GDPR

Privacy Do’s & Don’ts

ABU has summarized the most important implications of the GDPR for temporary staffing agencies in a concise overview.

UBN Data Breach Protocol

A data breach occurs when personal data is processed unlawfully, exposed to loss, or otherwise wrongfully or unintentionally obtained by a person or organization that should not have access to that data. This could involve a lost USB drive or a stolen laptop containing personal data, but it could also involve a breach of a data system or the accidental granting of access to data to individuals or entities that should not have access to it. A data breach can be as simple as sending an email to a mailing list where all email addresses are visible to everyone.

Examples of a data breach include:

  • You sent an email containing personal information to the wrong person
  • Some resumes were thrown in the trash (and therefore not in the bin for shredding)
  • Someone knows your login credentials for Citrix or another UBN application
  • You provide proof of identity to a third party, with the exception of immigration documents provided to temporary staffing agencies.

Reporting Requirement

In the event of a serious data breach, UBN is required under the General Data Protection Regulation (GDPR) to report it to the Dutch Data Protection Authority (AP) within 72 hours and, in some cases, to the individuals concerned. If the data breach is minor and does not pose a privacy risk to the data subject(s), it does not need to be reported to the AP. Every data breach, no matter how minor, must be recorded internally.

It is important that everyone knows what to do in the event of (a suspected) data breach. Below, you can read about how you are expected to respond.

At UBN, we have a central reporting center for (suspected) data breaches.
The members of the UBN Data Breach Reporting Center are:

  • Maurits Mulder; 0618131700

If Maurits cannot be reached, please contact:

  • ICT Advisor; 0297 288 873

The Protocol

Immediately after an employee or staff member discovers or becomes aware of a possible loss or unlawful processing of personal data within UBN, he or she must report it to the UBN data breach reporting center.

The Data Breach Reporting Center determines whether a (potential) data breach has occurred and, if so, whether this data breach must be reported to the Dutch Data Protection Authority and/or to the affected individual(s).

The data breach reporting center will, if necessary, report the breach to the Dutch Data Protection Authority and/or the data subject(s). Employees are not permitted to report the (potential) data breach to the Dutch Data Protection Authority and/or the data subject(s) on their own.

If the employee disagrees with the data breach reporting center’s decision to report—or not to report—the (potential) data breach to the Dutch Data Protection Authority and/or the data subject(s), he or she should contact management.