Incidents & Security
What to Do When Your Business Has a Data Breach
A step-by-step guide for Jamaican businesses on containing, assessing, escalating and documenting a personal-data breach under the Data Protection Act.
What you will learn
- How to contain a breach and prevent further exposure
- What facts to establish about the incident
- How to assess the impact on affected individuals
- Why escalation and documentation matter
A staff member sends payroll information to the wrong email address. A laptop containing customer records disappears. An attacker gains access to your website. Employee information is accidentally published. A WhatsApp message containing customer information goes to the wrong group.
These can all raise data-protection concerns.
First: contain the incident
Your immediate priority is preventing further exposure. Depending on the incident, this might involve:
- disabling an account;
- changing credentials;
- recalling an email;
- removing a public file;
- isolating a compromised computer;
- contacting a processor; or
- restricting system access.
Second: establish what happened
Record:
- date and time discovered;
- person who discovered it;
- affected system;
- personal data involved;
- number or categories of people potentially affected;
- whether sensitive information was involved;
- whether information was encrypted;
- processors involved; and
- actions already taken.
Third: assess the breach
Consider potential consequences for affected individuals. Could someone suffer:
- identity theft;
- financial loss;
- discrimination;
- reputational harm;
- embarrassment;
- loss of confidentiality; or
- other adverse consequences?
Fourth: escalate immediately
Jamaica's DPA imposes time-sensitive breach obligations. Organisations should therefore have an escalation procedure rather than allowing an incident to remain in someone's inbox.
Fifth: document your response
Even after the immediate problem is resolved, document: what happened, why it happened, what was affected, what you did, and what will prevent recurrence.
Build your response before you need it
The worst time to design a breach-response process is during a breach.
Put this into practice
Record and manage incidents from discovery through closure.
Set Up My Breach Response PlanFrequently asked questions
Key takeaways
- Contain the incident first, but do not destroy evidence.
- Establish what happened, what data was involved and who is affected.
- Assess the potential consequences for affected individuals.
- Jamaica's DPA imposes time-sensitive breach obligations, so escalate immediately.
- Document the incident and the lessons that prevent recurrence.
