A personal data breach is a breach of security which directly affects the confidentiality, integrity and/or availability of personal data.
This includes breaches that result from accidental or deliberate actions and means that a breach is more than just about losing personal data.
Personal data breaches can include:
- Access to information by unauthorised individuals
- Sending personal data to an incorrect recipient via electronic or physical means
- Alteration of personal data without permission and/or need; and
- Loss of availability of personal data.
When to report a data breach
Please inform us as soon as possible if:
- You have received correspondence from Wigan Council and you are not, or you suspect that you are not, the intended recipient.
- You believe your personal information may have been breached, or you are concerned about something that could lead to an incident in the future.
Any data breaches should be reported to our Data Protection Officer.
What you should and shouldn't do
We recommend that you:
Do
- Delete any emails (including from your deleted items) where you are not/suspect you are not the intended recipient or “return to sender” if it is a letter received in the post
- Let us know of any concerns as soon as possible.
Don't
- Open any correspondence which is not addressed to you (this includes letters, as well as emails, messages or any other form of correspondence)
- Share the information with others.
Investigation
Following receipt of your concerns, an appropriate officer will review them and determine whether any further action/investigation is necessary.
If the concerns relate to your personal information, we will keep you informed throughout the process and advise you of any outcomes if appropriate.
If an investigation involves a staff member's actions, we can't share specific details due to their Data Protection rights. However, we may be able to provide a summary of the outcome.
Reporting to the Information Commissioner’s Office
In certain circumstances it may be necessary for the Information Governance Team to raise concerns with the Information Commissioner’s Office (ICO), the UK's independent body set up to uphold information rights.
If a breach involves your personal information and we need to inform the ICO, we will let you know.