CB: Loss of confidentiality

0 – Examples of data exposed to confidentiality risks without evidence that illegal processing has occurred.

  • A paper file or laptop is lost during transit.
  • Equipment has been disposed without destruction of the personal data

+0.25 – Examples of data disposed to a number of known recipients:

  • An email with personal data has been wrongly sent to a number of known recipients.
  • Some customers could access other customers' accounts in an online service.

+0.5 – Examples of data disposed to an unknown number of recipients:

  • Data are published on an internet message board.
  • Data are uploaded to a P2P site.
  • An employee sells a CD ROM with customer data.
  • A wrongly configured website makes publically accessible on internet data from internal users.
Last modified: Saturday, 20 February 2021, 11:58 PM