The controller must report the data breach that occurred at the processor
Following a data breach at an electronic medical records system provider, the Polish data protection authority (UODO) reminds controllers of their notification obligations.
This communication follows media revelations about a personal data breach affecting nearly 19 million Poles at MyDr, a provider of Electronic Medical Documentation systems. The authority emphasizes that controllers using this processor must first obtain confirmation from the processor that the incident indeed concerns the data entrusted to them. They must then assess the risk to the rights and freedoms of natural persons to determine whether notification to the UODO is required, in accordance with Article 33 paragraph 1 of the GDPR, within 72 hours after becoming aware of the breach. If the breach is likely to result in a high risk, the controller must also promptly inform the data subjects, as provided by Article 34 of the GDPR. This notification must notably describe the nature of the breach, possible consequences such as the risk of identity theft or discrimination, and the measures taken or proposed to address it, such as recommending blocking a national identification number (PESEL) or seeking psychological support.
This communication follows media revelations about a personal data breach affecting nearly 19 million Poles at MyDr, a provider of Electronic Medical Documentation systems. The authority emphasizes that controllers using this processor must first obtain confirmation from the processor that the incident indeed concerns the data entrusted to them. They must then assess the risk to the rights and freedoms of natural persons to determine whether notification to the UODO is required, in accordance with Article 33 paragraph 1 of the GDPR, within 72 hours after becoming aware of the breach. If the breach is likely to result in a high risk, the controller must also promptly inform the data subjects, as provided by Article 34 of the GDPR. This notification must notably describe the nature of the breach, possible consequences such as the risk of identity theft or discrimination, and the measures taken or proposed to address it, such as recommending blocking a national identification number (PESEL) or seeking psychological support.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire