<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Data Protection Commission Archives - L2 Cyber Security Solutions Ltd.</title>
	<atom:link href="https://www.l2cybersecurity.com/tag/data-protection-commission/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.l2cybersecurity.com/tag/data-protection-commission/</link>
	<description>#SecuritySimplified</description>
	<lastBuildDate>Wed, 24 Jan 2024 16:22:24 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.l2cybersecurity.com/wp-content/uploads/2023/03/cropped-Logo-Only-Favicon-Transparent-32x32.png</url>
	<title>Data Protection Commission Archives - L2 Cyber Security Solutions Ltd.</title>
	<link>https://www.l2cybersecurity.com/tag/data-protection-commission/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>#WeekendWisdom 068 A Data Breach of Bank Details</title>
		<link>https://www.l2cybersecurity.com/weekendwisdom-068-a-data-breach-of-bank-details/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Fri, 05 Mar 2021 02:00:57 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[#SecuritySimplified]]></category>
		<category><![CDATA[#WeekendWisdom]]></category>
		<category><![CDATA[Bank Details]]></category>
		<category><![CDATA[Clare]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Data Breach of Bank Details]]></category>
		<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Data Protection Commission]]></category>
		<category><![CDATA[Data Protection Commission Report 2020]]></category>
		<category><![CDATA[DPC]]></category>
		<category><![CDATA[Limerick]]></category>
		<category><![CDATA[Tipperary]]></category>
		<category><![CDATA[Whatsapp]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=2467</guid>

					<description><![CDATA[<p>Welcome to #WeekendWisdom number 68. This week we&#8217;re going to talk about a data breach of bank details. Where is this coming from? As I said last week, the Data Protection Commission had issued a report for 2020. I&#8217;ve had a chance to read through it now in a bit more detail. I really love&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/weekendwisdom-068-a-data-breach-of-bank-details/">#WeekendWisdom 068 A Data Breach of Bank Details</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Welcome to #WeekendWisdom number 68. This week we&#8217;re going to talk about a data breach of bank details.<span id="more-2467"></span></p>
<div style="width: 1920px;" class="wp-video"><video class="wp-video-shortcode" id="video-2467-1" width="1920" height="1080" preload="metadata" controls="controls"><source type="video/mp4" src="https://www.l2cybersecurity.com/wp-content/uploads/2021/03/WeekendWisdom-068-lo.mp4?_=1" /><a href="https://www.l2cybersecurity.com/wp-content/uploads/2021/03/WeekendWisdom-068-lo.mp4">https://www.l2cybersecurity.com/wp-content/uploads/2021/03/WeekendWisdom-068-lo.mp4</a></video></div>
<h3>Where is this coming from?</h3>
<p>As I said last week, the Data Protection Commission had issued a report for 2020. I&#8217;ve had a chance to read through it now in a bit more detail. I really love looking at the case studies that they include there because these are real life events that have occurred.</p>
<p>One of them struck me as something that could occur anywhere.</p>
<h3>What? A data breach of bank details??? That&#8217;s serious!</h3>
<p>It was Case Study 15: Bank details sent by WhatsApp. What had occurred was that a customer of a financial institution had gotten in contact with them wanting to get a copy of their BIC and IBAN details. The member of staff that was dealing with the enquiry knew this person. So, because of that, they took a picture of the details on their personal phone and sent them by WhatsApp to the customer.</p>
<h3>WhatsApp is encrypted, so it must be safe. Right?</h3>
<p>But it turns out the details that they took the photo of were for somebody else. So, when the customer reported this incident to the bank, they realised this was a data breach. That customer had seen somebody else&#8217;s personal details.</p>
<h3>How does a business prevent this type of issue?</h3>
<p>This is simply a staff training issue. Staff need to be aware that they should always follow proper protocols when dealing with people&#8217;s personal details. To make sure that they provide the correct details to the correct person.</p>
<p>As I say it could happen to anybody. So use that example with your staff today.</p>
<p>So that’s it for this week. Lets be careful out there and we’ll talk to you again next week.</p>
<hr />
<h2>How can L2 Cyber Security help you?</h2>
<p>We offer a full range of <a href="https://www.l2cybersecurity.com/training" target="_blank" rel="noopener noreferrer">training programmes</a>, which can be delivered online or in-person<strong>*</strong>.</p>
