Skip to content

Lesson 7 of 8 · 9 min

Responding to an incident

Data entrusted by mistake, an unwanted action, a suspicious account: contain, understand, report.

An incident is not always spectacular. A colleague has uploaded a payroll file to the wrong project. An email went out with the wrong attachment. An unusual sign-in appears on an account. In every case, the same method applies: contain, understand, report.

  1. Remove access to the exposed content: move or delete the file, remove the extra members from the project.
  2. For a suspicious account, change the password and close its open sessions from the account’s sessions page.
  3. If a secret has been exposed, change it immediately.
  4. Alert the administrator and your data protection officer.

The audit log records administration and security events: sign-ins, changes to members, roles and settings. The “Activity” screen of the user concerned records the work: what each task produced, its effects and the approvals given. Together, they let you say what happened, when, and what may have gone out.

If the incident is a data security breach that is likely to result in a high risk to people, Article 24 of the revised FADP requires it to be reported to the FDPIC as soon as possible. The GDPR sets a deadline of 72 hours for notifying the supervisory authority, in Article 33. Your data protection officer decides on the notification, with the information you have gathered.

References

  1. Swiss Confederation (2020). Federal Act on Data Protection (FADP), SR 235.1. In force since 1 September 2023. www.fedlex.admin.ch/eli/cc/2022/491/fr
  2. European Parliament and Council of the European Union (2016). Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation). Official Journal of the European Union, L 119. data.europa.eu/eli/reg/2016/679/oj