4 respond principles
requests: 2 layers response
leverage privacy governance structure:
Negligence elements (when fail to notify DS of breach)
IRP responders
Privacy incident (breach) definition
any potential, actual compromise of PI in form that facilitates intentional or unintentional access by unauthorised third party
escalation
internal process of employees alerting supervisors about incident, who report to pre-defined list of experts
IRP
US fed govt (OMB) guidance re breach notification requirement
Cautions against notification when breach poses little or no risk of harm. To assess risk of harm, consider: