Note: If find suspicious or anything weird- report to [email protected] or raise a ticket here
Purpose
To outline the process for notifying affected individuals of a breach of sensitive information.
Scope
This applies to all employees, volunteers, and other individuals working under contractual agreements with Flink.
Definitions
State Breach ā Unauthorized acquisition or reasonable belief of unauthorized acquisition of Personal Information that compromises the security, confidentiality, or integrity of the Personal Information.
Personal Information ā Personal Information has many definitions including definitions by statute which may vary from state to state. Most generally, Personal Information is a combination of data elements which could uniquely identify an individual. Please review applicable state data breach statutes to determine what definition of Personal Information is applicable for purposes of the document.
Personal Data Breach ā Unauthorized acquisition, access, use, or disclosure of unsecured PII.
Personally Identifiable Information (PII) ā Information in any form that consists of a combination of an individualās name and one or more of the following: email address, Social Security Number, driverās license or state ID, account numbers, credit card numbers, debit card numbers, personal code, security code, password, personal ID number, photograph, fingerprint, or other information which could be used to identify an individual.
GDPR Breach ā Unauthorized acquisition or reasonable belief of unauthorized acquisition of personal information protected by GDPR. This information includes, but is not limited to, government issued ID numbers, financial account numbers or other information posing a risk of identity theft.
Private Information ā Information protected by GDPR, Personally Identifiable Information, Personal Information and Protected Information collectively.
Procedure
Reporting a Possible Breach
Any employee who becomes aware of a possible breach of privacy involving Private Information in the custody or control of Flink will immediately inform their supervisor/manager, and the ISO at [email protected] or or raise a ticket here .
āNotification should occur immediately upon discovery of a possible breach or before the end of your shift if other duties interfere, however, in no case should notification occur later than twenty-four (24) hours after discovery.
The supervisor/manager will verify the circumstances of the possible breach and inform the ISO within twenty-four (24) hours of the initial report.
You may contact the ISO directly..
Provide the ISO with as much detail as possible.
Be responsive to requests for additional information from the ISO.
Be aware that the ISO has an obligation to follow up on any reasonable belief that Private Information has been compromised.
The ISO, in conjunction with Flinkā Legal Counsel, will decide whether or not to notify the President/CEO as appropriate by taking into consideration the seriousness and scope of the breach.
Containing the Breach
The ISO will take the following steps to limit the scope and effect of the breach.
Work with the department(s) to immediately contain the breach. Examples include, but are not limited to:
Stopping the unauthorized practice
Recovering the records, if possible
Shutting down the system that was breached
Mitigating the breach, if possible
Correcting weaknesses in security practices
Notifying the appropriate authorities including the local Police Department if the breach involves, or may involve, any criminal activity
Investigating and Evaluating the Risks Associated with the Breach
To determine what other steps are immediately necessary, the ISO in collaboration with Flinkā Legal Counsel and affected department(s) and administration, will investigate the circumstances of the breach.
A team will review the results of the investigation to determine root cause(es), evaluate risks, and develop a resolution plan.
The Privacy Breach Assessment tool will help aid the investigation.
The ISO, in collaboration with Flinkā Legal Counsel, will consider several factors in determining whether to notify individuals affected by the breach including, but not limited to:
Contractual obligations
Legal obligations ā Flinkā Legal Counsel should complete a separate legal assessment of the potential breach and provide the results of the assessment to the ISO and the rest of the breach response team
Risk of identity theft or fraud because of the type of information lost such as social security number, banking information, identification numbers
Risk of physical harm if the loss puts an individual at risk of stalking or harassment
Number of individuals affected
Notification
The ISO will work with the department(s) involved, Flinkā Legal Counsel and appropriate leadership to decide the best approach for notification and to determine what may be required by law.
If required by law, notification of individuals affected by the breach will occur as soon as possible following the breach.
āAffected individuals must be notified without reasonable delay, but in no case later than sixty (60) calendar days after discovery, unless instructed otherwise by law enforcement or other applicable local laws.
Notices must be in plain language and include basic information, including:
What happened
Types of sensitive information involved
Steps individuals should take
Steps covered entity is taking
Contact Information
Notices should be sent by email. If insufficient or out-of-date contact information is available, then a substitute notice is required as specified below.
If law enforcement authorities have been contacted, those authorities will assist in determining whether notification may be delayed in order not to impede a criminal investigation.
The required elements of notification vary depending on the type of breach and which law is implicated. As a result, Flinkā ISO and Legal Counsel should work closely to draft any notification that is distributed.
Indirect notification such as website information, posted notices, media will generally occur only where direct notification could cause further harm, or contact information is lacking.
If a breach affects five-hundred (500) or more individuals, or contact information is insufficient, Flink will notify a prominent media outlet that is appropriate for the size of the location with affected individuals, and notice will be provided in the form of a press release.
Using multiple methods of notification in certain cases may be the most effective approach.
Business associates must notify Flink if they incur or discover a breach of unsecured PII.
Notices must be provided without reasonable delay and in no case later than sixty (60) days after discovery of the breach.
Business associates must cooperate with Flink in investigating and mitigating the breach.
Prevention
Once immediate steps are taken to mitigate the risks associated with the breach, the ISO will investigate the cause of the breach.
If necessary, this will include a security audit of physical, organizational, and technological measures.
This may also include a review of any mitigating steps taken.
The ISO will assist the responsible department to put into effect adequate safeguards against further breaches.
Procedures will be reviewed and updated to reflect the lessons learned from the investigation and regularly thereafter.
The resulting plan will also include audit recommendations, if appropriate.
Compliance and Enforcement
All managers and supervisors are responsible for enforcing these procedures. Flink takes security very seriously to protect our users, assets and data. Flink could take appropriate actions in case of violating the company policy.