# "How to"s



# How to report a data breach

<span style="mso-bookmark: _Toc517868368;"><span style="mso-bookmark: _Toc514259200;">**<span lang="EN-US" style="font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: Calibri; mso-ansi-language: EN-US; mso-fareast-language: EN-US;">- Who reports</span>**</span></span><span style="mso-bookmark: _Toc520817055;"><span style="mso-bookmark: _Toc517868368;"><span style="mso-bookmark: _Toc514259200;"><span lang="EN-US" style="font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: Calibri; mso-ansi-language: EN-US; mso-fareast-language: EN-US;">: Any **employee** of DOME's partners, or any data subject that might have been affected by a data breach in a processing activity that relates to the DOME project, who becomes aware of an incident must immediately report the incident.</span></span></span></span><span lang="EN-US" style="font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: Calibri; mso-ansi-language: EN-US; mso-fareast-language: EN-US;"> In addition, the identification of an incident may occur through sources internal or external to DOME.</span>

<span style="mso-bookmark: _Toc502313123;"><span style="mso-bookmark: _Toc520817056;"><span style="mso-bookmark: _Toc517868369;"><span style="mso-bookmark: _Toc514259201;"><span lang="EN-US" style="font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: 'Microsoft Sans Serif'; mso-ansi-language: EN-US; mso-fareast-language: EN-US;"><span style="mso-list: Ignore;"><span style="font: 7.0pt 'Times New Roman';">- </span></span></span>**<span lang="EN-US" style="font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: Calibri; mso-ansi-language: EN-US; mso-fareast-language: EN-US;">How and when to communicate</span>**</span></span></span></span><span style="mso-bookmark: _Toc520817056;"><span style="mso-bookmark: _Toc517868369;"><span style="mso-bookmark: _Toc514259201;"><span lang="EN-US" style="font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: Calibri; mso-ansi-language: EN-US; mso-fareast-language: EN-US;"> : This communication will be done **<u>within the first 24 hours after the occurrence of the incident </u>**by sending an email to the Privacy Helpdesk to the mailbox <privacy.helpdesk@dome-project.eu> . </span></span></span></span>

<span lang="EN-US" style="font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: 'Microsoft Sans Serif'; mso-ansi-language: EN-US; mso-fareast-language: EN-US;"><span style="mso-list: Ignore;">-<span style="font: 7.0pt 'Times New Roman';"> </span></span></span>**<span lang="EN-US" style="font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: Calibri; mso-ansi-language: EN-US; mso-fareast-language: EN-US;">What is communicated</span>**<span lang="EN-US" style="font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: Calibri; mso-ansi-language: EN-US; mso-fareast-language: EN-US;">: It is essential that as much information as possible is provided in detail to the Privacy Helpdesk staff about what has happened. The communication should contain the following minimum information and answer the following questions:</span>

- - <span lang="EN-US" style="font-size: 8.0pt; line-height: 150%; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol; mso-ansi-language: EN-US; mso-fareast-language: EN-US;"><span style="mso-list: Ignore;"><span style="font: 7.0pt 'Times New Roman';"> </span></span></span><u><span lang="EN-US" style="font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: Calibri; mso-ansi-language: EN-US; mso-fareast-language: EN-US;">When</span></u><span lang="EN-US" style="font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: Calibri; mso-ansi-language: EN-US; mso-fareast-language: EN-US;">: Day and time when the incident occurred and when it was recorded.</span>
    - <span lang="EN-US" style="font-size: 8.0pt; line-height: 150%; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol; mso-ansi-language: EN-US; mso-fareast-language: EN-US;"><span style="mso-list: Ignore;"><span style="font: 7.0pt 'Times New Roman';"> </span></span></span><u><span lang="EN-US" style="font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: Calibri; mso-ansi-language: EN-US; mso-fareast-language: EN-US;">Where</span></u><span lang="EN-US" style="font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: Calibri; mso-ansi-language: EN-US; mso-fareast-language: EN-US;">: place where the incident occurs.</span>
    - <span lang="EN-US" style="font-size: 8.0pt; line-height: 150%; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol; mso-ansi-language: EN-US; mso-fareast-language: EN-US;"><span style="mso-list: Ignore;"><span style="font: 7.0pt 'Times New Roman';"> </span></span></span><u><span lang="EN-US" style="font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: Calibri; mso-ansi-language: EN-US; mso-fareast-language: EN-US;">What</span></u><span lang="EN-US" style="font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: Calibri; mso-ansi-language: EN-US; mso-fareast-language: EN-US;">: description of what happened in the incident, description of the actual and potential consequences, equipment, systems and data categories affected, facts related to the incident. What kind of personal data was affected (e.g., health data, religion, sexual orientation, data of minors, fingerprints, images, voice or data on union membership).</span>
    - <span lang="EN-US" style="font-size: 8.0pt; line-height: 150%; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol; mso-ansi-language: EN-US; mso-fareast-language: EN-US;"><span style="mso-list: Ignore;"><span style="font: 7.0pt 'Times New Roman';"> </span></span></span><span lang="EN-US" style="font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: Calibri; mso-ansi-language: EN-US; mso-fareast-language: EN-US;">How much personal data may have been compromised?</span>
    - <span lang="EN-US" style="font-size: 8.0pt; line-height: 150%; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol; mso-ansi-language: EN-US; mso-fareast-language: EN-US;"><span style="mso-list: Ignore;"><span style="font: 7.0pt 'Times New Roman';"> </span></span></span><u><span lang="EN-US" style="font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: Calibri; mso-ansi-language: EN-US; mso-fareast-language: EN-US;">Who</span></u><span lang="EN-US" style="font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: Calibri; mso-ansi-language: EN-US; mso-fareast-language: EN-US;">: companies involved, people involved.</span>
    - <span lang="EN-US" style="font-size: 8.0pt; line-height: 150%; font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol; mso-ansi-language: EN-US; mso-fareast-language: EN-US;"><span style="mso-list: Ignore;"><span style="font: 7.0pt 'Times New Roman';"> </span></span></span><span lang="EN-US" style="font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: Calibri; mso-ansi-language: EN-US; mso-fareast-language: EN-US;">Any other information you consider relevant.</span>