<p>L2 Cyber Security are also a partner of <a href="https://www.cyberriskaware.com/" target="_blank" rel="noopener noreferrer">CyberRiskAware</a> for online self-directed Cyber Security Awareness training and Phishing testing.</p>
<p>Contact us for more information at <a href="mailto:info@L2CyberSecurity.com" target="_blank" rel="noopener noreferrer">info@L2CyberSecurity.com</a>.</p>
<p><strong>*</strong>With appropriate social distancing and other health and safety measures adhered to.</p>
<hr />
<h2>Follow us on Social media:</h2>
<p>Liam is available on <a href="https://twitter.com/L2actual" target="_blank" rel="noopener noreferrer">Twitter</a>, <a href="https://www.linkedin.com/in/lynchliam/" target="_blank" rel="noopener noreferrer">LinkedIn</a> and <a href="https://www.instagram.com/l2actual/" target="_blank" rel="noopener noreferrer">Instagram</a>.</p>
<p>Follow L2 Cyber on <a href="https://twitter.com/L2Cyber" target="_blank" rel="noopener noreferrer">Twitter</a>, <a href="https://www.linkedin.com/company/l2cyber/" target="_blank" rel="noopener noreferrer">LinkedIn</a>, <a href="https://www.instagram.com/l2cyber/" target="_blank" rel="noopener noreferrer">Instagram</a> and <a href="https://www.facebook.com/L2Cyber/" target="_blank" rel="noopener noreferrer">Facebook</a>.</p>
<p><a href="https://www.l2cybersecurity.com/" target="_blank" rel="noopener noreferrer">© L2 Cyber Security Solutions</a></p>
<p>The post <a href="https://www.l2cybersecurity.com/weekendwisdom-068-a-data-breach-of-bank-details/">#WeekendWisdom 068 A Data Breach of Bank Details</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		<enclosure url="https://www.l2cybersecurity.com/wp-content/uploads/2021/03/WeekendWisdom-068-lo.mp4" length="31885243" type="video/mp4" />

			</item>
		<item>
		<title>#WeekendWisdom 067 Data Protection Commission Report 2020</title>
		<link>https://www.l2cybersecurity.com/weekendwisdom-067-data-protection-commission-report-2020/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Fri, 26 Feb 2021 02:15:40 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[#SecuritySimplified]]></category>
		<category><![CDATA[#WeekendWisdom]]></category>
		<category><![CDATA[Clare]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Data Protection Commission]]></category>
		<category><![CDATA[Data Protection Commission Report 2020]]></category>
		<category><![CDATA[DPC]]></category>
		<category><![CDATA[GDPR Complaints]]></category>
		<category><![CDATA[Limerick]]></category>
		<category><![CDATA[Tipperary]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=2462</guid>

					<description><![CDATA[<p>Welcome to #WeekendWisdom number 67. This week we&#8217;re going to talk about Data Protection Commission Report 2020. Yesterday the Data Protection Commission (DPC) in Ireland released their annual report for 2020 and I&#8217;ll just give a quick summary of its findings here. What is the number 1 complaint that the DPC get? The number one&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/weekendwisdom-067-data-protection-commission-report-2020/">#WeekendWisdom 067 Data Protection Commission Report 2020</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Welcome to #WeekendWisdom number 67. This week we&#8217;re going to talk about Data Protection Commission Report 2020.<span id="more-2462"></span></p>
<div style="width: 1920px;" class="wp-video"><video class="wp-video-shortcode" id="video-2462-2" width="1920" height="1080" preload="metadata" controls="controls"><source type="video/mp4" src="https://www.l2cybersecurity.com/wp-content/uploads/2021/02/WeekendWisdom-067-lo.mp4?_=2" /><a href="https://www.l2cybersecurity.com/wp-content/uploads/2021/02/WeekendWisdom-067-lo.mp4">https://www.l2cybersecurity.com/wp-content/uploads/2021/02/WeekendWisdom-067-lo.mp4</a></video></div>
<p>Yesterday the Data Protection Commission (DPC) in Ireland released their annual report for 2020 and I&#8217;ll just give a quick summary of its findings here.</p>
<h3>What is the number 1 complaint that the DPC get?</h3>
<p>The number one source of complaints for the third year in a row under the GDPR remains access requests. So, businesses out there are still having trouble giving people access to their data that they&#8217;re entitled to.</p>
<p>I always focus in the training to make sure that people get their access rights done properly. They have proper procedures in place to handle these requests from individuals.</p>
<h3>Any figures for Data Breaches?</h3>
<p>Over in regard to data breaches. The number of those reported to the Data Protection Commission has increased again by about 8% overall.</p>
<p>But the number one source of data breaches was unauthorised disclosures of personal data, which was up 12.5% over last year, to nearly 6,000 breaches, which is really, really significant.</p>
<p>Data Breaches caused by hacking were up about 40% and Ransomware incidents also doubled over last year. So, things are going the wrong way.</p>
<h3>Is there any good news in the Data Protection Commission Report 2020?</h3>
<p>Just to finish on a happy note. I was delighted to see that data breaches in regard to phishing have halved over last year. So that must mean people are getting really good training out there on how to spot dodgy emails.</p>
<p>So that’s it for this week. Lets be careful out there and we’ll talk to you again next week.</p>
<hr />
<h2>How can L2 Cyber Security help you?</h2>
<p>We offer a full range of <a href="https://www.l2cybersecurity.com/training" target="_blank" rel="noopener noreferrer">training programmes</a>, which can be delivered online or in-person<strong>*</strong>.</p>
<p>L2 Cyber Security are also a partner of <a href="https://www.cyberriskaware.com/" target="_blank" rel="noopener noreferrer">CyberRiskAware</a> for online self-directed Cyber Security Awareness training and Phishing testing.</p>
<p>Contact us for more information at <a href="mailto:info@L2CyberSecurity.com" target="_blank" rel="noopener noreferrer">info@L2CyberSecurity.com</a>.</p>
<p><strong>*</strong>With appropriate social distancing and other health and safety measures adhered to.</p>
<hr />
<h2>Follow us on Social media:</h2>
<p>Liam is available on <a href="https://twitter.com/L2actual" target="_blank" rel="noopener noreferrer">Twitter</a>, <a href="https://www.linkedin.com/in/lynchliam/" target="_blank" rel="noopener noreferrer">LinkedIn</a> and <a href="https://www.instagram.com/l2actual/" target="_blank" rel="noopener noreferrer">Instagram</a>.</p>
<p>Follow L2 Cyber on <a href="https://twitter.com/L2Cyber" target="_blank" rel="noopener noreferrer">Twitter</a>, <a href="https://www.linkedin.com/company/l2cyber/" target="_blank" rel="noopener noreferrer">LinkedIn</a>, <a href="https://www.instagram.com/l2cyber/" target="_blank" rel="noopener noreferrer">Instagram</a> and <a href="https://www.facebook.com/L2Cyber/" target="_blank" rel="noopener noreferrer">Facebook</a>.</p>
<p><a href="https://www.l2cybersecurity.com/" target="_blank" rel="noopener noreferrer">© L2 Cyber Security Solutions</a></p>
<p>The post <a href="https://www.l2cybersecurity.com/weekendwisdom-067-data-protection-commission-report-2020/">#WeekendWisdom 067 Data Protection Commission Report 2020</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		<enclosure url="https://www.l2cybersecurity.com/wp-content/uploads/2021/02/WeekendWisdom-067-lo.mp4" length="31011550" type="video/mp4" />

			</item>
		<item>
		<title>#WeekendWisdom 034 Ransomware Case Study</title>
		<link>https://www.l2cybersecurity.com/weekendwisdom-034-ransomware-case-study/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Thu, 25 Jun 2020 23:15:33 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[#SecuritySimplified]]></category>
		<category><![CDATA[#WeekendWisdom]]></category>
		<category><![CDATA[Clare]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Data Protection Commission]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[GDPR Report]]></category>
		<category><![CDATA[Limerick]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[Ransomware Case Study]]></category>
		<category><![CDATA[Ransomware Incident]]></category>
		<category><![CDATA[Tipperary]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=2166</guid>

					<description><![CDATA[<p>Welcome to #WeekendWisdom number 34. This week we&#8217;re going to talk about a ransomware case study. Where did this ransomware case study come from? Earlier this week the data protection commission issued a report on the first two years of the GDPR and their regulatory activity within it. It is quite an interesting report for&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/weekendwisdom-034-ransomware-case-study/">#WeekendWisdom 034 Ransomware Case Study</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Welcome to #WeekendWisdom number 34. This week we&#8217;re going to talk about a ransomware case study.<span id="more-2166"></span></p>
<div style="width: 1280px;" class="wp-video"><video class="wp-video-shortcode" id="video-2166-3" width="1280" height="720" preload="metadata" controls="controls"><source type="video/mp4" src="https://www.l2cybersecurity.com/wp-content/uploads/2020/06/WeekendWisdom-034-lo.mp4?_=3" /><a href="https://www.l2cybersecurity.com/wp-content/uploads/2020/06/WeekendWisdom-034-lo.mp4">https://www.l2cybersecurity.com/wp-content/uploads/2020/06/WeekendWisdom-034-lo.mp4</a></video></div>
<h3>Where did this ransomware case study come from?</h3>
<p>Earlier this week the <a href="https://www.dataprotection.ie/" target="_blank" rel="noopener noreferrer">data protection commission</a> issued <a href="https://www.dataprotection.ie/sites/default/files/uploads/2020-06/DPC%20Ireland%202018-2020%20Regulatory%20Activity%20Under%20GDPR.pdf" target="_blank" rel="noopener noreferrer">a report</a> on the first two years of the GDPR and their regulatory activity within it.</p>
<p>It is quite an interesting report for privacy professionals and I read through it with a great deal of interest. And I came across a case study about a ransomware incident that a sports and leisure company had suffered. It was interesting in that data protection commission had gone back to the company after being told about the breach and they asked for quite a detailed list of items from that company. You can see this list here.</p>
<h3>What did the Data Protection Commission want to know?</h3>
<p>So you can see that they wanted to know:</p>
<ul>
<li>The chronology of the events that led up to the incident.</li>
<li>They wanted a description of the hardware and software that the company used.</li>
<li>What was the source and the attack vector of that ransomware</li>
<li>What was the variant</li>
<li>Was there some audit logs</li>
<li>What was the demand notice for the ransomware</li>
<li>Very important of course, whether there were backups available to recover from and</li>
<li>finally what types of measures that company have put in place to try and prevent this from occurring in the first place</li>
</ul>
<h3>That seems like a lot for a ransomware incident.</h3>
<p>That&#8217;s quite a detailed list of items and if you couldn&#8217;t answer those questions right now in your business, then you need some help. You need to have things like:</p>
<ul>
<li>A data breach handling procedure</li>
<li>Need to have a asset registers for your hardware and software</li>
<li>Your security setup and</li>
<li>Your backups</li>
</ul>
<p>All of these things you need to have those put in place in case this ever happens to you. So feel free to reach out if you need any assistance or advice on that.</p>
<p>So that’s it for this week. Let’s be careful out there and we’ll talk to you again next week.</p>
<hr />
<h2>How can L2 Cyber Security help you?</h2>
<p>We offer a full range of <a href="https://www.l2cybersecurity.com/training" target="_blank" rel="noopener noreferrer">training programmes</a>, which can be delivered online or in-person<strong>*</strong>.</p>
<p>L2 Cyber Security are also a partner of <a href="https://www.cyberriskaware.com/" target="_blank" rel="noopener noreferrer">CyberRiskAware</a> for online self-directed Cyber Security Awareness training.</p>
<p>We can also provide assistance on implementing mitigation measures to help protect your business from #Ransomware.</p>
<p>Contact us for more information at <a href="mailto:info@L2CyberSecurity.com" target="_blank" rel="noopener noreferrer">info@L2CyberSecurity.com</a>.</p>
<p><strong>*</strong>With appropriate social distancing and other health and safety measures adhered to.</p>
<hr />
<h2>Follow us on Social media:</h2>
<p>Liam is available on <a href="https://twitter.com/L2_Evangelist" target="_blank" rel="noopener noreferrer">Twitter</a>, <a href="https://www.linkedin.com/in/lynchliam/" target="_blank" rel="noopener noreferrer">LinkedIn</a> and <a href="https://www.instagram.com/l2_evangelist/" target="_blank" rel="noopener noreferrer">Instagram</a>.</p>
<p>Follow L2 Cyber on <a href="https://twitter.com/L2Cyber" target="_blank" rel="noopener noreferrer">Twitter</a>, <a href="https://www.linkedin.com/company/l2cyber/" target="_blank" rel="noopener noreferrer">LinkedIn</a>, <a href="https://www.instagram.com/l2cyber/" target="_blank" rel="noopener noreferrer">Instagram</a> and <a href="https://www.facebook.com/L2Cyber/" target="_blank" rel="noopener noreferrer">Facebook</a>.</p>
<p><a href="https://www.l2cybersecurity.com/" target="_blank" rel="noopener noreferrer">© L2 Cyber Security Solutions</a></p>
<p>The post <a href="https://www.l2cybersecurity.com/weekendwisdom-034-ransomware-case-study/">#WeekendWisdom 034 Ransomware Case Study</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		<enclosure url="https://www.l2cybersecurity.com/wp-content/uploads/2020/06/WeekendWisdom-034-lo.mp4" length="25023185" type="video/mp4" />

			</item>
		<item>
		<title>First Annual Report from the DPC</title>
		<link>https://www.l2cybersecurity.com/first-annual-report-dpc/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Fri, 01 Mar 2019 16:30:03 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Annual Report]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Data Protection Commission]]></category>
		<category><![CDATA[DPC]]></category>
		<category><![CDATA[GDPR]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=1605</guid>

					<description><![CDATA[<p>The first annual report from the Data Protection Commission, under the auspices of the GDPR has just been released. Have you read it yet? It&#8217;s only 104 pages and unless you are a privacy nerd (like me) you may find it tough going. Truth be told, I struggled to stay fully focused on it as&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/first-annual-report-dpc/">First Annual Report from the DPC</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img decoding="async" class="alignleft size-thumbnail wp-image-1606" src="https://www.l2cybersecurity.com/wp-content/uploads/2019/03/DPC-first-annual-report-150x150.jpg" alt="first annual report" width="150" height="150" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2019/03/DPC-first-annual-report-150x150.jpg 150w, https://www.l2cybersecurity.com/wp-content/uploads/2019/03/DPC-first-annual-report.jpg 300w" sizes="(max-width: 150px) 100vw, 150px" />The first annual report from the Data Protection Commission, under the auspices of the GDPR has just been released. <span id="more-1605"></span>Have you read it yet? It&#8217;s only 104 pages and unless you are a privacy nerd (like me) you may find it tough going. Truth be told, I struggled to stay fully focused on it as I read through it.</p>
<h3>Surely this isn&#8217;t the first annual report?</h3>
<p>The office of the Data Protection Commissioner has been around for many many years and have issued many many annual reports. When the GDPR came along on 25th May, the office was renamed to be the Data Protection Commission. This report (which you can <a href="https://www.dataprotection.ie/sites/default/files/uploads/2019-03/DPC Annual Report 25 May - 31 December 2018.pdf" target="_blank" rel="noopener noreferrer">read here</a>) is their first report covering the period 25th May &#8211; 31st December 2018.</p>
<p>Due to the fact that there are investigations still going on from before 25th May 2018, under the previous legislation, the report shows two sets of figures. This post will concentrate on the GDPR figures.</p>
<h3>What are the highlights?</h3>
<p>There were nearly 2,000 complaints made. The top 10 of these accounted for 94% of all complaints. They are:</p>
<p><img fetchpriority="high" decoding="async" class="aligncenter size-full wp-image-1607" src="https://www.l2cybersecurity.com/wp-content/uploads/2019/03/Report-complaints.jpg" alt="Top 10 GDPR complaints 2018" width="457" height="603" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2019/03/Report-complaints.jpg 457w, https://www.l2cybersecurity.com/wp-content/uploads/2019/03/Report-complaints-227x300.jpg 227w" sizes="(max-width: 457px) 100vw, 457px" /></p>
<p>Issues around access rights was also the number 1 complaint (39%) under the previous legislation, so this is the most important area that a business or organisation should get right. I&#8217;m a little surprised by the complaints under Right of Rectification. That is such a simple one to get correct, why were there 30 complaints? ?‍♂️</p>
<h3>Data breaches are on the rise.</h3>
<p>There were nearly 3,700 data breaches reported. 85% of them were in the category of unauthorised disclosure which wasn&#8217;t really surprising.</p>
<p><img decoding="async" class="aligncenter size-full wp-image-1608" src="https://www.l2cybersecurity.com/wp-content/uploads/2019/03/DPC-Data-Breaches-2018.jpg" alt="Data breaches 2018" width="500" height="432" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2019/03/DPC-Data-Breaches-2018.jpg 500w, https://www.l2cybersecurity.com/wp-content/uploads/2019/03/DPC-Data-Breaches-2018-300x259.jpg 300w" sizes="(max-width: 500px) 100vw, 500px" /></p>
<p>It&#8217;s interesting to note that there were 226 incidents (6%) which related to paper records. I actually think that figure should be a little bit higher, as I suspect people don&#8217;t consider losing or poorly disposing of paper records to be a proper data breach.</p>
<h3>What about the Facebook problems reported last year?</h3>
<p>They are in there too. There are 15 Statutory Inquiries into multinational technology companies. 10 of these inquiries relate to Facebook (7), or Facebook owned companies (WhatsApp 2 and Instagram 1). Of those 10 complaints 4 related to Legal Basis for processing and 3 relate to the <a href="https://www.l2cybersecurity.com/facebook-breach-dpc-public/" target="_blank" rel="noopener noreferrer">data breach reported in September 2018</a>.</p>
