{"id":614,"date":"2018-06-20T22:52:18","date_gmt":"2018-06-20T21:52:18","guid":{"rendered":"https:\/\/sigbi.org\/bingley\/?page_id=614"},"modified":"2018-06-21T22:41:57","modified_gmt":"2018-06-21T21:41:57","slug":"si-bingleys-data-breach-policy","status":"publish","type":"page","link":"https:\/\/sigbi.org\/bingley\/gdpr\/si-bingleys-data-breach-policy\/","title":{"rendered":"SI Bingley Club&#8217;s Data Breach Policy"},"content":{"rendered":"<p>SOROPTIMIST INTERNATIONAL OF BINGLEY<br \/>\nCLUB\u2019S DATA BREACH POLICY<\/p>\n<p>For the purpose of this document, references to Soroptimist International Great Britain and Ireland (SIGBI) Limited and Soroptimist International may be written as \u201cSIGBI\u201d and \u201cSI\u201d only.<\/p>\n<p>Bingley Club Data Breach Policy<\/p>\n<p>Introduction<br \/>\nSI Bingley holds and processes personal data which needs to be protected. Every care is taken to protect the data we hold. Compromise of information, confidentiality, integrity or availability may result in harm to individuals, reputational damage, detrimental effect on service provision, legislative non-compliance and financial penalties.<\/p>\n<p>Purpose<br \/>\nThis policy sets out the procedure to be followed to ensure a consistent and effective approach throughout the organisation.<\/p>\n<p>Scope<br \/>\nThe policy relates to all personal data held by us, regardless of format. It applies to anyone who handles this personal data, including those working on our behalf. The objective of the policy is to contain any breaches, to minimise the risks associated with the breach and to consider what action is necessary to secure personal data and prevent any further breach.<\/p>\n<p>Types of breach<br \/>\nAn incident is an event or action which may compromise the confidentiality, integrity or availability of systems or data, either accidentally or deliberately, and has caused or has the potential to cause damage to data subjects\/members.<\/p>\n<p>An incident includes but is not restricted to:<br \/>\n\u2022 Loss or theft of personal data or the equipment on which the data is stored e.g. laptop, memory stick, smartphone, or paper record.<br \/>\n\u2022 Theft or failure of equipment on which personal data is stored<br \/>\n\u2022 Unauthorised use of or access to personal data<br \/>\n\u2022 Attempts to gain unauthorised access to personal data<br \/>\n\u2022 Unauthorised disclosure of personal data<br \/>\n\u2022 Website defacement<br \/>\n\u2022 Hacking attack<\/p>\n<p>Reporting an incident<br \/>\nAny person using personal data on behalf of the club is responsible for reporting data breach incidents immediately to the Executive and Development Committee, using the Data Breach Report Form set out below.<\/p>\n<p>The report should contain the following details:<br \/>\n\u2022 Date and time of discovery of breach.<br \/>\n\u2022 Details of person who discovered the breach.<br \/>\n\u2022 The nature of the personal data involved.<br \/>\n\u2022 How many data subjects\u2019\/members\u2019 data is affected.<\/p>\n<p>Containment and recovery<br \/>\nThe Executive and Development Committee will first ascertain if the breach is still occurring. If so, appropriate steps will be taken immediately to minimise the effects of the breach. An assessment will be carried out to establish the severity of the breach and the nature of further investigation required. Consideration will be given as to whether the police should be informed. Advice from appropriate experts will be sought if necessary. A suitable course of action will be taken to ensure a resolution to the breach.<\/p>\n<p>Investigation and risk assessment<br \/>\nAn investigation will be carried out without delay and where possible within 24 hours of the breach being discovered. The Executive and Development Committee will assess the risks associated with the breach, the potential consequences for the data subjects\/members, how serious and substantial those are and how likely they are to occur.<\/p>\n<p>The investigation will take into account the following:<br \/>\n\u2022 The type of data involved and its sensitivity.<br \/>\n\u2022 The protections in place (e.g. encryption).