九州影院

Menu

Wananga landing Wananga landing
Topic

Privacy breaches

23 October 2023

Privacy are usually minor and caused by human error. If you create or discover a privacy breach, the focus is on protecting the person or people whose privacy has been breached, minimising the impact where possible, and preventing further breaches, not blaming individuals. See what to do if you create or discover a privacy breach at UC.听

HOW TO APPLY

What is a privacy breach?

A privacy breach occurs when an organisation or individual either intentionally or accidentally:

  • Provides unauthorised or accidental access to someone's personal information
  • Discloses, alters, loses or destroys someone's personal information
  • A privacy breach also occurs when someone is unable to access their personal information due to, for example, their account being hacked

If you aren鈥檛 sure if what has happened is a breach 鈥 tell us anyway and we can confirm if it was a privacy breach or a near miss.听Contact us on听privacy@canterbury.ac.nz.

If the privacy breach involves sending an email to an incorrect email address, follow these steps:

  1. Contact the service desk at听0508 824 843 or +64 3 369 5000听to see if the emails can be removed from the incorrect recipient's inbox.
  2. Contact us at听privacy@canterbury.ac.nz听to report it, and follow the rest of the process on this page.

Privacy Breaches occur. They are usually minor and听most commonly caused听by human error 鈥 often sending an email to an incorrect email address.

After discovering a privacy breach, the focus is on the protection of the person or people whose privacy has been breached, minimising the impact where possible, and preventing further breaches, not blaming individuals.听

It is important to follow the below steps if you create or discover a privacy breach at UC.

Privacy Breach Cycle Graphic

Contain

  1. Privacy breach or near miss is discovered by a听University听staff听member/student/community member.听
  2. Do not try and manage the situation yourself.听
  3. Inform the potential privacy breach to your line Manager (if applicable) and to the听Information and Records Management (IRM)听team via听privacy@canterbury.ac.nz. Please include as much information as possible about the situation.
  4. If this is a system breach please also contact the helpdesk (0508 824 843 or +64 3 369 5000) to get the issue stopped immediately.

Assess

The听IRM听team will assess:

  • What has happened听
  • How it has happened
  • What systems听or processes听are involved
  • Whose听information has been affected 鈥 staff, student, third party etc.
  • The scale of the breach 鈥 internal/external, email, system etc.
  • The type of information included听e.g.听medical info, home addresses
  • What could be done with this information by the recipient
  • What can be done to retrieve or secure the personal information

They will听make a plan听for response considering the risks associated with the breach. They will include appropriate individuals and teams across the campus as needed.

Notify

The team will decide who needs to be informed about the incident. This may be听the:

  • Individuals affected听
  • Stakeholders听
  • Public听
  • Privacy Commissioner

Some breaches need to be notified to the Privacy Commissioner. This must happen for all breaches involving medical information. All breaches which meet a threshold for 鈥榮erious harm鈥 must be notified. The听IRM听team will decide this in line with听the Privacy Act and听guidance from the Privacy Commission.

Prevent

A key part of responding to Privacy breaches is reporting on them. All privacy breaches are tracked internally and reported on to senior management.听Please note 鈥 no individuals will be named in the report, the reporting is about the issue and solutions, not blame.

Reviewing what happened is the last key component. A review of the incident to check if there are system or process issues which can be improved. If听so听recommendations will be made from the team.

Privacy Preferences

By clicking "Accept All Cookies", you agree to the storing of cookies on your device to enhance site navigation, analyse site usage, and assist in our marketing efforts.