P15. Data breaches

The company should publicly disclose information about its processes for responding to data breaches.

Elements
  1. Does the company clearly disclose that it will notify the relevant authorities without undue delay when a data breach occurs?
  2. Does the company clearly disclose its process for notifying data subjects who might be affected by a data breach?
  3. Does the company clearly disclose what kinds of steps it will take to address the impact of a data breach on its users?
Research guidance

When the security of users’ data has been compromised due to a data breach, companies should have clearly disclosed processes in place for addressing the security threat and for notifying affected users. Given that data breaches can result in significant threats to an individual’s financial or personal security, in addition to exposing private information, companies should make these security processes publicly available. Individuals can then make informed decisions and consider the potential risks before signing up for a service or giving a company their information.

Company press releases or blog posts addressing a data breach after it has occurred do not qualify as sufficient disclosure for this indicator. We expect companies to have formal policies in place regarding their handling of data breaches if and when they occur, and companies to make this information about these policies and commitments public.

Potential sources:

  • Company terms of service or privacy policy
  • Company security guide