<p>The other companies that had inquiries ongoing are Apple with 2, Twitter 2 and LinkedIn 1.</p>
<h3>Was there anything else interesting in the report?</h3>
<p>Well yes there was. It&#8217;s to do with how the DPC acted when dealing with some of the complaints they came across. There were a few case studies provided (pages 24-26). The DPC handled these without the need to impose sanctions, by making the data controller aware of their failings and providing ways to rectify the situation.</p>
<p>What was also interesting was where complaints had come in about data controllers, who had been investigated previously by the Office of the Data Protection Commissioner. In these cases, the DPC prosecuted them in court and had financial penalties applied (pages 64-67). These cases were taken under previous legislation, so the sanctions were small enough. But this shows that if you, as a controller, come to the DPC&#8217;s attention multiple times, they will take a dim view of your behaviour.</p>
<h3>Conclusion:</h3>
<p>There was a lot more to this first annual report than what I covered above, but for most businesses, these are the items that matter.</p>
<p>If you would like to avail of a free 1 hour consultation to find out what you need to do to prepare your business for the GDPR, then please send an e-mail to <a href="mailto:info@l2cybersecurity.com">info@l2cybersecurity.com</a> and somebody will get back to you.</p>
<p>#GDPR #SimpleGDPR</p>
<p>#SecuritySimplified</p>
<p>The post <a href="https://www.l2cybersecurity.com/first-annual-report-dpc/">First Annual Report from the DPC</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Dash cam &#8211; Machina Non Grata.</title>
		<link>https://www.l2cybersecurity.com/dash-cam-machina-non-grata/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Mon, 24 Dec 2018 16:09:37 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Dash cam]]></category>
		<category><![CDATA[Data Protection Commission]]></category>
		<category><![CDATA[DPC]]></category>
		<category><![CDATA[GDPR]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=1525</guid>

					<description><![CDATA[<p>A dash cam is a popular Christmas present or indeed a present at any time of year. I got one earlier this year and have been having it merrily record the road ahead of my car ever since. I was doing this with the belief that the household exemption covered such recording. This is the&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/dash-cam-machina-non-grata/">Dash cam &#8211; Machina Non Grata.</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="alignleft size-thumbnail wp-image-1526" src="https://www.l2cybersecurity.com/wp-content/uploads/2018/12/dash-cam-banned-150x150.jpg" alt="dash cam banned" width="150" height="150" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2018/12/dash-cam-banned-150x150.jpg 150w, https://www.l2cybersecurity.com/wp-content/uploads/2018/12/dash-cam-banned.jpg 300w" sizes="auto, (max-width: 150px) 100vw, 150px" />A dash cam is a popular Christmas present or indeed a present at any time of year. I got one earlier this year and have been having it merrily record the road ahead of my car ever since. I was doing this with the belief that the household exemption covered such recording. This is the exemption that covers things like home CCTV systems. However <a href="https://www.dataprotection.ie/en/guidance-landing/guidance-drivers-use-dash-cams" target="_blank" rel="noopener">recent guidance from the Data Protection Commission</a> has changed my attitude towards them.<span id="more-1525"></span></p>
<h3>A dash cam and data protection.</h3>
<p>Basically it states that if you use a dash cam and record a public area, you become a data controller. A data controller is required to have policies and procedures in place for how the data is processed, stored, shared, etc.</p>
<ul>
<li>You need to be transparent about the recording. So you need to have signage that indicates recording is taking place.</li>
<li>You need to specify under what legal basis is the recording being made.</li>
<li>You must also state how long you will retain the data.</li>
<li>If someone is aware of the existence of your dash cam, then they are entitled to ask for a copy of footage of them from you. You have 30 days to respond to the request. You must also redact (blur/black out) any other identifiable individuals who may be also in that recording.</li>
<li>The individuals have more rights available to them. You can find out <a href="https://www.l2cybersecurity.com/wp-content/uploads/2017/05/GDPR-01-Individuals-rights-1.pdf" target="_blank" rel="noopener">what they are here</a>.</li>
<li>There is a need to ensure the data is properly secured and limit who has access to it.</li>
<li>You should not share any footage online in a social media platform.</li>
<li>Gardaí may request a copy of the footage, but you can only give it to them when they provide you with a written request under Section 41 of the Data Protection Act 2018.</li>
</ul>
<h3>But my insurer is giving me a discount.</h3>
<p>Some insurance companies are incentivising people to install a dash cam. This makes things even more tricky. If any of the following are a requirement of an insurance policy:</p>
<ul>
<li>You are required to install and use the camera;</li>
<li>You are required to provide footage to your insurer at their request or to upload it to their website;</li>
<li>Your insurer monitors your use of the camera; and/or</li>
<li>Your insurer instructs you as to which model of camera or application you must use.</li>
</ul>
<p>then you are entering into a joint data controller relationship. This requires that a legal arrangement be put in place that sets out each parties respective responsibilities. So I would think twice about doing this.</p>
<p>If you want to get in touch and discuss this, then please either ring <span style="color: #ff0000;"><strong>087-436-2675</strong></span> or drop an e-mail to <a href="mailto:info@L2CyberSecurity.com" target="_blank" rel="noopener">info@L2CyberSecurity.com</a>.</p>
<h3>My story.</h3>
<p>Earlier this year, I lost the two wing mirrors on my car in two separate incidents, within weeks of each other. The first one I lost my passenger side mirror, as I swerved to avoid an oncoming car that drifted in front of me. I lost my mirror and also destroyed the mirror of a new parked car. The drifting car did not stop. I had to pay for a new wing mirror for the parked car of €210.</p>
<p>The second incident, I lost my drivers side mirror to an idiot coming around a corner at speed on my side of the road. He tried to get back to his side of the road as I swerved towards the bushes, but no good. He didn&#8217;t stop either, but he lost his drivers mirror too. I&#8217;ve a ten year old car, so even getting second hand mirrors, the two cost me €250.</p>
<p>I was given a dash cam, so the next time that happened, I&#8217;d have something to show to the Gardaí. Of course nothing has happened to me since I got it. Anyway, because of the above, I have removed the dash cam and here it is about to be put away.</p>
<p><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-1527" src="https://www.l2cybersecurity.com/wp-content/uploads/2018/12/IMG_20181224_112210.jpg" alt="dash cam for sale" width="592" height="722" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2018/12/IMG_20181224_112210.jpg 592w, https://www.l2cybersecurity.com/wp-content/uploads/2018/12/IMG_20181224_112210-246x300.jpg 246w" sizes="auto, (max-width: 592px) 100vw, 592px" /></p>
<p>#SecuritySimplified #GDPR</p>
<p>The post <a href="https://www.l2cybersecurity.com/dash-cam-machina-non-grata/">Dash cam &#8211; Machina Non Grata.</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Facebook Breach &#8211; The DPC was very public about it.</title>
		<link>https://www.l2cybersecurity.com/facebook-breach-dpc-public/</link>
		
		<dc:creator><![CDATA[Liam]]></dc:creator>
		<pubDate>Fri, 05 Oct 2018 15:11:05 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Data Protection Commission]]></category>
		<category><![CDATA[DPC]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Facebook breach]]></category>
		<category><![CDATA[GDPR]]></category>
		<guid isPermaLink="false">https://www.l2cybersecurity.com/?p=1418</guid>

					<description><![CDATA[<p>Unless you&#8217;ve been living under a rock for the last week, you will have heard about the Facebook breach. This is where the accounts of at least 50 million people were compromised by evil doers. There was another 40 million people who may have been at risk too. Facebook became aware of the breach on&#8230;</p>
<p>The post <a href="https://www.l2cybersecurity.com/facebook-breach-dpc-public/">Facebook Breach &#8211; The DPC was very public about it.</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="alignleft size-thumbnail wp-image-2875" src="https://www.l2cybersecurity.com/wp-content/uploads/2018/10/Facebook-Breach-1-150x150.jpg" alt="Facebook Breach" width="150" height="150" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2018/10/Facebook-Breach-1-150x150.jpg 150w, https://www.l2cybersecurity.com/wp-content/uploads/2018/10/Facebook-Breach-1.jpg 300w" sizes="auto, (max-width: 150px) 100vw, 150px" />Unless you&#8217;ve been living under a rock for the last week, you will have heard about the Facebook breach. This is where the accounts of at least 50 million people were compromised by evil doers. <span id="more-1418"></span>There was another 40 million people who may have been at risk too. Facebook became aware of the breach on Tuesday 25th September and took action by Thursday 27th. This action was to log the 90 million users out of Facebook and make them sign in again. They reported the data breach to the Data Protection Commission (DPC) on Friday 28th September.</p>
<p>As you should know by now, the General Data Protection Regulation (GDPR) requires a business to notify the regulatory authority for data protection within 72 hours of becoming aware of the breach, where there is a risk to the rights and freedoms of the affected individuals. They also must notify the affected individuals if there is a high risk to their rights and freedoms and must do so without undue delay.</p>
<p>Facebook notified both on Friday. They put out <a href="https://newsroom.fb.com/news/2018/09/security-update/" target="_blank" rel="noopener">a public notice</a> about the breach and the DPC were notified, as <a href="https://www.dataprotection.ie/docs/EN/03-10-2018-Facebook-Data-Breach-Commencement-of-Investigation/i/1787.htm">confirmed by them</a> earlier this week. Here are some tweets from the Data Protection Commission:</p>
<p><img loading="lazy" decoding="async" width="577" height="337" class="size-full wp-image-1421 aligncenter" src="https://www.l2cybersecurity.com/wp-content/uploads/2018/10/DPC-Tweet-1.jpg" alt="&quot;&lt;yoastmark" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2018/10/DPC-Tweet-1.jpg 577w, https://www.l2cybersecurity.com/wp-content/uploads/2018/10/DPC-Tweet-1-300x175.jpg 300w" sizes="auto, (max-width: 577px) 100vw, 577px" /></p>
<p><img loading="lazy" decoding="async" width="582" height="475" class="wp-image-1422 size-full aligncenter" src="https://www.l2cybersecurity.com/wp-content/uploads/2018/10/DPC-Tweet-2.jpg" alt="&quot;&lt;yoastmark" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2018/10/DPC-Tweet-2.jpg 582w, https://www.l2cybersecurity.com/wp-content/uploads/2018/10/DPC-Tweet-2-300x245.jpg 300w" sizes="auto, (max-width: 582px) 100vw, 582px" /></p>
<p><img loading="lazy" decoding="async" width="570" height="676" class="size-full wp-image-1423 aligncenter" src="https://www.l2cybersecurity.com/wp-content/uploads/2018/10/DPC-Tweet-3.jpg" alt="&quot;&lt;yoastmark" srcset="https://www.l2cybersecurity.com/wp-content/uploads/2018/10/DPC-Tweet-3.jpg 570w, https://www.l2cybersecurity.com/wp-content/uploads/2018/10/DPC-Tweet-3-253x300.jpg 253w" sizes="auto, (max-width: 570px) 100vw, 570px" /></p>
<h3>The DPC talked very publicly about the Facebook breach, didn&#8217;t they?</h3>
<p>And this is what I want to address in this post. This Facebook breach was addressed very publicly by the DPC. I would believe that this is because Facebook is such a huge source of personal data. Also the fact that this story has attracted massive worldwide attention. If they didn&#8217;t come out with those tweets, they would have been accused of all sorts of bad practice.</p>
<p>I don&#8217;t expect them to be publicly tweeting about a data breach in a small business, which accidentally sent a spreadsheet containing customer personal data to an incorrect e-mail recipient. It&#8217;s very important you realise this. I don&#8217;t want any business owner, who becomes aware of a data breach which needs to be reported, to decide not to notify the DPC in case they should start tweeting about it.</p>
<p>If you become aware of a notifiable breach, please report it. Unless you are a massive source of personal data, I don&#8217;t expect the DPC to tweet about it. It will be dealt with reasonably discreetly.</p>
<h3>Want to find out more about data breaches?</h3>
<p>I did a short (&lt;2 minute) video on <a href="https://www.l2cybersecurity.com/video-6-examples-data-breach/" target="_blank" rel="noopener">6 examples of a data breach</a>. If you head over to my <a href="https://www.youtube.com/channel/UCJzeEIeoYCmU8T5jkQjnekg" target="_blank" rel="noopener">YouTube channel</a> you can see an entire video series with more discussion about the different examples of data breaches.</p>
<p>In the meantime, lets be careful out there.</p>
<p>#GDPR #SecuritySimplified</p>
<p>The post <a href="https://www.l2cybersecurity.com/facebook-breach-dpc-public/">Facebook Breach &#8211; The DPC was very public about it.</a> appeared first on <a href="https://www.l2cybersecurity.com">L2 Cyber Security Solutions Ltd.</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
