Home

Some companies that have chosen us

Privacy Officer and Privacy Consultant
CDP Scheme according to ISO/IEC 17024:2012
European Privacy Auditor
ISDP©10003 Certification Scheme according to ISO/IEC 17065:2012
Auditor
According to standard UNI 11697:2017
Lead Auditor ISO/IEC 27001:2022
According to standard ISO/IEC 17024:2012
Data Protection Officer
According to standard ISO/IEC 17024:2012
Anti-Bribery Lead Auditor Expert
According to standard ISO/IEC 17024:2012
ICT Security Manager
According to standard UNI 11506:2017
IT Service Management (ITSM)
According to the ITIL Foundation
Ethical Hacker (CEH)
According to the EC-Council
Network Defender (CND)
According to the EC-Council
Computer Hacking Forensics Investigator (CHFI)
According to the EC-Council
Penetration Testing Professional (CPENT)
According to the EC-Council

Professional qualifications

Stay up-to-date with world news!

Select your topics of interest:

News

Home / News
/
FINNISH SUPERVISORY AUTHORITY: the security breach of personal information due to the vulnerability of the Exchange Microsoft Software shall be reported to the authorities and registered to the Office of the EDPS

FINNISH SUPERVISORY AUTHORITY: the security breach of personal information due to the vulnerability of the Exchange Microsoft Software shall be reported to the authorities and registered to the Office of the EDPS

The Office of the European Data Protection Supervisor remembers that the Data Controller shall notify to data subjects the personal data breach and to the Supervisory Authority when this data breach can represent an high risk for data subjects. The Cybersecurity Center has warned about a critical vulnerability of the Exchange Microsoft Server at the beginning of March. 

The EDPS Office received 28 notices of personal data breaches related to a critical vulnerability into the Exchange Microsoft Mail Server since March. This number is going to increase. 

The Cybersecurity Center has estimated that at the beginning of March the vulnerability was actively exploited and that an organization which uses a vulnerable Exchange Microsoft Mail Server was a victim of data breach. The simple installation of a software update is not sufficient to hold off a hacker. You can read additional information on the advice in the Bulletin of the Cybersecurity Center. 

The personal data security breach shall be reported if personal data have been lost

In the event of a personal data breach, the data controller shall carry out the risk assessment caused by the personal data breach.

In the event of a personal data breach, personal data is destroyed, lost, altered, unauthorizedly disclosed or accessed by an unauthorized person.

A data breach of an email server is likely to represent a high risk to the rights and freedoms of data subjects. Such personal data breach shall be notified to the persons affected without undue delay. The notification to data subjects is specified in Article 34 of the GDPR.

A high-risk personal data breach must be reported to the supervisory authority, i.e. the Office of the Data Protection Ombudsman. The data controller is responsible for making the notification. The personal data breach shall be notified without undue delay and, where possible, within 72 hours after the breach has been detected. A high-risk security breach shall also be documented.

SOURCE: AUTORITA’ PER LA PROTEZIONE DEI DATI DELLA FINLANDIA

Recommended to you

Advanced Research