What is a Personal Data Security Incident Response Plan?

Estimated reading time: 2 minutes

Summary

Did you know that 63% of small and medium-sized enterprises have already suffered some kind of data breach incident? This data comes from the 2019 Ponemon Institute's Global Data Security Study.

Now that companies are becoming increasingly digital and the General Data Protection Law (LGPD) is in effect, it is becoming ever more important to prevent these incidents and know what to do when they occur.

This is what the Personal Data Security Incident Response Plan is for. This document is also called an IRP, or Incident Response PlanIt should contain:

  • The definition of an incident for your company;
  • A description of the procedures to be followed when an incident occurs;
  • The tools, technologies, and resources to be used;
  • A description of the collaborators involved in the process and their responsibilities.

Start preparing your IRP (Income Tax Return).

 

To develop this plan, the role of the DPO/Data Protection Officer is crucial, as they are already familiar with privacy and cybersecurity issues within the company. This plan cannot be rigid; it must be adapted and updated whenever incidents occur and it is put into practice.

When creating the plan, it's necessary to define what constitutes an incident within the company and what risks the organization is facing. Knowing the volume of data processed by the institution and the risks involved is fundamental, and a good tool for... Data Mapping It helps in this process.

Next, it is necessary to appoint those responsible for responding when an incident occurs. They must have a good understanding of technology, cybersecurity, and data protection laws such as LGPD and GDPR.

The response steps must be well defined, both in the technological aspect with system backups, and in the legal aspect, to respond to cases of leaks or misuse of personal information before the ANPD (Brazilian National Data Protection Authority).

 

Gathering information on incident reporting

 

Between February and March of this year, the National Data Protection Authority (ANPD) conducted a survey on the notification of security incidents under Article 48 of the LGPD (Brazilian General Data Protection Law).

The goal was to contribute to the development of this regulation, the first draft of which will be subject to public consultation and hearing soon.

Public consultation is a method that allows for public participation during the preliminary phases of a regulatory process. It includes the collection of data, ideas, suggestions, and opinions on a given topic. The ANPD (National Data Protection Authority) can use this data as input for the study phases and the development of proposals for normative acts and regulations.

One example of a contribution to this gathering of information came from the Brazilian Internet Association (Abranet). The organization proposed that security incidents be divided into three levels, according to risk and potential for damage. It also suggested that some cases should be exempt from mandatory reporting, among other suggestions.

Even though the LGPD (Brazilian General Data Protection Law) is new to some companies and the ANPD (National Data Protection Authority) is still studying various issues related to data protection, your organization needs to be prepared.

Start working on a good Incident Response Plan and invest in good privacy management tools It is essential to avoid future problems and maintain the most transparent relationship with the public possible.

About the Author

Meet the author of this article.

Want to see how Privacy Tools can help your company in practice?

Request a personalized demonstration and see how our solutions adapt to your needs.

Related articles section

Read also