Contain
- Privacy breach or near miss is discovered by aUniversitystaffmember/student/community member.
- Do not try and manage the situation yourself.
- Inform the potential privacy breach to your line Manager (if applicable) and to theInformation and Records Management (IRM)team viaprivacy@canterbury.ac.nz. Please include as much information as possible about the situation.
- If this is a system breach please also contact the helpdesk (0508 824 843 or +64 3 369 5000) to get the issue stopped immediately.
Assess
TheIRMteam will assess:
- What has happened
- How it has happened
- What systemsor processesare involved
- Whoseinformation has been affected – staff, student, third party etc.
- The scale of the breach – internal/external, email, system etc.
- The type of information includede.g.medical info, home addresses
- What could be done with this information by the recipient
- What can be done to retrieve or secure the personal information
They willmake a planfor response considering the risks associated with the breach. They will include appropriate individuals and teams across the campus as needed.
Notify
The team will decide who needs to be informed about the incident. This may bethe:
- Individuals affected
- Stakeholders
- Public
- Privacy Commissioner
Some breaches need to be notified to the Privacy Commissioner. This must happen for all breaches involving medical information. All breaches which meet a threshold for ‘serious harm’ must be notified. TheIRMteam will decide this in line withthe Privacy Act andguidance from the Privacy Commission.
Prevent
A key part of responding to Privacy breaches is reporting on them. All privacy breaches are tracked internally and reported on to senior management.Please note – no individuals will be named in the report, the reporting is about the issue and solutions, not blame.
Reviewing what happened is the last key component. A review of the incident to check if there are system or process issues which can be improved. Ifsorecommendations will be made from the team.