<br \/>\n\u2022 What has happened to the data.<br \/>\n\u2022 Whether the data could be put to illegal or inappropriate use.<br \/>\n\u2022 Who the data subjects\/members are, how many are involved, and the potential effects on them.<br \/>\n\u2022 Any wider consequences.<\/p>\n<p>Notification<br \/>\nThe Executive and Development Committee will decide with appropriate advice who needs to be notified of the breach. Every incident will be assessed on a case by case basis. Consideration will be given to notifying the Information Commissioner if a large number of people are affected or the consequences for the data subjects\/members are very serious. Guidance on when and how to notify the ICO is available on their website:<br \/>\nwww.ico.org.uk\/media\/1536\/breach_reporting.pdf<\/p>\n<p>Notification to the data subjects\/members whose personal data has been affected by the incident will include a description of how and when the breach occurred, and the nature of the data involved. Specific and clear advice will be given on what they can do to protect themselves and what has already been done to mitigate the risks. The Executive and Development Committee will keep a record of all actions taken in respect of the breach.<\/p>\n<p>Evaluation and response<br \/>\nOnce the incident is contained, the Executive and Development Committee will carry out a review of the causes of the breach, the effectiveness of the response, and whether any changes to systems, policies or procedures should be undertaken. Consideration will be given to whether any corrective action is necessary to minimise the risk of similar incidents occurring.<\/p>\n<p>See next page for a Data Breach Report.<\/p>\n<p>Data Breach Report<br \/>\nDate and Time of Discovery of Breach<br \/>\nName of Person Discovering Breach<br \/>\nNature of Personal Data Involved<\/p>\n<p>How Many Individuals\u2019 Data is affected<br \/>\nAssessment Carried Out By<br \/>\nWhat actions were taken?<\/p>\n<p>Further Investigation\/Advice required?<\/p>\n<p>Resolution<\/p>\n<p>Signed by: Date:<\/p>\n","protected":false},"excerpt":{"rendered":"<p>SOROPTIMIST INTERNATIONAL OF BINGLEY CLUB\u2019S DATA BREACH POLICY For the purpose of this document, references&#8230;<\/p>\n","protected":false},"author":552,"featured_media":0,"parent":606,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-614","page","type-page","status-publish","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>SI Bingley Club&#039;s Data Breach Policy | SI Bingley | SIGBI<\/title>\n<meta name=\"description\" content=\"SIGBI : SI Bingley : SI Bingley Club&#039;s Data Breach Policy : SI Bingley is part of a worldwide organisation of women, find more information regarding the SI Bingley Club&#039;s Data Breach Policy here.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/sigbi.org\/bingley\/gdpr\/si-bingleys-data-breach-policy\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SI Bingley Club&#039;s Data Breach Policy | SI Bingley | SIGBI\" \/>\n<meta property=\"og:description\" content=\"SIGBI : SI Bingley : SI Bingley Club&#039;s Data Breach Policy : SI Bingley is part of a worldwide organisation of women, find more information regarding the SI Bingley Club&#039;s Data Breach Policy here.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/sigbi.org\/bingley\/gdpr\/si-bingleys-data-breach-policy\/\" \/>\n<meta property=\"og:site_name\" content=\"SI Bingley\" \/>\n<meta property=\"article:modified_time\" content=\"2018-06-21T21:41:57+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/sigbi.org\/bingley\/gdpr\/si-bingleys-data-breach-policy\/\",\"url\":\"https:\/\/sigbi.org\/bingley\/gdpr\/si-bingleys-data-breach-policy\/\",\"name\":\"SI Bingley Club's Data Breach Policy | SI Bingley | SIGBI\",\"isPartOf\":{\"@id\":\"https:\/\/sigbi.org\/bingley\/#website\"},\"datePublished\":\"2018-06-20T21:52:18+00:00\",\"dateModified\":\"2018-06-21T21:41:57+00:00\",\"description\":\"SIGBI : SI Bingley : SI Bingley Club's Data Breach Policy : SI Bingley is part of a worldwide organisation of women, find more information regarding the SI Bingley Club's Data Breach Policy here.