However, there are some important elements that any organisation which stores/transmits personal information should know.

  1. The Data Protection Commissioner (DPC) imposes obligations on organisations to take appropriate measures to protect the security of personal data which they store. This could include data on customers, employees, patients, etc.
  2. If an organisation’s files containing personal data are accessed by unauthorised persons, any potentially affected person must be notified, and a report must be filed with the DPC.
  3. The DPC has extensive powers over organisations deemed to have taken insufficient steps to protect personal data, to ensure any data breaches are rectified.
  4. Even if your organisation is a victim of personal data theft (either through an online hacking event, or theft of a physical item containing personal data, e.g. laptop), you are still liable for the data breach.

What does this mean for your business?
If you store any personal information, you should ensure that it can only be accessed by authorised staff. This starts by determining what you store, where you store it, and determining if these locations are protected against unauthorised access.

