سԹ

Menu

Wananga landing Wananga landing
Topic

Privacy breaches

23 October 2023

Privacy are usually minor and caused by human error. If you create or discover a privacy breach, the focus is on protecting the person or people whose privacy has been breached, minimising the impact where possible, and preventing further breaches, not blaming individuals. See what to do if you create or discover a privacy breach at UC.

HOW TO APPLY

What is a privacy breach?

A privacy breach occurs when an organisation or individual either intentionally or accidentally:

  • Provides unauthorised or accidental access to someone's personal information
  • Discloses, alters, loses or destroys someone's personal information
  • A privacy breach also occurs when someone is unable to access their personal information due to, for example, their account being hacked

If you aren’t sure if what has happened is a breach – tell us anyway and we can confirm if it was a privacy breach or a near miss.Contact us onprivacy@canterbury.ac.nz.

If the privacy breach involves sending an email to an incorrect email address, follow these steps:

  1. Contact the service desk at0508 824 843 or +64 3 369 5000to see if the emails can be removed from the incorrect recipient's inbox.
  2. Contact us atprivacy@canterbury.ac.nzto report it, and follow the rest of the process on this page.

Privacy Breaches occur. They are usually minor andmost commonly causedby human error – often sending an email to an incorrect email address.

After discovering a privacy breach, the focus is on the protection of the person or people whose privacy has been breached, minimising the impact where possible, and preventing further breaches, not blaming individuals.

It is important to follow the below steps if you create or discover a privacy breach at UC.

Privacy Breach Cycle Graphic

Contain

  1. Privacy breach or near miss is discovered by aUniversitystaffmember/student/community member.
  2. Do not try and manage the situation yourself.
  3. Inform the potential privacy breach to your line Manager (if applicable) and to theInformation and Records Management (IRM)team viaprivacy@canterbury.ac.nz. Please include as much information as possible about the situation.
  4. If this is a system breach please also contact the helpdesk (0508 824 843 or +64 3 369 5000) to get the issue stopped immediately.

Assess

TheIRMteam will assess:

  • What has happened
  • How it has happened
  • What systemsor processesare involved
  • Whoseinformation has been affected – staff, student, third party etc.
  • The scale of the breach – internal/external, email, system etc.
  • The type of information includede.g.medical info, home addresses
  • What could be done with this information by the recipient
  • What can be done to retrieve or secure the personal information

They willmake a planfor response considering the risks associated with the breach. They will include appropriate individuals and teams across the campus as needed.

Notify

The team will decide who needs to be informed about the incident. This may bethe:

  • Individuals affected
  • Stakeholders
  • Public
  • Privacy Commissioner

Some breaches need to be notified to the Privacy Commissioner. This must happen for all breaches involving medical information. All breaches which meet a threshold for ‘serious harm’ must be notified. TheIRMteam will decide this in line withthe Privacy Act andguidance from the Privacy Commission.

Prevent

A key part of responding to Privacy breaches is reporting on them. All privacy breaches are tracked internally and reported on to senior management.Please note – no individuals will be named in the report, the reporting is about the issue and solutions, not blame.

Reviewing what happened is the last key component. A review of the incident to check if there are system or process issues which can be improved. Ifsorecommendations will be made from the team.

Privacy Preferences

By clicking "Accept All Cookies", you agree to the storing of cookies on your device to enhance site navigation, analyse site usage, and assist in our marketing efforts.