This form is used to document and assess any incidents involving personal data. It helps the Bank identify potential risks, take appropriate action, and ensure compliance with data protection requirements.
A personal data incident is any event that affects the security or handling of personal data. This could include accidental disclosure, loss, or unauthorized access to personal data including a cyber incident or personal data breach.
Example: An email containing a customer's personal details is accidentally sent to the wrong recipient. Even though this may have been an honest mistake and not a deliberate breach, it is still considered a personal data breach because personal data was exposed in a way that wasn't intended.
The Data Privacy Officer (DPO) is responsible for reviewing all completed Personal Data Incident Report Forms, assessing risks, and ensuring appropriate steps are taken. The DPO will also determine if notification to affected individuals or regulatory authorities is required.
Under the Barbados Data Protection Act 2019-29 (DPA), certain data breaches that pose a risk to individuals must be reported to the Data Protection Commissioner within the required timeframe. The information collected in this form will assist in determining if such a report is necessary.
Report the incident immediately using this form. If you're unsure about any details, provide as much information as possible.
You should contact the Data Privacy Officer (DPO) at inga.king@rfhl.com or ext. 4037 for guidance.
After you submit the form, the Data Privacy Officer (DPO) will review the incident to assess its impact and determine the next steps. Investigation: the DPO may gather more details. Reporting Obligations: if the incident meets legal requirements, the Bank may need to report it to the Data Protection Commissioner, other regulators, or the Board of Directors within the required timeframe. Mitigation Measures: steps may be taken to limit harm, such as securing accounts or notifying affected individuals. The Bank will handle each case based on its severity.
Emails sent to the wrong recipient: contact the recipient and request deletion; obtain confirmation of deletion; recall the email if possible; notify the DPO. Lost/stolen devices: remotely wipe or lock; change linked passwords; report to IT security and the DPO. Unauthorized access: reset passwords and enable MFA; delete the user profile; revoke access; conduct a security review. Physical documents lost: attempt retrieval if safe; inform the relevant department; secure remaining records.
Biometric Data: information about your unique physical or behavioural characteristics that can be used to identify you, such as fingerprints, facial features, or voice.
Containment: taking immediate steps to stop a personal data incident from getting worse, such as restricting access, recalling an email, or disabling a compromised account.
Cyber Incident: any event that disrupts or threatens the security of a computer system, network, or digital information (e.g. a hacker attempting to break in, or malware infecting a computer).
Data Subject: an individual whose personal data is collected, stored, or processed, for example customers, employees, or any other individuals whose data is held by the Bank.
Mitigation measures: steps taken to reduce harm after a personal data incident occurs, helping protect affected individuals, contain the incident, and reduce the likelihood of future occurrences.
Personal Data: any information that can identify a person on its own or when combined with other information, such as names, contact information, identification numbers, IP address, etc.
Personal Data Breach: when personal data is accidentally or unlawfully lost, destroyed, changed, shared without permission, or accessed by someone who shouldn't have it.
Personal Data Incident: any event that affects the security or handling of personal data, including accidental disclosure, loss, or unauthorized access, including a cyber incident or data breach.
Recovery: actions to fix the issue and prevent recurrence, which may include restoring lost data, strengthening security measures, or updating policies.
Sensitive Personal Data: personal data on a data subject's racial or ethnic origin; political opinions; religious or similar beliefs; membership of a political body; trade-union membership; genetic data; biometric data; sexual orientation or sexual life; financial record or position; criminal record; or proceedings for any offence. This is data that could significantly affect an individual's privacy if misused.
For any additional questions or concerns, please reach out to the Data Privacy Officer (DPO).
Footnotes / Notes for Completion. Section 1: provide your name, role, department, and contact details. Section 2: specify when the incident occurred and when it was discovered; indicate whether it happened on-site, remotely, or externally; describe clearly what happened. Section 3: list the categories of data affected, estimate the number of data subjects, and indicate whether sensitive personal data is involved. Section 4: explain potential risks, whether affected individuals were notified, and any mitigation measures taken. Section 5: describe containment and recovery actions. Section 6: indicate any external reporting. Section 8: sign and date the form before submission. If unsure how to contain or recover from an incident, contact the IT Security Team, Corporate Security Officer, or DPO.