\",\"breadcrumb\":{\"@id\":\"https:\/\/sigbi.org\/bingley\/gdpr\/si-bingleys-data-breach-policy\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/sigbi.org\/bingley\/gdpr\/si-bingleys-data-breach-policy\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/sigbi.org\/bingley\/gdpr\/si-bingleys-data-breach-policy\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/sigbi.org\/bingley\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"GDPR\",\"item\":\"https:\/\/sigbi.org\/bingley\/gdpr\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"SI Bingley Club&#8217;s Data Breach Policy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/sigbi.org\/bingley\/#website\",\"url\":\"https:\/\/sigbi.org\/bingley\/\",\"name\":\"SI Bingley\",\"description\":\"A Soroptimist International of Great Britain and Ireland Club website\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/sigbi.org\/bingley\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"SI Bingley Club's Data Breach Policy | SI Bingley | SIGBI","description":"SIGBI : SI Bingley : SI Bingley Club's Data Breach Policy : SI Bingley is part of a worldwide organisation of women, find more information regarding the SI Bingley Club's Data Breach Policy here.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/sigbi.org\/bingley\/gdpr\/si-bingleys-data-breach-policy\/","og_locale":"en_US","og_type":"article","og_title":"SI Bingley Club's Data Breach Policy | SI Bingley | SIGBI","og_description":"SIGBI : SI Bingley : SI Bingley Club's Data Breach Policy : SI Bingley is part of a worldwide organisation of women, find more information regarding the SI Bingley Club's Data Breach Policy here.","og_url":"https:\/\/sigbi.org\/bingley\/gdpr\/si-bingleys-data-breach-policy\/","og_site_name":"SI Bingley","article_modified_time":"2018-06-21T21:41:57+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/sigbi.org\/bingley\/gdpr\/si-bingleys-data-breach-policy\/","url":"https:\/\/sigbi.org\/bingley\/gdpr\/si-bingleys-data-breach-policy\/","name":"SI Bingley Club's Data Breach Policy | SI Bingley | SIGBI","isPartOf":{"@id":"https:\/\/sigbi.org\/bingley\/#website"},"datePublished":"2018-06-20T21:52:18+00:00","dateModified":"2018-06-21T21:41:57+00:00","description":"SIGBI : SI Bingley : SI Bingley Club's Data Breach Policy : SI Bingley is part of a worldwide organisation of women, find more information regarding the SI Bingley Club's Data Breach Policy here.","breadcrumb":{"@id":"https:\/\/sigbi.org\/bingley\/gdpr\/si-bingleys-data-breach-policy\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/sigbi.org\/bingley\/gdpr\/si-bingleys-data-breach-policy\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/sigbi.org\/bingley\/gdpr\/si-bingleys-data-breach-policy\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/sigbi.org\/bingley\/"},{"@type":"ListItem","position":2,"name":"GDPR","item":"https:\/\/sigbi.org\/bingley\/gdpr\/"},{"@type":"ListItem","position":3,"name":"SI Bingley Club&#8217;s Data Breach Policy"}]},{"@type":"WebSite","@id":"https:\/\/sigbi.org\/bingley\/#website","url":"https:\/\/sigbi.org\/bingley\/","name":"SI Bingley","description":"A Soroptimist International of Great Britain and Ireland Club website","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/sigbi.org\/bingley\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/sigbi.org\/bingley\/wp-json\/wp\/v2\/pages\/614","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sigbi.org\/bingley\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/sigbi.org\/bingley\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/sigbi.org\/bingley\/wp-json\/wp\/v2\/users\/552"}],"replies":[{"embeddable":true,"href":"https:\/\/sigbi.org\/bingley\/wp-json\/wp\/v2\/comments?post=614"}],"version-history":[{"count":4,"href":"https:\/\/sigbi.org\/bingley\/wp-json\/wp\/v2\/pages\/614\/revisions"}],"predecessor-version":[{"id":634,"href":"https:\/\/sigbi.org\/bingley\/wp-json\/wp\/v2\/pages\/614\/revisions\/634"}],"up":[{"embeddable":true,"href":"https:\/\/sigbi.org\/bingley\/wp-json\/wp\/v2\/pages\/606"}],"wp:attachment":[{"href":"https:\/\/sigbi.org\/bingley\/wp-json\/wp\/v2\/media?parent=614"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}