Search

How can we help?

Icon

GDPR: the ICO attempts to clarify obligation to report serious data breaches

Faced with misleading press stories, the ICO has been addressing misconceptions about the GDPR by publishing myth busting blogs, including on the new requirement to report serious breaches of personal data.

Not all personal data breaches will need to be reported to the ICO, only if a risk to people’s rights and freedoms is likely.  The ICO does not give strict instructions of what incidents are serious enough to report but reiterates it is when people may suffer a significant detriment such as damage to reputation or financial loss. The ICO has encouraged all organisations to look at the types of incidents they could face to develop a sense of what would be serious.

Although the requirement to report a serious breach is without undue delay and where feasible within 72 hours, they don’t expect a full final report with all details within this time. The ICO have said that fines will be proportionate and will not be issued for every failure (although only time will tell what this will mean in practice). They remind firms that the point of the GDPR is not to punish organisations but to encourage companies to improve their ability to prevent breaches.

Under the current data protection law, reporting is best practice anyway even if not mandatory. Involving the ICO early can ensure the firm receives the best guidance and mitigate any fines issued.

Under the current data protection law, reporting is best practice anyway even if not mandatory. Involving the ICO early can ensure the firm receives the best guidance and mitigate any fines issued.

Organisations are encouraged to start planning now to ensure roles and processes are in place for when GDPR comes into effect in May 2018.

About this article

Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website

About this article

Read, listen and watch our latest insights

art
  • 19 September 2017
  • Construction

Modern slavery in construction supply chains: does your business comply

‘Modern Slavery’ is a term which encapsulates slavery, servitude, forced or compulsory labour, and human trafficking.

art
  • 15 September 2017
  • Employment

ACAS publishes guidance on supporting parents with ill or premature babies

ACAS has published guidance providing important information for both employees and employers in relation to premature births or full-term births where a child is ill.

art
  • 15 September 2017
  • Immigration

Establishing a business presence in the UK – the sole representative visa

Our immigration lawyers have recently seen an increase in enquiries from successful overseas business owners who wish to establish a business presence in the UK. Such individuals have explored the Tier 1 Entrepreneur visa route but either do not want to live in the UK or do not wish to make a large investment, such as the £200,000 required under the Entrepreneur route.

art
  • 12 September 2017
  • Corporate and M&A

CG Archive Acquisition Marks 30th for OASIS Group

Clarkslegal, led by corporate lawyers Jon Chapman and Esma Kilic, have advised OASIS Group on all of their UK acquisitions.

art
  • 12 September 2017
  • Employment

New requirements for companies to reveal pay ratio between bosses and workers

The government has announced a series of reforms aimed at increasing boardroom accountability and enhancing trust in business. These are a partial implementation of pledges in the Conservative manifesto for the May 2017 general election, which itself was much less alarming to businesses than Theresa May’s July 2016 Conservative party leadership campaign pledge to have employees represented on company boards.The proposals are that, on an annual basis around 900 listed companies will have to publish and justify the pay ratio between CEOs and their average UK worker

art
  • 11 September 2017
  • Commercial Real Estate

Does a commercial tenant in a commercial building have responsibility for fire safety?

The Grenfell Tower fire struck on 14 June 2017 in the 24-storey block of public housing flats in North Kensington, West London, causing at least 80 deaths and initiated a debate into fire safety and the rights and responsibilities of tenants and landlords. in relation to fire safety in premises, including in commercial, as well as residential, premises.