Republic Bank (Barbados) Limited
Republic Bank
Placeholder logo. Swap for the official Republic Bank asset before final release.
PERSONAL DATA INCIDENT REPORT FORM

Purpose of the Personal Data Incident Report Form

This form is used to document and assess any incidents involving personal data. It helps the Bank identify potential risks, take appropriate action, and ensure compliance with data protection requirements.

A personal data incident is any event that affects the security or handling of personal data. This could include accidental disclosure, loss, or unauthorized access to personal data including a cyber incident or personal data breach.

Example: An email containing a customer's personal details is accidentally sent to the wrong recipient. Even though this may have been an honest mistake and not a deliberate breach, it is still considered a personal data breach because personal data was exposed in a way that wasn't intended.

Reporting to the Role of the Data Privacy Officer (DPO)

The Data Privacy Officer (DPO) is responsible for reviewing all completed Personal Data Incident Report Forms, assessing risks, and ensuring appropriate steps are taken. The DPO will also determine if notification to affected individuals or regulatory authorities is required.

Reporting to the Data Protection Commissioner

Under the Barbados Data Protection Act 2019-29 (DPA), certain data breaches that pose a risk to individuals must be reported to the Data Protection Commissioner within the required timeframe. The information collected in this form will assist in determining if such a report is necessary.

Important Information Before You Start

  • Notes for Completion are found in the footnotes. Key Definitions and Frequently Asked Questions (FAQs) can be found at Section 9.
  • Be Clear & Factual: Provide as much detail as you can. If exact numbers aren't available, estimates are acceptable.
  • Need Help? If you have any questions or need assistance while completing this form, please contact the DPO at inga.king@rfhl.com or ext. 4037 for guidance.
  • Next Steps: Once you submit this form, the DPO will review your report and may contact you if further information is needed.
Section 1: Reporting Individual
Name *
Position / Role *
Department *
Contact Information *
Section 2: Incident Details
5 Date & Time of Incident * Date required (yyyy/mm/dd). Time optional.
6 Date Incident was Discovered *
7 Location of Incident * Branch and Department where the incident occurred
8 Description of Incident * What happened? How was it discovered?
Section 3: Data Involved
9 Categories of Personal Data Affected * e.g. names, contact information, ID numbers. Provide relevant details of each category.
10 Number of Data Subjects Affected * If known
11 Does the incident involve Sensitive Personal Data? *
If yes, select all that apply:
Section 4: Incident Impact
12 Potential risks to individuals * Select all that apply
13 Have affected individual(s) been notified? *
If yes, select the method(s) of notification (select all that apply):
14 Mitigation measures taken *
Section 5: Containment and Recovery
15 Has the incident been contained? *
16 Steps taken to recover affected data or systems
Section 6: Notification Requirements
17 Has the incident been reported to other departments or external bodies? * e.g. law enforcement, IT Security Team, Enterprise Risk
If yes, select all that apply:
Section 7: Additional Information
18 Any other relevant details or documents? (Attach files if necessary)
Attached files are listed on the printed PDF for reference. Remember to attach the actual files to your email.
Section 8: Authorization
19 Submitted By *
Signature:
Draw, type, or import a signature image here. To use your saved Adobe signature (Fill & Sign or Digital ID), leave this blank, save the form as a PDF, and sign that PDF in Adobe Acrobat or Reader. Imported signature
20 Reviewed & Approved By (Supervisor / Manager)
Signature:
Draw, type, or import a signature image here. To use your saved Adobe signature (Fill & Sign or Digital ID), leave this blank, save the form as a PDF, and sign that PDF in Adobe Acrobat or Reader. Imported signature
Section 9: Frequently Asked Questions & Key Definitions

1. What should I do if I suspect a personal data incident?

Report the incident immediately using this form. If you're unsure about any details, provide as much information as possible.

2. Who can I contact if I need help completing the form?

You should contact the Data Privacy Officer (DPO) at inga.king@rfhl.com or ext. 4037 for guidance.

3. What happens after I submit this form?

After you submit the form, the Data Privacy Officer (DPO) will review the incident to assess its impact and determine the next steps. Investigation: the DPO may gather more details. Reporting Obligations: if the incident meets legal requirements, the Bank may need to report it to the Data Protection Commissioner, other regulators, or the Board of Directors within the required timeframe. Mitigation Measures: steps may be taken to limit harm, such as securing accounts or notifying affected individuals. The Bank will handle each case based on its severity.

4. What are some examples of mitigation measures?

Emails sent to the wrong recipient: contact the recipient and request deletion; obtain confirmation of deletion; recall the email if possible; notify the DPO. Lost/stolen devices: remotely wipe or lock; change linked passwords; report to IT security and the DPO. Unauthorized access: reset passwords and enable MFA; delete the user profile; revoke access; conduct a security review. Physical documents lost: attempt retrieval if safe; inform the relevant department; secure remaining records.

Key Definitions

Biometric Data: information about your unique physical or behavioural characteristics that can be used to identify you, such as fingerprints, facial features, or voice.

Containment: taking immediate steps to stop a personal data incident from getting worse, such as restricting access, recalling an email, or disabling a compromised account.

Cyber Incident: any event that disrupts or threatens the security of a computer system, network, or digital information (e.g. a hacker attempting to break in, or malware infecting a computer).

Data Subject: an individual whose personal data is collected, stored, or processed, for example customers, employees, or any other individuals whose data is held by the Bank.

Mitigation measures: steps taken to reduce harm after a personal data incident occurs, helping protect affected individuals, contain the incident, and reduce the likelihood of future occurrences.

Personal Data: any information that can identify a person on its own or when combined with other information, such as names, contact information, identification numbers, IP address, etc.

Personal Data Breach: when personal data is accidentally or unlawfully lost, destroyed, changed, shared without permission, or accessed by someone who shouldn't have it.

Personal Data Incident: any event that affects the security or handling of personal data, including accidental disclosure, loss, or unauthorized access, including a cyber incident or data breach.

Recovery: actions to fix the issue and prevent recurrence, which may include restoring lost data, strengthening security measures, or updating policies.

Sensitive Personal Data: personal data on a data subject's racial or ethnic origin; political opinions; religious or similar beliefs; membership of a political body; trade-union membership; genetic data; biometric data; sexual orientation or sexual life; financial record or position; criminal record; or proceedings for any offence. This is data that could significantly affect an individual's privacy if misused.

For any additional questions or concerns, please reach out to the Data Privacy Officer (DPO).

Official Use Only

Comments (DPO)
Reviewed By (DPO): Name
Date

Footnotes / Notes for Completion. Section 1: provide your name, role, department, and contact details. Section 2: specify when the incident occurred and when it was discovered; indicate whether it happened on-site, remotely, or externally; describe clearly what happened. Section 3: list the categories of data affected, estimate the number of data subjects, and indicate whether sensitive personal data is involved. Section 4: explain potential risks, whether affected individuals were notified, and any mitigation measures taken. Section 5: describe containment and recovery actions. Section 6: indicate any external reporting. Section 8: sign and date the form before submission. If unsure how to contain or recover from an incident, contact the IT Security Team, Corporate Security Officer, or DPO.

STAGING PREVIEW Complete all required fields (*), then use Print / Save as PDF and email the saved PDF securely to the DPO. This form does not transmit data. Nothing leaves your device until you email the PDF.