# How to request a data removal

<span lang="EN-US" style="font-size: 11.0pt; font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: ES; mso-bidi-language: AR-SA;">A data subject might submit a data removal or data erasure request by electronic means at any time. This data removal request will be addressed to the following address : <privacy.helpdesk@dome-project.eu></span>

<span lang="EN-US" style="font-size: 11.0pt; font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: ES; mso-bidi-language: AR-SA;">The data subjects will be informed of the need to include in its request's subject "EXERCISE OF RIGHTS DOME", in order for the Partner to be able to identify the processing activity it relates to.</span>

<span lang="EN-US" style="font-size: 11.0pt; font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: ES; mso-bidi-language: AR-SA;">Data subjects will also be permitted to act on their rights via postal service requests to a particular Partner, however, in this type of requests they will also necessarily need to include in its subject "EXERCISE OF RIGHTS DOME". </span>

<span lang="EN-US" style="font-size: 11.0pt; font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: ES; mso-bidi-language: AR-SA;">In any and all formats, the data subject will necessarily need to specify the data protection right that they are requesting, which will mean that we recommend that the request's subject will actually contain the following phrase : "EXERCISE OF DATA REMOVAL DOME".</span>

<span lang="EN-US" style="font-size: 11.0pt; font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: ES; mso-bidi-language: AR-SA;">When the data subject submits the request by electronic means, and unless the data subject requests otherwise, the information necessarily contained in the response will be provided in a commonly used electronic format. </span>

**<span lang="EN-US" style="font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US;"></span>**

# How to request a data update

<span lang="EN-US" style="font-size: 11.0pt; font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: ES; mso-bidi-language: AR-SA;">A data subject might submit a data update request by electronic means at any time. This data update request will be addressed to the following address: <privacy.helpdesk@dome-project.eu></span>

<span lang="EN-US" style="font-size: 11.0pt; font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: ES; mso-bidi-language: AR-SA;">The data subjects will be informed of the need to include in its request's subject "EXERCISE OF RIGHTS DOME", in order for the Partner to be able to identify the processing activity it relates to.</span>

<span lang="EN-US" style="font-size: 11.0pt; font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: ES; mso-bidi-language: AR-SA;">Data subjects will also be permitted to act on their rights via postal service requests to a particular Partner, however, in this type of requests they will also necessarily need to include in its subject "EXERCISE OF RIGHTS DOME", as was also obliged in the electronic format. </span>

<span lang="EN-US" style="font-size: 11.0pt; font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: ES; mso-bidi-language: AR-SA;">In any and all formats, the data subject will necessarily need to specify the data protection right that they are requesting, which will mean that we recommend that the request's subject will actually contain the following phrase : "EXERCISE OF DATA UPDATE DOME". In the body of the request, they will need to specify the data that they wish to modify,</span>

<span lang="EN-US" style="font-size: 11.0pt; font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: ES; mso-bidi-language: AR-SA;">When the data subject submits the request by electronic means, and unless the data subject requests otherwise, the information necessarily contained in the response will be provided in a commonly used electronic format. </span>

**<span lang="EN-US" style="font-family: 'Microsoft Sans Serif',sans-serif; mso-fareast-font-family: 'Times New Roman'; mso-ansi-language: EN-US;"></span>**

# How to report a provider data breach

**<span lang="EN-US">- Who reports</span>**<span lang="EN-US">: Any **employee** of DOME's partners, or any data subject that might have been affected by a data breach in a processing activity that relates to the DOME project, who becomes aware of an incident must immediately report the incident.</span><span lang="EN-US"> In addition, the identification of an incident may occur through sources internal or external to DOME.</span>

<span lang="EN-US">- </span>**<span lang="EN-US">How and when to communicate</span>**<span lang="EN-US"> : This communication will be done **<u>within the first 24 hours after the occurrence of the incident </u>**by sending an email to the Privacy Helpdesk to the mailbox <privacy.helpdesk@dome-project.eu>.</span>

<span lang="EN-US">- </span>**<span lang="EN-US">What is communicated</span>**<span lang="EN-US">: It is essential that as much information as possible is provided in detail to the Privacy Helpdesk staff about what has happened. The communication should contain the following minimum information and answer the following questions:</span>

- <u><span lang="EN-US">When</span></u><span lang="EN-US">: Day and time when the incident occurred and when it was recorded.</span>
- <u><span lang="EN-US">Where</span></u><span lang="EN-US">: place where the incident occurs.</span>
- <u><span lang="EN-US">What</span></u><span lang="EN-US">: description of what happened in the incident, description of the actual and potential consequences, equipment, systems and data categories affected, facts related to the incident. What kind of personal data was affected (e.g., health data, religion, sexual orientation, data of minors, fingerprints, images, voice or data on union membership).</span>
- <span lang="EN-US">How much personal data may have been compromised?</span>
- <u><span lang="EN-US">Who</span></u><span lang="EN-US">: companies involved, people involved.</span>
- <span lang="EN-US">Any other information you consider relevant.</span>

# How to get in touch with the DPO

The DOME Project's Data Protection Officer has been set up as a Data Protection Board, made up of representative from a member of each Work Package Leader, as well as representation from the Privacy&amp;Ethics by Design Officer.

The Data Protection Board can be reached at <dpb@dome-project.eu>.