Task:                     

[07.202-ADGM] - COMPLIANCE: NOTIFY THE OFFICE OF DATA PROTECTION OF DATA BREACHES

Purpose:      

This application form must be submitted by ADGM registered entities to inform the Office of Data Protection of a personal data breach. A personal data breach is any confirmed incident in which Personal Data has been lost, accessed and/or disclosed in an unauthorized fashion either accidentally or deliberately.

Legal Entities:    

All ADGM registered entities, i.e. Companies, Partnerships, Foundations, DLT Foundations

Questions:         


1) Do we have access to the client’s entity profile on the KOUNTED portal? If not, this must be requested via ORS.

                               

2) Provide responses to the following questions:

                     a) Details of Data Protection Breach

Details of the Incident

Incident Date

How did the Incident happen

Reason for the delay in reporting the incident to the Commissioner (if any)

What measures did you put in place to prevent the incident from occurring?

Details of Policies & Procedures in place that are considered relevant to the incident

Policies & Procedures Implementation Date

b) Personal Data at Risk

Details of Personal data that has been placed at risk

Details of affected financial or sensitive data

Number of affected individuals

Are the affected individuals aware of the incident?

Potential detriment to individuals and adverse effect on those individuals

Have any affected individuals complained to the Data Controller

Has the organization taken any action to minimize/mitigate the effect on the affected individuals?

Has the data placed at risk now been recovered?

Steps that the Data Controller has taken to prevent a recurrence of the incident

c) Data Processors (Third Party)

Was the incident a result of a breach by a Data Processor? (If No, skip to Training and Guidance)

What action(s) did the Processor take to minimise/mitigate the effect on the affected individuals?

Were there any contractual obligations with the Processor regarding the use of personal data?

Did the contractual obligations include technical and organisations regarding security?

Do you consider the incident has breached any contractual obligations or safeguards?

What action have you taken with regard to the Processor?

d) Training and Guidance

As a Data Controller did you provide your staff with training on the requirements of the Data protection Regulations?

Is the training mandatory for all staff?

Had all of the staff members involved in this incident received training?

As the Data Controller are you providing any detailed guidance to staff on the handling of personal data in relation to the incident you are reporting?

e) Previous Reports

Have you reported any previous incidents to the Commissioner in the last two years?

g) Miscellaneous

Have you notified any other (overseas) data protection authorities about this incident?

Have you informed the Police about this incident?

Has there been any media coverage of the incident?

Pay Attention:   

1)      Under Article 32 of ADGM’s Data Protection Regulations 2021, Data Controllers must notify the Office of Data Protection of personal data breaches without undue delay and, where feasible, not later than 72 hours after becoming aware of them.

2)      Data Controllers must inform the Office of Data Protection of a data breach. ‘Data Controller’ means any ADGM registered entity that alone or jointly with others determines the purposes and means of the processing of Personal Data. A representative of the Data Controller should make the notification to the ADGM Office of Data Protection on behalf of the Data Controller.

Submission:       

Online via the ADGM RA portal https://newreg.adgm.com/

                               

Use the application form: “Notify the Office of Data Protection”

Timeline:             

Data Controllers must notify the Office of Data Protection of personal data breaches without undue delay and, where feasible, not later than 72 hours after becoming aware of them.

Timeframe:        

KOUNTED 1-2 working days including drafting the online application, provided all the relevant information has been provided


ADGM: 3-5 working days, returns and timeframe for approval subject to review.

Supporting documents:

The notification must include the following information:

·         a description of the nature of the breach including

o   categories and approximate numbers of data subjects concerned; 

o   categories and approximate numbers of personal data records concerned;

 

·         the name and contact details of your data protection officer or other contact person who can provide more information;

·         the likely consequences of the breach; and

·         a description of the measures taken or proposed to be taken to address the breach, including measures to mitigate its possible adverse effects if appropriate.

 

Applicable Legislation:   

KOUNTED Fees:

Please add the KOUNTED fees

ADGM Fees:      

Nil

Fine:                     

To be determined by the Office of Data Protection


LINKED FILES: