Incidents & Security

What to Do When Your Business Has a Data Breach

A step-by-step guide for Jamaican businesses on containing, assessing, escalating and documenting a personal-data breach under the Data Protection Act.

Beginner 10 min
This module is general information, not legal advice, and is being reviewed by our legal team. For your specific situation, consult the official Data Protection Act, 2020 or seek professional advice.

What you will learn

  • How to contain a breach and prevent further exposure
  • What facts to establish about the incident
  • How to assess the impact on affected individuals
  • Why escalation and documentation matter

A staff member sends payroll information to the wrong email address. A laptop containing customer records disappears. An attacker gains access to your website. Employee information is accidentally published. A WhatsApp message containing customer information goes to the wrong group.

These can all raise data-protection concerns.

First: contain the incident

Your immediate priority is preventing further exposure. Depending on the incident, this might involve:

  • disabling an account;
  • changing credentials;
  • recalling an email;
  • removing a public file;
  • isolating a compromised computer;
  • contacting a processor; or
  • restricting system access.
Watch out. Do not destroy evidence while attempting to contain the problem.

Second: establish what happened

Record:

  • date and time discovered;
  • person who discovered it;
  • affected system;
  • personal data involved;
  • number or categories of people potentially affected;
  • whether sensitive information was involved;
  • whether information was encrypted;
  • processors involved; and
  • actions already taken.

Third: assess the breach

Consider potential consequences for affected individuals. Could someone suffer:

  • identity theft;
  • financial loss;
  • discrimination;
  • reputational harm;
  • embarrassment;
  • loss of confidentiality; or
  • other adverse consequences?

Fourth: escalate immediately

Jamaica's DPA imposes time-sensitive breach obligations. Organisations should therefore have an escalation procedure rather than allowing an incident to remain in someone's inbox.

Fifth: document your response

Even after the immediate problem is resolved, document: what happened, why it happened, what was affected, what you did, and what will prevent recurrence.

Build your response before you need it

The worst time to design a breach-response process is during a breach.

Legal note. This module is general information about Jamaica's Data Protection Act, 2020, not legal advice. For your specific obligations and timelines, consult the Act or a qualified professional.

Put this into practice

Record and manage incidents from discovery through closure.

Set Up My Breach Response Plan

Frequently asked questions

Any incident that leads to personal data being lost, disclosed, altered, destroyed or accessed without authorisation can raise data-protection concerns.

Key takeaways

  • Contain the incident first, but do not destroy evidence.
  • Establish what happened, what data was involved and who is affected.
  • Assess the potential consequences for affected individuals.
  • Jamaica's DPA imposes time-sensitive breach obligations, so escalate immediately.
  • Document the incident and the lessons that prevent recurrence.

Continue learning

Tools

Ask the Privacy Assistant

Beta