read this incident report?Urgent100%
These are real answers stored from one run on this example.
The prism behind it
Flag incident reports that may be notifiable breaches
Fields
- Reporter's job title or team
- Incident report
Context
Incident reports sent by staff of Oakmere Homes, a housing association in England, through the internal incident form or the incident mailbox: an email or letter sent to the wrong person, a lost laptop or phone, a shared link left open, a suspicious login, a supplier telling us about an incident at their end. Each report is read so that the ones that may be personal data breaches reach the privacy team straight away, at any hour, and IT faults with no personal data go to IT. Rules we follow (UK GDPR): - A personal data breach is a breach of security that leads to personal data being lost, destroyed, changed, disclosed or accessed without authority, by accident or unlawfully. - A breach must be reported to the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of us becoming aware of it, unless it is unlikely to put people's rights and freedoms at risk. When the risk to people is likely to be high, they must be told too. Whether a breach is notifiable is a judgment for the privacy team. These answers only sort and prioritise the reports. Code records when the report arrived, runs the 72-hour clock and reads any number of people the report states. Nothing here judges the member of staff who made the report.
Questions
Does the incident report say what happened, what data was involved and who received it or could see it? Yes / No
Read the report. Yes: The report says what happened, what kind of data or device was involved, and who received it or could have accessed it, or that nobody could. No: The report leaves out at least one of these, so the privacy team would have to ask the reporter before judging it.
What kind of incident does the report describe? Choice
Read the report. Choose the option that describes how the incident happened. If more than one fits, choose the first cause.
Does the incident involve information about identifiable people? Yes / No
Read the report. Count names, contact details, account or tenancy records, case notes, photos, recordings, and any file or device the report says held details about customers, tenants, staff or others. Yes: The incident involves details about people who could be identified. No: The incident involves no information about identifiable people, such as a broken printer or a company-only price list.
Does the incident involve health, children's, financial account, government ID or password data, or other sensitive data? Yes / No
Read the report. Count health or disability information, data about children, ethnic origin, religion, sexual life or orientation, criminal records, bank or card details, National Insurance, passport or other ID numbers, and passwords or security answers. Yes: The report says at least one of these was involved. No: The report mentions none of these. Names, addresses and contact details on their own do not count.
Did the data reach, or could it have reached, someone outside the organisation? Yes / No
Read the report. Count a wrong recipient outside the organisation, a device lost in a public place, a public link, and outside access to a system. Yes: The data reached, or could have reached, someone outside the organisation. No: The data stayed inside the organisation, such as an email sent to the wrong colleague, or nothing left at all.
Does the report say the data was recovered or the exposure was closed? Yes / No
Read the report. Count a recipient who confirmed deletion, a link removed, a device found or wiped remotely, or a password reset on a compromised account. Asking for deletion with no reply yet does not count. Yes: The report says the data was recovered or the exposure was closed. No: The report says nothing of the kind, or says the exposure is still open or unconfirmed.
Does the report say whether the data or device was encrypted or password protected? Choice
Read the report. A negative statement, such as "it was not password protected", counts as saying the data was not protected.
Roughly how many people does the report suggest the data is about? Choice
Read the report. Give a rough band only; code reads any number the report states.
How soon should the privacy team read this incident report? Scale
Read the whole report and judge the risk to the people whose data is involved. This sets the order of the queue; it is not a decision on whether the breach is notifiable.
Lens columns
enough_detail, enough_detail_probability, incident_type, incident_type_probability, personal_data_involved, personal_data_involved_probability, sensitive_data_involved, sensitive_data_involved_probability, left_the_organisation, left_the_organisation_probability, contained, contained_probability, encryption, encryption_probability, people_affected, people_affected_probability, review_priority, review_priority_average
Run it on your own text
Add this prism in the app, change any question, and test it on a file of your own.