Received
Decided
Request Reference 25002
Requester Type
Department of Social Protection

the present date to include: • Nature and extent of each breach (e.g., type of data compromised, number of individuals affected). • Internal communications or reports discussing the breaches. • Notifications sent to affected individuals, if applicable. • Any correspondence with the Data Protection Commission regarding these incidents. 2. Records of cybersecurity incidents within the same timeframe, including but not limited to: • Any successful or attempted cyber-attacks, hacking incidents, or unauthorized access to the Department's systems. • Internal assessments or audits conducted following such incidents. • Steps taken to mitigate the risks and prevent future breaches. 3. Copies of any internal reviews or reports generated in response to these breaches or incidents, detailing: • The Department’s response strategy. • Changes or improvements made to data security protocols as a result of these incidents. • Any external consultations or advice received regarding these issues. 4. Records of communication between the Department and any third-party vendors or service providers regarding data security measures, particularly those implemented or revised following any breach.