Privacy Do’s & Don’ts
ABU has summarized the key implications of the GDPR for staffing agencies in a concise overview.
UBN Data Breach Protocol
A data breach occurs when personal data is processed unlawfully, exposed to loss, or otherwise wrongfully or unintentionally falls into the hands of a person or organization that should not have access to that data. This could involve a lost USB drive or a stolen laptop containing personal data, but also a breach of a data system or accidentally granting access to data to individuals or entities who should not have access to it. A data breach can be as simple as sending an email to a mailing list where all email addresses are visible to everyone.
Examples of data breaches include:
- You sent an email containing personal information to the wrong person
- Some resumes were thrown in the trash (and not in the shredder)
- Someone knows your login credentials for Citrix or another UBN application
- You provide identification to a third party, with the exception of immigration documents provided to hiring companies.
Reporting requirement
In the event of a serious data breach, UBN is required under the General Data Protection Regulation (GDPR) to report this to the Dutch Data Protection Authority (AP) within 72 hours and, in some cases, to the individuals concerned. If the data breach is minor and does not pose a privacy risk to the data subject(s), it does not need to be reported to the AP. Every data breach, no matter how minor, must be recorded internally.
It is important that everyone knows what to do in the event of (a suspected) data breach. Below, you can read about how you are expected to respond.
At UBN, we have a central reporting center for (suspected) data breaches.
The members of the UBN Data Breach Reporting Center are:
- Maurits Mulder; 0618131700
If Maurits cannot be reached, please contact:
- IT Advisor; 0297 288 873
The protocol
As soon as an employee discovers or becomes aware of a potential loss or unlawful processing of personal data within UBN, he or she must report it to the UBN Data Breach Reporting Center.
The Data Breach Reporting Center determines whether a (potential) data breach has occurred and, if so, whether this breach must be reported to the Dutch Data Protection Authority and/or the data subject(s).
If necessary, the data breach reporting center will notify the Dutch Data Protection Authority and/or the data subject(s). Employees are not permitted to report the (potential) data breach to the Dutch Data Protection Authority and/or the data subject(s) themselves.
If the employee disagrees with the data breach reporting center’s decision to report—or not to report—the (potential) data breach to the Dutch Data Protection Authority and/or the data subject(s), they should contact management.